Atlas / MCP servers / misbahsy / Video & Audio Editor

Video & Audio EditorSAFE

mcp/misbahsy/video-audio-editor

An FFMPEG powered MCP server for basic Video and Audio editing

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
27 9r · 17w · 1d
Transport
—
License
MIT
Stars
87
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A comprehensive Model Context Protocol (MCP) server that provides powerful video and audio editing capabilities through FFmpeg. This server enables AI assistants to perform professional-grade video editing operations including format conversion, trimming, overlays, transitions, and advanced audio processing.

[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://modelcontextprotocol.io/) [](https://smithery.ai/server/@misbahsy/video-audio-mcp)

✨ Features

  • 🎥 Video Processing: Format conversion, resolution scaling, codec changes, frame rate adjustment
  • 🎵 Audio Processing: Format conversion, bitrate adjustment, sample rate changes, channel configuration
  • ✂️ Editing Tools: Video trimming, speed adjustment, aspect ratio changes
  • 🎨 Overlays & Effects: Text overlays, image watermarks, subtitle burning
  • 🔗 Advanced Editing: Video concatenation with transitions, B-roll insertion, silence removal
  • 🎭 Transitions: Fade in/out effects, crossfade transitions between clips

🛠️ Available Tools

Core Video Operations

  • extract_audio_from_video - Extract audio tracks from video files
  • trim_video - Cut video segments with precise timing
  • convert_video_format - Convert between video formats (MP4, MOV, AVI, etc.)
  • convert_video_properties - Comprehensive video property conversion
  • change_aspect_ratio - Adjust video aspect ratios with padding or cropping
  • set_video_resolution - Change video resolution with quality preservation
  • set_video_codec - Switch video codecs (H.264,
Read from source at commit ccdb92248e40OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add video-edit-mcp -- uvx video-edit-mcp
claude-desktop
{
  "mcpServers": {
    "video-edit-mcp": {
      "command": "uvx",
      "args": [
        "video-edit-mcp"
      ]
    }
  }
}
03

Exposed tools (27)

9 read · 17 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_b_rollwriteInserts B-roll clips into a main video as overlays.
add_basic_transitionswriteAdds basic fade transitions to the beginning or end of a video.
add_image_overlaywriteAdds an image overlay (watermark/logo) to a video.
add_subtitleswriteBurns subtitles from an SRT file onto a video, with optional styling.
add_text_overlaywriteAdds one or more text overlays to a video at specified times and positions.
change_aspect_ratioreadChanges the aspect ratio of a video, using padding or cropping.
change_video_speedreadChanges the playback speed of a video (and its audio).
concatenate_videosreadConcatenates multiple video files into a single output file.
convert_audio_formatreadConverts an audio file to the specified target format.
convert_audio_propertiesreadConverts audio file format and ALL specified properties like bitrate, sample rate, and channels.
convert_video_formatreadConverts a video file to the specified target format, attempting to copy codecs first.
convert_video_propertiesreadConverts video file format and ALL specified properties like resolution, codecs, bitrates, and frame rate.
extract_audio_from_videoreadExtracts audio from a video file and saves it.
health_checkreadReturns a simple health status to confirm the server is running.
remove_silencedestructiveRemoves silent segments from an audio or video file.
set_audio_bitratewriteSets the bitrate for an audio file.
set_audio_channelswriteSets the number of channels for an audio file (1 for mono, 2 for stereo).
set_audio_sample_ratewriteSets the sample rate for an audio file.
set_video_audio_track_bitratewriteSets the audio bitrate of a video
set_video_audio_track_channelswriteSets the number of audio channels of a video
set_video_audio_track_codecwriteSets the audio codec of a video
set_video_audio_track_sample_ratewriteSets the audio sample rate of a video
set_video_bitratewriteSets the video bitrate of a video, attempting to copy the audio stream.
set_video_codecwriteSets the video codec of a video, attempting to copy the audio stream.
set_video_frame_ratewriteSets the frame rate of a video, attempting to copy the audio stream.
set_video_resolutionwriteSets the resolution of a video, attempting to copy the audio stream.
trim_videowriteTrims a video to the specified start and end times.
04

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
remove_silence
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.cursor/rules/mcp-python.md:604
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.cursor/rules/mcp.txt:4049
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.cursor/rules/mcp.txt:5421
This creates the beginnings of a .NET console application that can read the API key from user secrets.
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
.cursor/rules/mcp.txt:5645
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:81
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.cursor/rules/mcp.txt:12824
Client->>+Server: POST InitializedNotification<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.cursor/rules/mcp.txt:12828
Client->>+Server: POST ... request ...<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.cursor/rules/mcp.txt:12841
Client->>+Server: POST ... notification/response ...<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.cursor/rules/mcp.txt:15563
MCP clients **MUST NOT** send tokens to the MCP server other than ones issued by the MCP server's authorization server.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.cursor/rules/mcp.txt:16332
Client->>+Server: POST InitializedNotification<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
tests/sample.mp4
tests/sample.mp4
Why it matters. 10498677 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
tests/sample.png
tests/sample.png
Why it matters. 3208752 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ccdb92248e40full audit observations/trust-audit/mcp-server/misbahsy__video-audio-editor.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ccdb92248e40SAFEB88first audit
06

Questions

What is the Video & Audio Editor MCP server?

An FFMPEG powered MCP server for basic Video and Audio editing

What tools does Video & Audio Editor expose?

27 in total: 9 read-only, 17 that write, and 1 that can delete or overwrite (remove_silence). Every one is listed on this page with its risk.

Is Video & Audio Editor safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Video & Audio Editor need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (ccdb92248e40), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement