FL StudioSAFE
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This is an MCP server that connects Claude to FL Studio.
Made this in 3 days. We're open sourcing it to see what we can actually get out of it. The possibilities are endless.
If you're running to any issues, join our discord and we can setup it for you.
(also join if you interested in the future of music and AI or want to request features. we're building this with you)
https://discord.gg/ZjG9TaEhvy
Check out our AI-Powered DAW for musicians at www.veena.studio
All in browser. All for free.
Step 1: Download the Files
You should see two main items.
- A folder called Test Controller
- A python file called trigger.py
The Test Controller folder has a file called device_test.py that receives information from the MCP server. trigger.py is the MCP server.
Place the Test Controller folder in Image-Line/FL Studio/Settings/Hardware (Don't change the name of this file or folder)
Step 2: Set up MCP for Claude
Follow this tutorial to see how to setup MCP servers in Claude by edyting the claudedesktopconfig files.
https://modelcontextprotocol.io/quickstart/server
If you followed this process, make sure to change whatever mentions of weather.py to trigger.py
If the Hammer icon doesn't show up, open Task Manager and force close the Claude process.
It should then show up.
This is what my config file looks like
Step 3: Set Up Virtual MIDI Ports
For Windows
For Windows, download LoopMIDI from here.
https://www.tobias-erichsen.de/software/loopmidi.html
Install LoopMIDI and add a port using the + button.
This is what mine looks like:
For Mac
Your MIDI Ports would be automatically setup to receive data.
Step 4: Setup MIDI Controller
Open FL Studio.
Go To Options > MIDI Settings.
In the Input Tab, click the MIDI Input you just created with LoopM
2b899ac9879cOBSERVED · 2026-10-07Exposed tools (5)
1 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
list_midi_ports | read | List all available MIDI input ports |
play | write | Send MIDI message to start playback in FL Studio |
send_melody | write | |
send_midi_note | write | Send a MIDI note on/off message with specified duration |
stop | write | Send MIDI message to stop playback in FL Studio |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
Gates applied: no_behavioural_pass, no_license.
2b899ac9879cfull audit observations/trust-audit/mcp-server/veenastudio__fl-studio.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 2b899ac9879c | SAFE | B | 89 | first audit |
Questions
What tools does FL Studio expose?
5 in total: 1 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is FL Studio safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does FL Studio need?
No credential environment variables were found in its source, so it appears to need none.
How does FL Studio run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (2b899ac9879c), read on 2026-10-07. The repository is watched and re-audited when it changes.