DJ ClaudeBLOCK
DJ Claude — the only music MCP server with multi-agent collaboration
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
_ _ _ _ __| |(_) ___ | | __ _ _ _ __| | ___ / _` || | / __| | | / _` || | | |/ _` | / _ \ | (_| || | _ | (__ | || (_| || |_| | (_| || __/ \__,_|| | (_) \___| |_| \__,_| \__,_|\__,_| \___| _/ | |__/
The live music engine for AI agents.
[](https://www.npmjs.com/package/dj-claude) [](LICENSE) [](https://github.com/p-poss/dj-claude)
About
DJ Claude is the only music MCP server with multi-agent collaboration. Multiple AI agents connect over HTTP and jam together in real-time — one adds drums, another layers bass, a third drops a melody — and everything composes automatically. It works in your terminal, browser, or as a Claude Code plugin with slash commands. No browser tab, no API key, no external services required.
Under the hood, DJ Claude uses Strudel — a live coding environment for music — to generate and play patterns in real time. 20 MCP tools, 3 resources, conductor mode, mix snapshots, 22 presets, and 8 vibes. Agents can make music for you, themselves, and each other while they work.
Why DJ Claude?
- Multi-agent jam sessions — the first music MCP where multiple agents connect over HTTP and build music together in real-time, each adding layers that compose automatically
- Zero dependencies — no browser tab, no API key, no external services. Every tool works out of the box
- Claude Code plugin — one-step install from the marketplace with 20 slash commands
- Conductor mode — orchestrate a full band from a single directive, with auto-detected templates (jazz combo, rock band, electro
7fdb119f30e5OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add dj-claude -- npx -y [email protected]
claude mcp add dj-claude -- npx -y [email protected]
Exposed tools (24)
17 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
ASMR | read | Soft, whispery |
Claude | read | Warm, articulate |
Default | read | Warm, calm |
Robot | read | Robotic, vintage |
conduct | read | Orchestrate a full band — generates multiple layers at once from a single directive. Works without an API key when you provide |
conduct_evolve | read | Evolve all active layers through multiple stages — each layer gets modified 20-40% per stage with pauses between. Works without an API key when you provide |
export_code | read | Export the current Strudel code with header comments showing date and layer names. No API key needed. |
hush | write | Stop all music playback immediately. |
jam | write | Add or update a single layer in a collaborative jam session. Each layer has a role (drums, bass, melody, etc.) and layers are composed together with stack(). Works without an API key when you provide |
jam_clear | destructive | Remove one or all layers from the jam session. If no role is specified, all layers are cleared. |
jam_preview | read | Preview what a jam layer would sound like without actually adding it. Generates code but does NOT evaluate, store, or play it. Works without an API key when you provide |
jam_status | read | Show all active layers in the current jam session with their role names and code. |
live_mix | write | Autonomous DJ set — generates and evolves music through multiple stages with ~20s between each. Works without an API key when you provide |
mix_analysis | read | Analyze the current jam mix — detects octave ranges, effects, gain levels, and frequency band occupancy across all layers. Returns suggestions for improving the mix. No API key needed. |
now_playing | read | Check what music is currently playing, including the Strudel code and DJ commentary. |
play_music | read | Generate and play live music. Works without an API key when you provide |
play_preset | read | Play from the curated pattern library. No API key needed. Call without arguments to list all available presets. |
play_strudel | read | |
set_context | write | Tell DJ Claude what you\ |
set_vibe | write | Instantly set the musical vibe to match a mood. Great for matching music to the current coding task. Works without an API key using built-in patterns. If you want more creative/custom music and can write Strudel code yourself, prefer play_strudel instead. |
snapshot_list | read | List all saved mix snapshots. No API key needed. |
snapshot_load | read | Restore a previously saved mix snapshot — loads all layers and resumes playback. No API key needed. |
snapshot_save | write | Save the current mix (all layers + composed code) as a named snapshot. No API key needed. |
switch_audio | read | Switch the audio backend at runtime between Node (terminal) and Browser (higher quality, opens a browser tab). |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
exec(cmd, (err) => {const url = `http://127.0.0.1:${this.port}?autoplay`;console.error(`[dj-claude-http] MCP HTTP server listening on http://127.0.0.1:${port}/mcp`);const resp = await httpGet(`http://127.0.0.1:${port}/`);const resp404 = await httpGet(`http://127.0.0.1:${port}/nonexistent`);jam_clear
cli/README.md
"url": "http://127.0.0.1:4321/mcp"
@anthropic-ai/sdk, @modelcontextprotocol/sdk, dotenv, express, ink, ink-text-input, node-web-audio-api, react
@anthropic-ai/sdk, @strudel/web, @upstash/ratelimit, @upstash/redis, @tailwindcss/postcss, @types/node, @types/react, @types/react-dom
Gates applied: no_behavioural_pass.
7fdb119f30e5full audit observations/trust-audit/mcp-server/p-poss__dj-claude.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 7fdb119f30e5 | BLOCK | D | 69 | first audit |
Questions
What is the DJ Claude MCP server?
DJ Claude — the only music MCP server with multi-agent collaboration
What tools does DJ Claude expose?
24 in total: 17 read-only, 6 that write, and 1 that can delete or overwrite (jam_clear). Every one is listed on this page with its risk.
Is DJ Claude safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does DJ Claude need?
It reads ANTHROPIC_API_KEY, DJ_CLAUDE_MAX_TOKENS, ELEVENLABS_API_KEY, NEXT_PUBLIC_TURNSTILE_SITE_KEY, TURNSTILE_SECRET_KEY and UPSTASH_REDIS_REST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does DJ Claude run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as dj-claude at 0.1.18.
How current is this page?
The grade is for one exact copy of the source (7fdb119f30e5), read on 2026-10-09. The repository is watched and re-audited when it changes.