Media ProcessorSAFE
A Node.js server implementing Model Context Protocol (MCP) for media processing operations, providing powerful video and image manipulation capabilities.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@maoxiaoke/mcp-media-processor)
A Node.js server implementing Model Context Protocol (MCP) for media processing operations, providing powerful video and image manipulation capabilities.
Features
- Video processing and conversion
- Image processing and manipulation
- Media compression
- Video trimming and editing
- Image effects and watermarking
Prerequisites
Before using this server, make sure you have the following dependencies installed on your system:
- FFmpeg: Required for video processing operations
- macOS:
brew install ffmpeg - Ubuntu/Debian:
sudo apt-get install ffmpeg - Windows: Download from FFmpeg official website
- ImageMagick: Required for image processing operations
- macOS:
brew install imagemagick - Ubuntu/Debian:
sudo apt-get install imagemagick - Windows: Download from ImageMagick official website
How to use
Add this to your claude_desktop_config.json:
NPX
{
"mcpServers": {
"mediaProcessor": {
"command": "npx",
"args": [
"-y",
"mcp-media-processor@latest"
]
}
}
}API
Tools
Video Operations
- execute-ffmpeg
- Execute any FFmpeg command with custom options
- Inputs:
inputPath(string): Absolute path to input video fileoptions(string[]): Array of FFmpeg command optionsoutputPath(string, optional): Absolute path for output fileoutputFilename(string, optional): Output filename
- convert-video
- Convert video to different format
- Inputs:
inputPath(string): Absolute path to input video fileoutputFormat(string): Desired output format (e.g., mp4, mkv, avi)outputPath(string, optional): Custom output pathoutputFilename(string
ab10b97267f1OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-media-processor -- npx -y [email protected]
{
"mcpServers": {
"mcp-media-processor": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (10)
7 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add-watermark | write | Add watermark to image |
apply-effect | write | Apply visual effect to image |
compress-image | read | Compress PNG image using ImageMagick |
compress-video | read | Compress video file |
convert-image | read | Convert image to different format |
convert-video | read | Convert video to different format |
execute-ffmpeg | write | Execute any FFmpeg command with custom options |
resize-image | read | Resize image to specified dimensions |
rotate-image | read | Rotate image by specified degrees |
trim-video | read | Trim video to specified duration |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
@modelcontextprotocol/sdk, fluent-ffmpeg, os, zod, @types/fluent-ffmpeg, @types/node, typescript
test/nazha.HEIC
test/nazha.mov
test/share.mov
Gates applied: no_behavioural_pass, no_license.
ab10b97267f1full audit observations/trust-audit/mcp-server/maoxiaoke__media-processor.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ab10b97267f1 | SAFE | B | 89 | first audit |
Questions
What is the Media Processor MCP server?
A Node.js server implementing Model Context Protocol (MCP) for media processing operations, providing powerful video and image manipulation capabilities.
What tools does Media Processor expose?
10 in total: 7 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Media Processor safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Media Processor need?
No credential environment variables were found in its source, so it appears to need none.
How does Media Processor run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-media-processor at 1.0.8.
How current is this page?
The grade is for one exact copy of the source (ab10b97267f1), read on 2026-10-08. The repository is watched and re-audited when it changes.