Atlas / MCP servers / verygoodplugins / Stream Deck

Stream DeckCAUTION

mcp/verygoodplugins/stream-deck

MCP server for Elgato Stream Deck control — set buttons, manage pages, wire actions

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
11 4r · 3w · 4d
Transport
stdio
License
MIT
Stars
51
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Stream Deck MCP

Stream Deck MCP lets agents build and reconfigure real Elgato Stream Deck profiles.

Quick Start · Demo · Features · Tools · Development

Tell your AI what Stream Deck you want. Get back a polished profile with buttons, icons, colors, dials, touch-strip art, and the shell scripts behind it. Stream Deck MCP writes the same profile format the Elgato desktop app already uses, so agents can author real local decks without making you build a Stream Deck plugin first.

It works with Claude Desktop, Claude Code, Cursor, Codex, and any MCP client that can launch a stdio server.

Quick Start

Claude Code:

claude mcp add streamdeck -- uvx streamdeck-mcp

Claude Desktop, Cursor, Codex, and other MCP clients can use the same command:

{
"mcpServers": {
"streamdeck": {
"command": "uvx",
"args": ["streamdeck-mcp"]
}
}
}

Then ask your agent for a deck:

Make me a Slack control board for my Stream Deck + XL.

For Claude Code, install the bundled designer skill for better layout, palette, hardware, and plugin-action guidance:

uvx --from streamdeck-mcp streamdeck-mcp-install-skill

Demo

Product trailer generated with Remotion, showing hardware inventory, plugin discovery, configured action reuse, and a final Stream Deck + XL reveal.

Features

  • Profile-native authoring - reads and writes Elgato ProfilesV3 files directl
Read from source at commit e74975bb939dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add streamdeck-mcp -- None streamdeck-mcp==0.3.0
03

Exposed tools (11)

4 read · 3 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
streamdeck_clear_alldestructiveClear all buttons on the current page
streamdeck_clear_buttondestructiveClear a button (remove image and text)
streamdeck_create_pagewriteCreate a new button page/profile
streamdeck_delete_pagedestructiveDelete a page (cannot delete
streamdeck_disconnectdestructiveDisconnect from Stream Deck and reset it
streamdeck_get_buttonreadGet the current configuration of a button
streamdeck_list_devicesreadList attached Stream Deck devices without requiring an active connection
streamdeck_list_pagesreadList all available pages
streamdeck_restart_appwriteRestart the macOS Stream Deck desktop app after profile changes.
streamdeck_set_brightnesswriteSet the Stream Deck screen brightness
streamdeck_switch_pagereadSwitch to a different button page
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

MEDIUMInventory / provenance · inv.binary · CWE-1104
trailer/public/audio/deep-hit.wav
deep-hit.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
trailer/public/audio/final-impact.wav
final-impact.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
trailer/public/audio/switch-hit.wav
switch-hit.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
trailer/public/audio/ui-click.wav
ui-click.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
trailer/public/audio/whoosh.wav
whoosh.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
streamdeck_clear_all, streamdeck_clear_button, streamdeck_delete_page, streamdeck_disconnect
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
trailer/package.json
vitest
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
streamdeck_assets/skill/streamdeck-designer/references/integrations.md:149
**If not**: user provides the URL + a long-lived access token (Profile → Security → Long-Lived Access Tokens).
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
streamdeck_assets/skill/streamdeck-designer/references/integrations.md:315
- For production-level secrecy, suggest the macOS Keychain (`security find-generic-password`) or 1Password CLI (`op read`) as alternatives to `.env`.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
streamdeck_assets/skill/streamdeck-designer/references/patterns.md:82
- Key 23: Open `.env` or config file.
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
docs/screenshots/slack-control-board.jpg
docs/screenshots/slack-control-board.jpg
Why it matters. 1419296 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
streamdeck_assets/materialdesignicons-webfont.ttf
streamdeck_assets/materialdesignicons-webfont.ttf
Why it matters. 1307660 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
trailer/public/audio/synth-bed.wav
trailer/public/audio/synth-bed.wav
Why it matters. 1984544 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
trailer/public/images/slack-control-board.jpg
trailer/public/images/slack-control-board.jpg
Why it matters. 1419296 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e74975bb939dfull audit observations/trust-audit/mcp-server/verygoodplugins__stream-deck.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e74975bb939dCAUTIONB85first audit
06

Questions

What is the Stream Deck MCP server?

MCP server for Elgato Stream Deck control — set buttons, manage pages, wire actions

What tools does Stream Deck expose?

11 in total: 4 read-only, 3 that write, and 4 that can delete or overwrite (streamdeck_clear_all, streamdeck_clear_button, streamdeck_delete_page, streamdeck_disconnect). Every one is listed on this page with its risk.

Is Stream Deck safe to connect to an agent?

With care. The audit graded it B (85/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Stream Deck need?

No credential environment variables were found in its source, so it appears to need none.

How does Stream Deck run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as trailer at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (e74975bb939d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement