premiere-pro-mcp
BLOCKgrade D · trust 65/100Local-first MCP server for supported Adobe Premiere Pro workflows. Connect Claude, Codex, or Cursor through a local CEP bridge; inspect, preview, and approve edits.
adobeadobe premiere proai video editingcepclaudeclaude desktopcodexcreative cloudOverview
From the repository's own README, as read at the audited commit.
<div align="center"># MCP for Adobe Premiere Pro<!-- mcp-name: io.github.leancoderkavy/premiere-pro -->[](https://mcptoplist.com/server/glama%2Fleancoderkavy%2Fpremiere-pro-mcp)**Give compatible AI assistants structured control over supported Adobe Premiere Pro workflows.**Free, MIT licensed, local-first, and published to npm as [`premiere-pro-mcp`](https://www.npmjs.com/package/premiere-pro-mcp) — the only package name that installs this project.[Website](https://premiere-pro-mcp.com/) · [Recorded demo](https://premiere-pro-mcp.com/demo/) · [Compare servers](https://premiere-pro-mcp.com/compare/) · [Setup guides](https://premiere-pro-mcp.com/blog/how-to-set-up-premiere-pro-mcp/) · [Search tools](https://premiere-pro-mcp.com/tools/) · [Troubleshooting](https://premiere-pro-mcp.com/docs/troubleshooting/) · [Release facts](https://premiere-pro-mcp.com/facts/)Development source: 370 core tools across 53 modules, 4 resources, and 17 guided workflows. A connected UXP host adds 95 capability-gated tools.The [completed AE render handoff](docs/after-effects-render-handoff.md) previews and confirms importing one finished render into an existing Premiere bin, with host and file rechecks and an import receipt.[](LICENSE)[](https://nodejs.org)[](https://modelcontextprotocol.io/specification/2026-07-28)[](https://www.npmjs.com/package/premiere-pro-mcp)[](https://premiere-pro-mcp.fly.dev)[](https://www.adobe.com/products/premiere.html)[ 5 read · 2 write · 0 destructive
| Tool | Risk | Description |
|---|---|---|
assistant-edit | write | Transcript-locked dialogue analysis, preview, derivative assembly, captions, reframing, and structural review. |
captions | read | Caption-track creation, supported caption readback, sequence structure, and review-frame evidence. |
delivery | read | Export preflight, rendering, interchange export, review-frame export, queue state, and post-export local verification. |
essential | write | Connection, project and sequence inspection, safe edit-plan preview, save, delivery validation, export, and local delivery verification. |
get_notes | read | Read transcript review notes |
inspection | read | Read-only project, sequence, timeline, review, and render-queue inspection before an editorial or delivery handoff. |
intake | read | Session-scoped watched-folder monitoring, path-redacted proposals, deliberate import, and project inspection. |
Details
- Source
- leancoderkavy/premiere-pro-mcp
- npm
premiere-pro-mcp@1.15.2- Transports
- stdio · streamable-http
- Credentials it reads
ALLOW_UNAUTHENTICATEDGITHUB_TOKENMCP_AUTH_TOKENMCP_OAUTH_ALLOWED_SUBJECTSMCP_OAUTH_AUDIENCEMCP_OAUTH_ISSUERMCP_OAUTH_JWKS_URIMCP_OAUTH_REQUIRED_SCOPESNEXT_PUBLIC_POSTHOG_PROJECT_TOKENNODE_AUTH_TOKENNPM_TOKENPOSTHOG_API_KEY- License
- MIT
- Stars
- 259 · pushed 0d ago
Trust audit
Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(sql: string): void;
premiere-workflow-starter-kit.zip
baseURL: `http://127.0.0.1:${port}`,url: `http://127.0.0.1:${port}/health`,const TOKEN = "bridge-edge-token-at-least-16-characters";
const TOKEN = "test-token-at-least-16-characters";
.bk.yaml
.debug
it("rejects scripts containing eval()", async () => {it("rejects scripts containing new Function()", async () => {sendCommand('new Function("code")', { tempDir: "/tmp/test-bridge" })it("allows eval() in raw commands", async () => {export const AFTER_EFFECTS_HELPERS_VERSION = createHash("md5")export const HELPERS_VERSION = createHash("md5").update(HELPERS).digest("hex").slice(0, 12);import manifest from "../../public-product-manifest.json"
const repository = fileURLToPath(new URL("../../", import.meta.url));[`../../docs/design/marketing-artwork-v2/${name}-v2.png`, `marketing/${name}-v2.webp`, 1600],[`../../docs/design/marketing-artwork-v2/${name}-v2.png`, `marketing/${name}-v2-mobile.webp`, 720],import { sendCommand } from '../../dist/bridge/file-bridge.js'const fixtureURL = `http://127.0.0.1:${process.env.LANDING_E2E_POSTHOG_PORT || 3161}`POSTHOG_HOST: `http://127.0.0.1:${fixturePort}`,const url = `http://127.0.0.1:${address.port}`;@radix-ui/react-slot, class-variance-authority, clsx, lucide-react, next, radix-ui, tailwind-merge, @tailwindcss/postcss
@modelcontextprotocol/node, @modelcontextprotocol/server, jose, ws, zod, @modelcontextprotocol/client, @types/node, @types/ws
- Replaced UXP filesystem full access with operator-selected folder access and kept
Gates applied: no_behavioural_pass.
Audited 2026-09-16 · audit v0.4.0 · source sha 0ac5cfad9f54 · full audit: observations/trust-audit/mcp-server/leancoderkavy__premiere-pro-mcp.json · Report an issue or request a re-scan
Audit history
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-16 | 0ac5cfad9f54 | BLOCK | D | 65 | first audit |
Alternatives
Other servers in the same categories, safer ones first.
Questions
What is the premiere-pro-mcp MCP server?
Local-first MCP server for supported Adobe Premiere Pro workflows. Connect Claude, Codex, or Cursor through a local CEP bridge; inspect, preview, and approve edits.
What tools does premiere-pro-mcp expose?
7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is premiere-pro-mcp safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (65/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does premiere-pro-mcp need?
It reads ALLOW_UNAUTHENTICATED, GITHUB_TOKEN, MCP_AUTH_TOKEN, MCP_OAUTH_ALLOWED_SUBJECTS, MCP_OAUTH_AUDIENCE, MCP_OAUTH_ISSUER, MCP_OAUTH_JWKS_URI, MCP_OAUTH_REQUIRED_SCOPES, NEXT_PUBLIC_POSTHOG_PROJECT_TOKEN, NODE_AUTH_TOKEN, NPM_TOKEN and POSTHOG_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does premiere-pro-mcp run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as premiere-pro-mcp at 1.15.2.
How current is this page?
The grade is for one exact copy of the source (0ac5cfad9f54), read on 2026-09-16. The repository is watched and re-audited when it changes.
Provenance: OBSERVED · read 2026-09-16 · job trust-audit-2026-09-16