Music StudioBLOCK
Two-mode MCP music studio: scored composition (ABC notation) and live performance (Strudel). Interactive ext-apps UI with sheet music rendering, 30+ instruments, style presets, and live coding REPL.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English · 简体中文 · Français · 日本語
[](https://www.npmjs.com/package/mcp-music-studio) [](https://github.com/linxule/mcp-music-studio/actions/workflows/ci.yml) [](https://github.com/linxule/mcp-music-studio/blob/main/LICENSE)
Make music with an AI assistant, inside the chat. Ask for a song and get sheet music you can play and edit. Ask for a beat and get a live-coding player with visuals. Then edit the piece together, move its controls while it plays, or take turns with the AI.
Music Studio is an MCP server. MCP is a standard way to give an AI assistant extra tools; you need a chat app that supports it, such as Claude. In Claude, claude.ai and other apps that support MCP Apps, the player appears in the chat. In Claude Code and other terminal apps, you get a link that opens the player in your browser.
One live set in the player. Every section is a change made while the music plays. [Watch the full video](https://github.com/linxule/mcp-music-studio/releases/download/v0.5.3/mcp-music-studio-v0.5-live-set-1080p60.mp4).
Quick start
Add this URL as a remote MCP server. There is nothing to install.
https://music-studio.linxule.com/mcp
- **Claude and c
6b40c76478e0OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-music-studio -- npx -y [email protected]
Exposed tools (22)
15 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze-harmony | read | |
convert-abc-to-strudel | read | |
create-share-link | write | |
explain-selection | read | |
get-music-guide | read | |
get-session | read | |
get-strudel-guide | read | |
get-studio-state | read | |
late | read | x |
late-tool | read | |
play-current-music | read | |
play-live-pattern | read | |
play-sheet-music | read | |
search-music-docs | read | |
set-pattern | write | |
set-score | write | |
stop-music | write | |
suggest-edit | write | |
swap-pattern | read | |
t | read | d |
undo-studio-edit | write | |
update-session | write |
Trust audit
BLOCKgrade D · trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const shown = eval(shownSrc);
baseURL: "http://127.0.0.1:5211",
url: "http://127.0.0.1:5211",
wait_for "http://127.0.0.1:$WORKER_PORT/health" wrangler
wait_for "http://127.0.0.1:$HARNESS_PORT/" vite
const token = "AbC123-xyz_TOKEN-value.0987";
const check = new Function("feedbackVisible", "statusError", `const updateFeedback = new Function("setEditorMessage", "setStatus", "messages", "withTransposeNote", feedbackUpdate);expect(() => new Function(code), name).not.toThrow();
new Function(`async () => {\n${code}\n}`);const file = path.join(SFCACHE, crypto.createHash("sha1").update(url).digest("hex"));const file = path.join(SFCACHE, crypto.createHash("sha1").update(u).digest("hex"));import { montage, SCENES } from "../../../dev/film-score.ts";import { FINALE_START, FINALE_LAYERS, SCENES, montage } from "../../../dev/film-score.ts";import { SCENE_CUES, STOP_AT, withShader } from "../../../dev/film-song.ts";import { FINALE_LAYERS, SCENES, montage } from "../../../dev/film-score.ts";const built = [here("./strudel-validate-child.js"), here("../../dist/strudel-validate-child.js")];# Open http://127.0.0.1:5177/studio.html
const bytes = Uint8Array.from(atob(r.blob), c => c.charCodeAt(0));
const bin = atob(base64);
const bin = atob(resource.blob);
binary = atob(padded);
expect(Uint8Array.from(atob(audio), (c) => c.charCodeAt(0))).toEqual(ai.clip);
@modelcontextprotocol/client, @modelcontextprotocol/core, @modelcontextprotocol/ext-apps, abcjs, cors, express, tonal, zod
abcjs, acorn, agents, tonal, zod, typescript
Gates applied: no_behavioural_pass.
6b40c76478e0full audit observations/trust-audit/mcp-server/linxule__music-studio.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6b40c76478e0 | BLOCK | D | 63 | first audit |
Questions
What is the Music Studio MCP server?
Two-mode MCP music studio: scored composition (ABC notation) and live performance (Strudel). Interactive ext-apps UI with sheet music rendering, 30+ instruments, style presets, and live coding REPL.
What tools does Music Studio expose?
22 in total: 15 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Music Studio safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (63/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Music Studio need?
It reads CLOUDFLARE_API_TOKEN and CONTEXT7_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Music Studio run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-music-studio-worker at 0.12.4.
How current is this page?
The grade is for one exact copy of the source (6b40c76478e0), read on 2026-10-07. The repository is watched and re-audited when it changes.