PlexCAUTION
Plex MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to your Plex Media Server, Sonarr, Radarr, and Trakt.tv — all from a single unified server.
[](https://www.typescriptlang.org/) [](https://nodejs.org/) [](https://modelcontextprotocol.io/) [](https://opensource.org/licenses/MIT)
What is this?
This MCP server transforms your Plex Media Server into an AI-queryable database. Ask your AI assistant questions like:
- "What movies have I watched recently?"
- "Show me my viewing statistics for the past month"
- "What's the most popular content on my server?"
- "Find action movies in my library"
- "What's on my continue watching list?"
- "Add that new show to Sonarr"
- "What's in my download queue?"
- "Sync my watch history to Trakt"
- "Recommend me some movies I haven't seen"
Features
46 tools out of the box (58 with write operations enabled):
- Plex Library Management — Browse libraries, search media, get detailed metadata, list playlists and watchlist
- Tautulli-Style Analytics — Viewing statistics, user activity, popular content, watch history
- Personalized Recommendations — AI-powered movie suggestions based on your watch history, genres, directors, and actors. Supports per-user profiles for multi-user Plex servers.
- Sonarr/Radarr Integration — Browse, search, add series/movies, view queues, trigger downloads
- Trakt.tv Sync — OAuth au
ab3fb262fb94OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add plex-mcp-server --env PLEX_TOKEN=${PLEX_TOKEN} --env RADARR_API_KEY=${RADARR_API_KEY} --env SONARR_API_KEY=${SONARR_API_KEY} --env TRAKT_ACCESS_TOKEN=${TRAKT_ACCESS_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"plex-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"PLEX_TOKEN": "${PLEX_TOKEN}",
"RADARR_API_KEY": "${RADARR_API_KEY}",
"SONARR_API_KEY": "${SONARR_API_KEY}",
"TRAKT_ACCESS_TOKEN": "${TRAKT_ACCESS_TOKEN}"
}
}
}
}Exposed tools (61)
39 read · 17 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_to_playlist | write | Add a media item to a playlist (requires PLEX_ENABLE_MUTATIVE_OPS=true) |
add_to_watchlist | write | Add a local Plex movie or show to the account watchlist (requires PLEX_ENABLE_MUTATIVE_OPS=true) |
arr_get_status | read | Check connection status of Sonarr and Radarr services |
clear_playlist | destructive | Clear all items from a playlist (preview unless confirm=true; requires PLEX_ENABLE_MUTATIVE_OPS=true) |
create_playlist | write | Create a new Plex playlist (requires PLEX_ENABLE_MUTATIVE_OPS=true). |
delete_all_libraries | destructive | x |
delete_playlist | destructive | Delete a Plex playlist without deleting the underlying media (requires PLEX_ENABLE_MUTATIVE_OPS=true) |
export_library | read | Export a full library to a JSON file (within ./exports) |
get_active_sessions | read | Get currently active Plex streams — who is watching what right now, |
get_editable_fields | read | Get editable fields and available tags for a media item |
get_fully_watched | read | Get all fully watched movies and shows from a library |
get_libraries | read | x |
get_library_items | read | List items in a library with pagination (useful for large libraries) |
get_library_stats | read | Get library-specific statistics |
get_media_details | read | Get detailed information about a specific media item |
get_on_deck | read | Get on deck (continue watching) items |
get_playlist_items | read | Get items in a Plex playlist |
get_playlists | read | Get all Plex playlists |
get_popular_content | read | Get most popular content by plays or duration |
get_recently_added | read | Get recently added media |
get_recently_watched | read | Get recently watched movies and shows |
get_recommendations | read | Get personalized movie recommendations from your Plex library based on watch history. |
get_user_stats | read | Get user-specific watch statistics |
get_watch_history | read | Get detailed watch history with session information |
get_watch_stats | read | Get comprehensive watch statistics (Tautulli-style analytics) |
get_watchlist | read | Get the user |
mark_unwatched | read | Mark a Plex media item as unwatched (requires PLEX_ENABLE_MUTATIVE_OPS=true) |
mark_watched | read | Mark a Plex media item as watched (requires PLEX_ENABLE_MUTATIVE_OPS=true) |
ping | read | ping |
radarr_add_movie | write | Add a new movie to Radarr by TMDB ID |
radarr_get_calendar | read | Get upcoming movies from the Radarr calendar |
radarr_get_missing | read | Get missing/wanted movies from Radarr |
radarr_get_movies | read | List all movies in Radarr with optional title filter |
radarr_get_profiles | read | Get Radarr quality profiles and root folders (needed before adding movies) |
radarr_get_queue | read | Get the current Radarr download queue |
radarr_search | write | Search TMDB for new movies to add to Radarr |
radarr_trigger_search | write | Trigger a search for missing movies, optionally for a specific movie |
rate_media | write | Set the user |
remove_from_playlist | destructive | Remove an item from a playlist (requires PLEX_ENABLE_MUTATIVE_OPS=true) |
remove_from_watchlist | destructive | Remove a movie or show from the account watchlist by global Plex GUID or local rating key (requires PLEX_ENABLE_MUTATIVE_OPS=true) |
search_media | read | Search for media in Plex libraries |
some_future_tool | read | x |
sonarr_add_series | write | Add a new series to Sonarr by TVDB ID |
sonarr_get_calendar | read | Get upcoming episodes from the Sonarr calendar |
sonarr_get_missing | read | Get missing/wanted episodes from Sonarr |
sonarr_get_profiles | read | Get Sonarr quality profiles and root folders (needed before adding series) |
sonarr_get_queue | read | Get the current Sonarr download queue |
sonarr_get_series | read | List all series in Sonarr with optional title filter |
sonarr_search | write | Search TheTVDB for new series to add to Sonarr |
sonarr_trigger_search | write | Trigger a search for missing episodes, optionally for a specific series |
trakt_authenticate | write | Start Trakt.tv OAuth authentication process |
trakt_complete_auth | read | Complete Trakt.tv authentication with authorization code |
trakt_get_auth_status | read | Check Trakt.tv authentication status |
trakt_get_sync_status | write | Check status of ongoing sync operations |
trakt_get_user_stats | read | Get enhanced viewing statistics from Trakt.tv |
trakt_search | read | Search for movies and shows on Trakt.tv |
trakt_start_scrobbling | write | Enable real-time scrobbling to Trakt.tv |
trakt_sync_from_trakt | write | Get watch history from Trakt.tv for comparison |
trakt_sync_to_trakt | write | Sync Plex watch history to Trakt.tv |
update_metadata | write | Update metadata fields for a media item (requires PLEX_ENABLE_MUTATIVE_OPS=true) |
update_metadata_from_json | write | Update metadata from a JSON payload (requires PLEX_ENABLE_MUTATIVE_OPS=true) |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
CMD ["node", "-e", "fetch('http://127.0.0.1:'+(process.env.MCP_PORT||3000)+'/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"]clear_playlist, delete_all_libraries, delete_playlist, remove_from_playlist, remove_from_watchlist
.release-please-manifest.json
const readme = readFileSync(new URL("../../README.md", import.meta.url), "utf8");if curl -fsS --max-time 2 http://127.0.0.1:3000/health -o /tmp/health.json; then
baseUrl = `http://127.0.0.1:${port}`;@modelcontextprotocol/sdk, @toon-format/toon, axios, dotenv, @types/node, tsx, typescript, vitest
- Server entrypoints load `.env` automatically via `dotenv/config`.
- API tokens (Plex, Sonarr, Radarr, Trakt) are read from environment variables and never logged
* **transport:** bound sessions and request bodies, and repair idle expiry. An unauthenticated `POST /mcp` could previously exhaust memory, and every session was torn down 300s after creation regardle
Gates applied: no_behavioural_pass.
ab3fb262fb94full audit observations/trust-audit/mcp-server/niavasha__plex-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ab3fb262fb94 | CAUTION | B | 89 | first audit |
Questions
What is the Plex MCP server?
Plex MCP Server
What tools does Plex expose?
61 in total: 39 read-only, 17 that write, and 5 that can delete or overwrite (clear_playlist, delete_all_libraries, delete_playlist, remove_from_playlist, remove_from_watchlist). Every one is listed on this page with its risk.
Is Plex safe to connect to an agent?
With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Plex need?
It reads PLEX_TOKEN, RADARR_API_KEY, SONARR_API_KEY, TRAKT_ACCESS_TOKEN, TRAKT_CLIENT_SECRET and TRAKT_REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Plex run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as plex-mcp-server at 1.6.0.
How current is this page?
The grade is for one exact copy of the source (ab3fb262fb94), read on 2026-10-08. The repository is watched and re-audited when it changes.