Atlas / MCP servers / ghchen99 / MuseScore

MuseScoreBLOCK

mcp/ghchen99/musescore

A Model Context Protocol (MCP) server that provides programmatic control over MuseScore!

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
26 12r · 13w · 1d
Transport
—
License
MIT
Stars
107
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides programmatic control over MuseScore, via a WebSocket-based plugin system. This allows AI assistants like Claude to compose music, add lyrics, navigate scores, and control MuseScore directly.

Prerequisites

  • MuseScore 3.x or 4.x
  • Python 3.8+
  • Claude Desktop or compatible MCP client

Setup

1. Install the MuseScore Plugin

First, save the QML plugin code to your MuseScore plugins directory:

macOS: ~/Documents/MuseScore4/Plugins/musescore-mcp-websocket.qml Windows: %USERPROFILE%\Documents\MuseScore4\Plugins\musescore-mcp-websocket.qml Linux: ~/Documents/MuseScore4/Plugins/musescore-mcp-websocket.qml

2. Enable the Plugin in MuseScore

  1. Open MuseScore
  2. Go to Plugins → Plugin Manager
  3. Find "MuseScore API Server" and check the box to enable it
  4. Click OK

3. Setup Python Environment

git clone 
cd mcp-agents-demo
python -m venv .venv
source .venv/bin/activate  # On Windows: .venv\Scripts\activate
pip install -r requirements.txt

4. Configure Claude Desktop

Add to your Claude Desktop configuration file:

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json

{
"mcpServers": {
"musescore": {
"command": "/path/to/your/project/.venv/bin/python",
"args": [
"/path/to/your/project/server.py"
]
}
}
}

Note: Update the paths to match your actual project location.

Running the System

Order of Operations

  1. Start MuseScore first with a score open
  2. Run the MuseScore plugin: Go to Plugins → MuseScore API Server
  3. You should see console output: "Starting MuseScore API Server on port 8765"
  4. Then start the Python MCP server or restart Claude Desktop

[insert screenshot of different functionality, harmonisation, melodywriting, as

Read from source at commit cf2b0fe6b17bOBSERVED · 2026-10-07
02

Exposed tools (26)

12 read · 13 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_instrumentwriteAdd a new staff/instrument to the score.
add_lyricswriteAdd lyrics to consecutive notes starting from the current cursor position.
add_notewriteAdd a note at the current cursor position with the specified pitch and duration.
add_restwriteAdd a rest at the current cursor position.
add_tupletwriteAdd a tuplet at the current cursor position.
append_measurereadAppend measures to the end of the score.
connect_to_musescorereadConnect to the MuseScore WebSocket API.
delete_selectiondestructiveDelete the current selection or specified measure.
get_cursor_inforeadGet information about the current cursor position.
get_scorereadGet information about the current score.
go_to_beginning_of_scorereadNavigate to the beginning of the score.
go_to_final_measurereadNavigate to the final measure of the score.
go_to_measurereadNavigate to a specific measure.
insert_measurewriteInsert a measure at the current position.
next_elementwriteMove cursor to the next element.
next_staffwriteMove cursor to the next staff.
ping_musescorereadPing the MuseScore WebSocket API to check connection.
prev_elementwriteMove cursor to the previous element.
prev_staffwriteMove cursor to the previous staff.
processSequencereadProcess a sequence of commands.
select_current_measurereadSelect the current measure.
select_custom_rangeread
set_instrument_soundwriteChange the sound of an instrument on a staff.
set_staff_mutewriteMute or unmute a staff.
set_time_signaturewriteSet the time signature.
undoreadUndo the last action.
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
syntax_check.js:5
new Function(code);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_selection
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
examples/asian instrumental/Asian Instrumental.mscz
Asian Instrumental.mscz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/string quartet/String Quartet.mscz
String Quartet.mscz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, websockets
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
assets/mcp-muse.gif
assets/mcp-muse.gif
Why it matters. 19459211 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha cf2b0fe6b17bfull audit observations/trust-audit/mcp-server/ghchen99__musescore.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07cf2b0fe6b17bBLOCKD69first audit
05

Questions

What is the MuseScore MCP server?

A Model Context Protocol (MCP) server that provides programmatic control over MuseScore!

What tools does MuseScore expose?

26 in total: 12 read-only, 13 that write, and 1 that can delete or overwrite (delete_selection). Every one is listed on this page with its risk.

Is MuseScore safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MuseScore need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (cf2b0fe6b17b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement