ReaperSAFE
An MCP Server for interacting with Reaper projects.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This is an MCP server that connects Reaper projects to an MCP client like Claude Desktop, enabling you to ask questions about your projects and get comprehensive audio analysis for mixing feedback.
This server is read-only by design. It exposes no tools that lets AI modify your project. What it's good for is understanding what you've already made and learning how to improve it. Let AI suggest some ideas and you can try tweaking the knobs and understand how it affects your music by doing.
Tools
Project Discovery & Parsing
- `find_reaper_projects`: Finds all Reaper projects in the directory you specified in the config.
- `parse_reaper_project`: Parses a Reaper project file (.RPP) and returns detailed information including tempo, tracks, FX chains, and audio items.
Each track carries its position and identity (track_number matching Reaper's display order, guid), its routing (is_folder/folder_depth, main_send, receives, num_channels, midi_hardware_out), and its mixer state (volume, pan, mute, solo). Each item carries position, length, start_offset, playrate, mute, fades, and every take — with the active take marked, since that is the one that plays.
receives entries name the source track by index and by name, which is what distinguishes a live signal path from a leftover track: a track with main_send: false does not reach the master, and its audio is only audible through whatever receives from it.
These tools work in tandem. When you ask Claude a question about a specific Reaper project, it will use the find_reaper_projects tool to find the project, then use the parse_reaper_project tool to parse the project and answer your question.
Installed FX Discovery
- `list_installed_fx(plugin_type=None, search_query=None)`: Lists all installed FX/plugins available in Reaper.
Parameters:
plugin_type(optional): Filter by plugin type (VST2, VST3, AU, JS, CLAP)- `searc
9895dc0a921cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add reaper-mcp-server -- uvx reaper-mcp-server
{
"mcpServers": {
"reaper-mcp-server": {
"command": "uvx",
"args": [
"reaper-mcp-server"
]
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_audio_files | read | Analyze audio in a Reaper project for mixing feedback. |
find_reaper_projects | read | rpp_finder = RPPFinder(args.reaper_projects_dir) |
list_installed_fx | read | List all installed FX/plugins available in Reaper. |
parse_reaper_project | read | rpp_parser = RPPParser(project_path) |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
base64.b64decode(line, validate=True)
Gates applied: no_behavioural_pass.
9895dc0a921cfull audit observations/trust-audit/mcp-server/dschuler36__reaper.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 9895dc0a921c | SAFE | B | 89 | first audit |
Questions
What is the Reaper MCP server?
An MCP Server for interacting with Reaper projects.
What tools does Reaper expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Reaper safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Reaper need?
No credential environment variables were found in its source, so it appears to need none.
How does Reaper run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as reaper-mcp-server.
How current is this page?
The grade is for one exact copy of the source (9895dc0a921c), read on 2026-10-07. The repository is watched and re-audited when it changes.