Atlas / MCP servers / linxule / Music Studio

Music StudioBLOCK

mcp/linxule/music-studio

Two-mode MCP music studio: scored composition (ABC notation) and live performance (Strudel). Interactive ext-apps UI with sheet music rendering, 30+ instruments, style presets, and live coding REPL.

Verdict
BLOCK
Grade
D
Trust score
63 /100
Exposed tools
22 15r · 7w · 0d
Transport
stdio · streamable-http
License
AGPL-3.0
Stars
74
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English · 简体中文 · Français · 日本語

[](https://www.npmjs.com/package/mcp-music-studio) [](https://github.com/linxule/mcp-music-studio/actions/workflows/ci.yml) [](https://github.com/linxule/mcp-music-studio/blob/main/LICENSE)

Make music with an AI assistant, inside the chat. Ask for a song and get sheet music you can play and edit. Ask for a beat and get a live-coding player with visuals. Then edit the piece together, move its controls while it plays, or take turns with the AI.

Music Studio is an MCP server. MCP is a standard way to give an AI assistant extra tools; you need a chat app that supports it, such as Claude. In Claude, claude.ai and other apps that support MCP Apps, the player appears in the chat. In Claude Code and other terminal apps, you get a link that opens the player in your browser.

One live set in the player. Every section is a change made while the music plays. [Watch the full video](https://github.com/linxule/mcp-music-studio/releases/download/v0.5.3/mcp-music-studio-v0.5-live-set-1080p60.mp4).

Quick start

Add this URL as a remote MCP server. There is nothing to install.

https://music-studio.linxule.com/mcp
  • **Claude and c
Read from source at commit 6b40c76478e0OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-music-studio -- npx -y [email protected]
03

Exposed tools (22)

15 read · 7 write · 0 destructive.

ToolRiskDescription
analyze-harmonyread
convert-abc-to-strudelread
create-share-linkwrite
explain-selectionread
get-music-guideread
get-sessionread
get-strudel-guideread
get-studio-stateread
latereadx
late-toolread
play-current-musicread
play-live-patternread
play-sheet-musicread
search-music-docsread
set-patternwrite
set-scorewrite
stop-musicwrite
suggest-editwrite
swap-patternread
treadd
undo-studio-editwrite
update-sessionwrite
04

Trust audit

BLOCKgrade D · trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (10 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/verify-record.mjs:382
const shown = eval(shownSrc);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
playwright.config.ts:15
baseURL: "http://127.0.0.1:5211",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
playwright.config.ts:24
url: "http://127.0.0.1:5211",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/ci-browser.sh:52
wait_for "http://127.0.0.1:$WORKER_PORT/health" wrangler
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/ci-browser.sh:53
wait_for "http://127.0.0.1:$HARNESS_PORT/" vite
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/usage-format.test.ts:142
const token = "AbC123-xyz_TOKEN-value.0987";
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/abc-edit-feedback.test.ts:9
const check = new Function("feedbackVisible", "statusError", `
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/abc-edit-feedback.test.ts:34
const updateFeedback = new Function("setEditorMessage", "setStatus", "messages", "withTransposeNote", feedbackUpdate);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/abc-to-strudel.test.ts:678
expect(() => new Function(code), name).not.toThrow();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/guide-blocks.ts:90
new Function(`async () => {\n${code}\n}`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/showcase/film/lib.mjs:127
const file = path.join(SFCACHE, crypto.createHash("sha1").update(url).digest("hex"));
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/showcase/film/lib.mjs:441
const file = path.join(SFCACHE, crypto.createHash("sha1").update(u).digest("hex"));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/showcase/film/lab.mjs:4
import { montage, SCENES } from "../../../dev/film-score.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/showcase/film/screens.mjs:6
import { FINALE_START, FINALE_LAYERS, SCENES, montage } from "../../../dev/film-score.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/showcase/film/song.mjs:8
import { SCENE_CUES, STOP_AT, withShader } from "../../../dev/film-song.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/showcase/film/take.mjs:9
import { FINALE_LAYERS, SCENES, montage } from "../../../dev/film-score.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/shared/strudel-validate-host.ts:107
const built = [here("./strudel-validate-child.js"), here("../../dist/strudel-validate-child.js")];
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
dev/README.md:7
# Open http://127.0.0.1:5177/studio.html
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
dev/studio.ts:152
const bytes = Uint8Array.from(atob(r.blob), c => c.charCodeAt(0));
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/verify-record.mjs:101
const bin = atob(base64);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/share-host.ts:98
const bin = atob(resource.blob);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/shared/share-url.ts:183
binary = atob(padded);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/worker-tts.test.ts:547
expect(Uint8Array.from(atob(audio), (c) => c.charCodeAt(0))).toEqual(ai.clip);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/client, @modelcontextprotocol/core, @modelcontextprotocol/ext-apps, abcjs, cors, express, tonal, zod
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
worker/package.json
abcjs, acorn, agents, tonal, zod, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6b40c76478e0full audit observations/trust-audit/mcp-server/linxule__music-studio.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076b40c76478e0BLOCKD63first audit
06

Questions

What is the Music Studio MCP server?

Two-mode MCP music studio: scored composition (ABC notation) and live performance (Strudel). Interactive ext-apps UI with sheet music rendering, 30+ instruments, style presets, and live coding REPL.

What tools does Music Studio expose?

22 in total: 15 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Music Studio safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (63/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Music Studio need?

It reads CLOUDFLARE_API_TOKEN and CONTEXT7_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Music Studio run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-music-studio-worker at 0.12.4.

How current is this page?

The grade is for one exact copy of the source (6b40c76478e0), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement