Orkas Video StudioCAUTION
Turn your coding agent into a video studio: describe a video in plain language, and your agent writes the timeline and produces the file.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Drive video composition, generation, and editing — and a fully automatic end-to-end pipeline — from your coding agent. Claude Code, Codex, Cursor: any agent that can run a shell or speak MCP can use it.
https://github.com/user-attachments/assets/13411470-06da-4f64-9bc1-fa52fe27216b
OrkasVideoStudio is not a black-box video agent. A video is expressed as a readable, diffable, re-renderable plan (plan.json) that your agent — and you — can edit; change one line and only that piece re-renders. The agent is the brain; this project ships the knowledge (what makes a good video, and which production line to take), the deterministic capabilities (render / edit / transcribe / generate — thin wrappers over `hyperframes`, ffmpeg, and whisper.cpp), and that editable IR.
You talk to your agent in plain language — "make a 60-second vertical explainer on vector databases with a Chinese voiceover and captions" — and it reads the material, writes the timeline, and produces the file.
The four production lines
Three orthogonal capability axes, plus an automatic pipeline that weaves them together:
- Compose — script → designed HTML motion graphics → mp4. Explainers, kinetic typography,
lower-thirds, data viz, title cards, transitions. No paid keys.
- Edit — cut / join / trim-silence / de-filler / mix / burn-in subtitles / dub / localize
real footage you supply, plus highlight selection over long recordings. No paid keys.
- Generate — talking-head or cinematic AI footage and imagery via your own provider
keys (BYO — OpenAI, Gemini, Doubao; no managed backend, no lock-in).
- Auto (end-to-end) — when a deliverable needs more than one axis, the agent routes to a
single cross-modal plan.json: stage-plan builds the EDL, stage-assemble walks it and delegates each segment back to compose / generate / edit, and a deterministic **delive
99801e3a7456OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add video-studio-tools --env MUAPI_API_KEY=${MUAPI_API_KEY} --env OVS_IMAGE_API_KEY=${OVS_IMAGE_API_KEY} --env OVS_TTS_API_KEY=${OVS_TTS_API_KEY} --env OVS_VIDEO_API_KEY=${OVS_VIDEO_API_KEY} -- npx -y @orkas/[email protected]{
"mcpServers": {
"video-studio-tools": {
"command": "npx",
"args": [
"-y",
"@orkas/[email protected]"
],
"env": {
"MUAPI_API_KEY": "${MUAPI_API_KEY}",
"OVS_IMAGE_API_KEY": "${OVS_IMAGE_API_KEY}",
"OVS_TTS_API_KEY": "${OVS_TTS_API_KEY}",
"OVS_VIDEO_API_KEY": "${OVS_VIDEO_API_KEY}"
}
}
}
}Exposed tools (65)
41 read · 20 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
burnsubs | read | Burn an .srt/.ass subtitle file into the picture. |
check | read | Final browser/runtime/layout QA; includes lint. |
composition | read | Prepare or reconcile a manifest-owned HyperFrames composition. |
composition_prepare | write | Create a HyperFrames scaffold from composition-manifest.json without overwriting authored HTML. |
composition_reconcile | write | Apply manifest timing/audio metadata while preserving authored visual content. |
concat | read | Join clips (comma-separated --inputs). |
doctor | read | Check that Node.js 22+ and ffmpeg/ffprobe are available. |
draft | write | Run the VideoStudio draft gate, backed by HyperFrames render. |
edit | write | Edit real footage with ffmpeg (probe/trim/concat/burnsubs/overlay/extract-frame/loudness/mix). |
edit_burnsubs | write | Burn an .srt/.ass subtitle file into the picture. |
edit_concat | write | Join clips that share stream layout. |
edit_extract_frame | write | Save a still frame at a timestamp. |
edit_loudness | write | Measure integrated loudness / true peak. |
edit_mix | write | Lay timed audio segments onto a base video, then loudness-normalize. |
edit_normalize_loudness | write | Normalize audio loudness and write a new media file. |
edit_overlay | write | Composite an overlay image/video at (x,y). |
edit_probe | write | Probe duration/resolution/fps/audio. |
edit_remove_fillers | destructive | Drop filler words ( |
edit_trim | write | Cut [start, start+duration] (or [start, end]) into a new clip. |
edit_trim_silence | destructive | Drop silent gaps (deterministic auto-cut → tightened jump-cut); returns auditable evidence. |
extract-frame | write | Save a still frame at a timestamp. |
fit | read | Check narration text against an immutable target duration. |
gate | read | Resolve one canonical review/approval transition. |
gate_transition | read | Resolve the single canonical review/approval transition without performing it. |
get_skill | read | Print one skill’s full instructions. |
image | read | Generate an image via your configured image provider (BYO key). |
inspect | read | Deprecated alias for check. |
lint | read | Fast structural QA of a composition (HyperFrames lint). |
list_skills | read | List the available video skills. |
loudness | read | Measure integrated loudness / true peak. |
mix | read | Lay timed audio onto a base video (--segments JSON). |
narration | read | Plan and verify narration timing before or after synthesis. |
narration_fit | read | Check narration text against an immutable target duration before or after synthesis. |
normalize-loudness | write | Normalize audio loudness and write a new media file. |
overlay | read | Composite an overlay image/video at (x,y). |
ovs | write | OrkasVideoStudio — drive video compose/edit/generate from your coding agent. |
ovs_doctor | read | Check that Node.js 22+ and ffmpeg/ffprobe are available. |
plan | read | Work with the plan.json video IR. |
plan_promise_check | read | Production-method-aware delivery guard. Direct generation checks readability; local assembly checks the complete plan contract. Set probe_produced to assess the REAL produced cut. |
plan_rank_takes | read | De-duplicate repeated takes (same line recorded several times) and pick the best of each by quality. |
plan_summarize | read | Render a human-readable timeline of a plan.json. |
plan_validate | read | Validate a plan.json (structure, promise consistency, and the configured video provider\ |
prepare | write | Create index.html from composition-manifest.json without overwriting authored HTML. |
probe | read | Probe duration/resolution/fps/audio. |
promise-check | read | Production-method-aware delivery guard; exit 1 on a fail verdict. |
quality | read | Score footage quality (blur/exposure/black/freeze) → flags + 0..1 score. |
rank-takes | read | De-duplicate repeated takes and pick the best (reads a takes.json). |
reconcile | write | Apply manifest timing/audio metadata while preserving authored visuals. |
remove-fillers | destructive | Drop filler words (um/uh) using a transcript JSON; returns evidence. |
render | read | Render a composition with the packaged HyperFrames runtime. |
scenes | read | Detect scene/shot boundaries → cut candidates (for reducing long footage). |
silence | read | Detect silent spans (ffmpeg silencedetect). |
skill | read | Print one skill’s full instructions. |
skills | write | List or install the video skill pack. |
snapshot | read | Capture hook, per-scene, and payoff preview frames plus a contact sheet. |
speak | read | Synthesize narration to audio via your configured TTS provider. |
speech-capabilities | read | Show the configured executable BYO narration profile without exposing secrets. |
speech_capabilities | read | Show the configured executable BYO narration profile without exposing secrets. |
summarize | read | Print a human-readable timeline of a plan.json. |
transcribe | read | Transcribe speech (packaged HyperFrames / whisper.cpp). |
transition | read | Map explicit user authority and artifact state to one next action. |
trim | write | Cut [start, start+duration] (or [start, end]). |
trim-silence | destructive | Drop silent gaps (deterministic auto-cut → tightened jump-cut); returns evidence. |
validate | read | Validate a plan.json (structure, promise, and the configured video provider); exit 1 on errors. |
video | read | Generate a video clip via your configured video provider (BYO key). |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
- If `ovs speak` fails, never silently continue: tell the user, then either fix and retry the narration or explicitly proceed silent with that stated at the gate.
edit_remove_fillers, edit_trim_silence, remove-fillers, trim-silence
const cliDist = fileURLToPath(new URL('../../cli/dist/index.js', import.meta.url));const mcpDist = fileURLToPath(new URL('../../mcp/dist/index.js', import.meta.url));const cli = fileURLToPath(new URL('../../cli/dist/index.js', import.meta.url));baseUrl: `http://127.0.0.1:${port}`,baseUrl = `http://127.0.0.1:${(server.address() as AddressInfo).port}`;- run: sudo apt-get update && sudo apt-get install -y ffmpeg
@types/node, typescript, vitest
citty, typescript
typescript
@modelcontextprotocol/sdk, zod, typescript
typescript
Gates applied: instruction_override, no_behavioural_pass.
99801e3a7456full audit observations/trust-audit/mcp-server/orkas-ai__orkas-video-studio.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 99801e3a7456 | CAUTION | C | 79 | first audit |
Questions
What is the Orkas Video Studio MCP server?
Turn your coding agent into a video studio: describe a video in plain language, and your agent writes the timeline and produces the file.
What tools does Orkas Video Studio expose?
65 in total: 41 read-only, 20 that write, and 4 that can delete or overwrite (edit_remove_fillers, edit_trim_silence, remove-fillers, trim-silence). Every one is listed on this page with its risk.
Is Orkas Video Studio safe to connect to an agent?
With care. The audit graded it C (79/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Orkas Video Studio need?
It reads MUAPI_API_KEY, OVS_IMAGE_API_KEY, OVS_TTS_API_KEY and OVS_VIDEO_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Orkas Video Studio run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @orkas/video-studio-tools at 2026.9.10.
How current is this page?
The grade is for one exact copy of the source (99801e3a7456), read on 2026-09-29. The repository is watched and re-audited when it changes.