Atlas / MCP servers / dschuler36 / Reaper

ReaperSAFE

mcp/dschuler36/reaper

An MCP Server for interacting with Reaper projects.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
4 4r · 0w · 0d
Transport
stdio
License
MIT
Stars
125
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This is an MCP server that connects Reaper projects to an MCP client like Claude Desktop, enabling you to ask questions about your projects and get comprehensive audio analysis for mixing feedback.

This server is read-only by design. It exposes no tools that lets AI modify your project. What it's good for is understanding what you've already made and learning how to improve it. Let AI suggest some ideas and you can try tweaking the knobs and understand how it affects your music by doing.

Tools

Project Discovery & Parsing

  • `find_reaper_projects`: Finds all Reaper projects in the directory you specified in the config.
  • `parse_reaper_project`: Parses a Reaper project file (.RPP) and returns detailed information including tempo, tracks, FX chains, and audio items.

Each track carries its position and identity (track_number matching Reaper's display order, guid), its routing (is_folder/folder_depth, main_send, receives, num_channels, midi_hardware_out), and its mixer state (volume, pan, mute, solo). Each item carries position, length, start_offset, playrate, mute, fades, and every take — with the active take marked, since that is the one that plays.

receives entries name the source track by index and by name, which is what distinguishes a live signal path from a leftover track: a track with main_send: false does not reach the master, and its audio is only audible through whatever receives from it.

These tools work in tandem. When you ask Claude a question about a specific Reaper project, it will use the find_reaper_projects tool to find the project, then use the parse_reaper_project tool to parse the project and answer your question.

Installed FX Discovery

  • `list_installed_fx(plugin_type=None, search_query=None)`: Lists all installed FX/plugins available in Reaper.

Parameters:

  • plugin_type (optional): Filter by plugin type (VST2, VST3, AU, JS, CLAP)
  • `searc
Read from source at commit 9895dc0a921cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add reaper-mcp-server -- uvx reaper-mcp-server
claude-desktop
{
  "mcpServers": {
    "reaper-mcp-server": {
      "command": "uvx",
      "args": [
        "reaper-mcp-server"
      ]
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_audio_filesreadAnalyze audio in a Reaper project for mixing feedback.
find_reaper_projectsreadrpp_finder = RPPFinder(args.reaper_projects_dir)
list_installed_fxreadList all installed FX/plugins available in Reaper.
parse_reaper_projectreadrpp_parser = RPPParser(project_path)
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/reaper_mcp_server/test_rpp_parser_regressions.py:228
base64.b64decode(line, validate=True)

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 9895dc0a921cfull audit observations/trust-audit/mcp-server/dschuler36__reaper.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-079895dc0a921cSAFEB89first audit
06

Questions

What is the Reaper MCP server?

An MCP Server for interacting with Reaper projects.

What tools does Reaper expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Reaper safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Reaper need?

No credential environment variables were found in its source, so it appears to need none.

How does Reaper run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as reaper-mcp-server.

How current is this page?

The grade is for one exact copy of the source (9895dc0a921c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement