Ableton LiveSAFE
MCP Server implementation for Ableton Live OSC control
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
📌 Overview
The Ableton Live MCP Server is a server implementing the Model Context Protocol (MCP) to facilitate communication between LLMs and Ableton Live. It uses OSC (Open Sound Control) to send and receive messages to/from Ableton Live. It is based on AbletonOSC implementation and exhaustively maps available OSC adresses to **tools** accessible to MCP clients.
[](https://www.youtube.com/watch?v=12MzsQ3V7cs)
This project consists of two main components:
mcp_ableton_server.py: The MCP server handling the communication between
clients and the OSC daemon.
osc_daemon.py: The OSC daemon responsible for relaying commands to Ableton
Live and processing responses.
✨ Features
- Provides an MCP-compatible API for controlling Ableton Live from MCP clients.
- Uses python-osc for sending and receiving OSC messages.
- Based on the OSC implementation from
- Implements request-response handling for Ableton Live commands.
⚡ Installation
Requirements
- Python 3.8+
python-osc(for OSC communication)fastmcp(for MCP support)uv(recommended Python package installer)- AbletonOSC as a control surface
Installation Steps
- Install
uv(https://docs.astral.sh/uv/getting-started/installation):
curl -LsSf https://astral.sh/uv/install.sh | sh
- Clone the repository:
git clone https://github.com/your-username/mcp_ableton_server.git cd mcp_ableton_server
- Install the project and its dependencies:
uv sync
- Install AbletonOSC Follow the instructions at
a1440ea84fb3OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ableton-live-mcp-server -- uvx ableton-live-mcp-server
{
"mcpServers": {
"ableton-live-mcp-server": {
"command": "uvx",
"args": [
"ableton-live-mcp-server"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_track_names | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
a1440ea84fb3full audit observations/trust-audit/mcp-server/simon-kansara__ableton-live.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | a1440ea84fb3 | SAFE | B | 89 | first audit |
Questions
What is the Ableton Live MCP server?
MCP Server implementation for Ableton Live OSC control
What tools does Ableton Live expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Ableton Live safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Ableton Live need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (a1440ea84fb3), read on 2026-10-01. The repository is watched and re-audited when it changes.