Atlas / MCP servers / niavasha / Plex

PlexCAUTION

mcp/niavasha/plex-2

Plex MCP Server

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
61 39r · 17w · 5d
Transport
stdio · streamable-http
License
MIT
Stars
54
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to your Plex Media Server, Sonarr, Radarr, and Trakt.tv — all from a single unified server.

[](https://www.typescriptlang.org/) [](https://nodejs.org/) [](https://modelcontextprotocol.io/) [](https://opensource.org/licenses/MIT)

What is this?

This MCP server transforms your Plex Media Server into an AI-queryable database. Ask your AI assistant questions like:

  • "What movies have I watched recently?"
  • "Show me my viewing statistics for the past month"
  • "What's the most popular content on my server?"
  • "Find action movies in my library"
  • "What's on my continue watching list?"
  • "Add that new show to Sonarr"
  • "What's in my download queue?"
  • "Sync my watch history to Trakt"
  • "Recommend me some movies I haven't seen"

Features

46 tools out of the box (58 with write operations enabled):

  • Plex Library Management — Browse libraries, search media, get detailed metadata, list playlists and watchlist
  • Tautulli-Style Analytics — Viewing statistics, user activity, popular content, watch history
  • Personalized Recommendations — AI-powered movie suggestions based on your watch history, genres, directors, and actors. Supports per-user profiles for multi-user Plex servers.
  • Sonarr/Radarr Integration — Browse, search, add series/movies, view queues, trigger downloads
  • Trakt.tv Sync — OAuth au
Read from source at commit ab3fb262fb94OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add plex-mcp-server --env PLEX_TOKEN=${PLEX_TOKEN} --env RADARR_API_KEY=${RADARR_API_KEY} --env SONARR_API_KEY=${SONARR_API_KEY} --env TRAKT_ACCESS_TOKEN=${TRAKT_ACCESS_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "plex-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "PLEX_TOKEN": "${PLEX_TOKEN}",
        "RADARR_API_KEY": "${RADARR_API_KEY}",
        "SONARR_API_KEY": "${SONARR_API_KEY}",
        "TRAKT_ACCESS_TOKEN": "${TRAKT_ACCESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (61)

39 read · 17 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_to_playlistwriteAdd a media item to a playlist (requires PLEX_ENABLE_MUTATIVE_OPS=true)
add_to_watchlistwriteAdd a local Plex movie or show to the account watchlist (requires PLEX_ENABLE_MUTATIVE_OPS=true)
arr_get_statusreadCheck connection status of Sonarr and Radarr services
clear_playlistdestructiveClear all items from a playlist (preview unless confirm=true; requires PLEX_ENABLE_MUTATIVE_OPS=true)
create_playlistwriteCreate a new Plex playlist (requires PLEX_ENABLE_MUTATIVE_OPS=true).
delete_all_librariesdestructivex
delete_playlistdestructiveDelete a Plex playlist without deleting the underlying media (requires PLEX_ENABLE_MUTATIVE_OPS=true)
export_libraryreadExport a full library to a JSON file (within ./exports)
get_active_sessionsreadGet currently active Plex streams — who is watching what right now,
get_editable_fieldsreadGet editable fields and available tags for a media item
get_fully_watchedreadGet all fully watched movies and shows from a library
get_librariesreadx
get_library_itemsreadList items in a library with pagination (useful for large libraries)
get_library_statsreadGet library-specific statistics
get_media_detailsreadGet detailed information about a specific media item
get_on_deckreadGet on deck (continue watching) items
get_playlist_itemsreadGet items in a Plex playlist
get_playlistsreadGet all Plex playlists
get_popular_contentreadGet most popular content by plays or duration
get_recently_addedreadGet recently added media
get_recently_watchedreadGet recently watched movies and shows
get_recommendationsreadGet personalized movie recommendations from your Plex library based on watch history.
get_user_statsreadGet user-specific watch statistics
get_watch_historyreadGet detailed watch history with session information
get_watch_statsreadGet comprehensive watch statistics (Tautulli-style analytics)
get_watchlistreadGet the user
mark_unwatchedreadMark a Plex media item as unwatched (requires PLEX_ENABLE_MUTATIVE_OPS=true)
mark_watchedreadMark a Plex media item as watched (requires PLEX_ENABLE_MUTATIVE_OPS=true)
pingreadping
radarr_add_moviewriteAdd a new movie to Radarr by TMDB ID
radarr_get_calendarreadGet upcoming movies from the Radarr calendar
radarr_get_missingreadGet missing/wanted movies from Radarr
radarr_get_moviesreadList all movies in Radarr with optional title filter
radarr_get_profilesreadGet Radarr quality profiles and root folders (needed before adding movies)
radarr_get_queuereadGet the current Radarr download queue
radarr_searchwriteSearch TMDB for new movies to add to Radarr
radarr_trigger_searchwriteTrigger a search for missing movies, optionally for a specific movie
rate_mediawriteSet the user
remove_from_playlistdestructiveRemove an item from a playlist (requires PLEX_ENABLE_MUTATIVE_OPS=true)
remove_from_watchlistdestructiveRemove a movie or show from the account watchlist by global Plex GUID or local rating key (requires PLEX_ENABLE_MUTATIVE_OPS=true)
search_mediareadSearch for media in Plex libraries
some_future_toolreadx
sonarr_add_serieswriteAdd a new series to Sonarr by TVDB ID
sonarr_get_calendarreadGet upcoming episodes from the Sonarr calendar
sonarr_get_missingreadGet missing/wanted episodes from Sonarr
sonarr_get_profilesreadGet Sonarr quality profiles and root folders (needed before adding series)
sonarr_get_queuereadGet the current Sonarr download queue
sonarr_get_seriesreadList all series in Sonarr with optional title filter
sonarr_searchwriteSearch TheTVDB for new series to add to Sonarr
sonarr_trigger_searchwriteTrigger a search for missing episodes, optionally for a specific series
trakt_authenticatewriteStart Trakt.tv OAuth authentication process
trakt_complete_authreadComplete Trakt.tv authentication with authorization code
trakt_get_auth_statusreadCheck Trakt.tv authentication status
trakt_get_sync_statuswriteCheck status of ongoing sync operations
trakt_get_user_statsreadGet enhanced viewing statistics from Trakt.tv
trakt_searchreadSearch for movies and shows on Trakt.tv
trakt_start_scrobblingwriteEnable real-time scrobbling to Trakt.tv
trakt_sync_from_traktwriteGet watch history from Trakt.tv for comparison
trakt_sync_to_traktwriteSync Plex watch history to Trakt.tv
update_metadatawriteUpdate metadata fields for a media item (requires PLEX_ENABLE_MUTATIVE_OPS=true)
update_metadata_from_jsonwriteUpdate metadata from a JSON payload (requires PLEX_ENABLE_MUTATIVE_OPS=true)
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:35
CMD ["node", "-e", "fetch('http://127.0.0.1:'+(process.env.MCP_PORT||3000)+'/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"]
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_playlist, delete_all_libraries, delete_playlist, remove_from_playlist, remove_from_watchlist
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/docs-consistency.test.ts:14
const readme = readFileSync(new URL("../../README.md", import.meta.url), "utf8");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/ci.yml:38
if curl -fsS --max-time 2 http://127.0.0.1:3000/health -o /tmp/health.json; then
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/transport-sessions.test.ts:273
baseUrl = `http://127.0.0.1:${port}`;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @toon-format/toon, axios, dotenv, @types/node, tsx, typescript, vitest
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:174
- Server entrypoints load `.env` automatically via `dotenv/config`.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SECURITY.md:20
- API tokens (Plex, Sonarr, Radarr, Trakt) are read from environment variables and never logged
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:97
* **transport:** bound sessions and request bodies, and repair idle expiry. An unauthenticated `POST /mcp` could previously exhaust memory, and every session was torn down 300s after creation regardle
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha ab3fb262fb94full audit observations/trust-audit/mcp-server/niavasha__plex-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08ab3fb262fb94CAUTIONB89first audit
06

Questions

What is the Plex MCP server?

Plex MCP Server

What tools does Plex expose?

61 in total: 39 read-only, 17 that write, and 5 that can delete or overwrite (clear_playlist, delete_all_libraries, delete_playlist, remove_from_playlist, remove_from_watchlist). Every one is listed on this page with its risk.

Is Plex safe to connect to an agent?

With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Plex need?

It reads PLEX_TOKEN, RADARR_API_KEY, SONARR_API_KEY, TRAKT_ACCESS_TOKEN, TRAKT_CLIENT_SECRET and TRAKT_REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Plex run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as plex-mcp-server at 1.6.0.

How current is this page?

The grade is for one exact copy of the source (ab3fb262fb94), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement