StrudelCAUTION
A Model Context Protocol (MCP) server that gives Claude direct control over Strudel.cc for AI-assisted music generation and live coding.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
🎵 MCP server for AI-assisted live-coding music via strudel.cc Unofficial fan project. Not affiliated with, or endorsed by, the Strudel project. This adapter exists to make live-coding music accessible to beginners who want to try pattern-based music without learning the whole ecosystem first. Status: Beta | 88% statement coverage | Published to npm | Actively developed
[](https://github.com/williamzujkowski/live-coding-music-mcp/actions) [](https://www.npmjs.com/package/@williamzujkowski/live-coding-music-mcp) [](https://nerq.ai/kya/live-coding-music-mcp) []() [](LICENSE)
A Model Context Protocol (MCP) server that drives Strudel.cc from Claude for AI-assisted live-coding music, pattern generation, and algorithmic composition.
Current State: Beta. The core workflow (init → compose → playback → analyze) works reliably with real audio output. npm test reports ~3060 passing tests, 88.99% statement coverage / 79.99% branch coverage. CI is hardened with OpenSSF Scorecard, SHA-pinned actions, CODEOWNERS, Dependabot, and lint as a blocking gate.
What "Beta" means here:
- Tool schemas are stable within minor versions; breaking changes require a major bump
- Multi-session is supported as of
0cab11a8cb56OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add live-coding-music-mcp --env GEMINI_API_KEY=${GEMINI_API_KEY} --env STRUDEL_SECRET_PROBE=${STRUDEL_SECRET_PROBE} -- npx -y @williamzujkowski/[email protected]{
"mcpServers": {
"live-coding-music-mcp": {
"command": "npx",
"args": [
"-y",
"@williamzujkowski/[email protected]"
],
"env": {
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"STRUDEL_SECRET_PROBE": "${STRUDEL_SECRET_PROBE}"
}
}
}
}Exposed tools (28)
20 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
ai_assist | read | Gemini-backed pattern assistance. |
analyze | read | Audio analysis on the currently-playing pattern. |
analyze_pattern_local | read | Static analysis (events/cycle, complexity, optional BPM) without browser playback |
audio_capture | read | Record audio output from the live Strudel session. |
browser_window | read | Interact with the visible Strudel browser window. |
compose | write | Generate, write, and play a complete pattern in one step. Auto-initializes default browser if needed. |
diagnostics | read | Inspect server and browser state. |
edit_pattern | write | Mutate the current session pattern. |
effect | destructive | Add or remove a Strudel effect on the current session pattern. |
export_audio | write | Record a window of live Strudel audio and write it to a file. |
export_midi | read | Export current pattern to MIDI file. Parses note(), n(), and chord() functions. |
generate_part | read | Generate a single instrumental layer and append it to the current session pattern. |
generate_rhythm | read | Generate a rhythmic pattern and append it to the current session. |
get_pattern | read | Get current pattern code |
history | write | Navigate or inspect the pattern edit history. |
import_midi | write | Convert a .mid file into a playable Strudel pattern (Phase 1: literal transcription, #201). |
init | read | Initialize Strudel in browser |
music_theory | read | Music-theory queries. |
pattern_store | read | Persist patterns to disk and read them back. |
playback | read | Control transport on the current session. |
query_pattern_events | read | Enumerate events the pattern would emit between two cycle indices (max 16 cycles) |
session | read | Manage isolated Strudel browser sessions (multi-session, #108). |
set_tempo | write | Set BPM. Writes setcpm(bpm/4), assuming one bar of 4/4 per cycle. |
shape | read | Shape the current pattern along one of three high-level dimensions. |
transform | write | Apply a single transform op to the current session pattern. |
transpile_pattern | read | Transpile pattern source via StrudelEngine; returns transpiled code or syntax error |
validate_pattern_local | read | Validate pattern syntax against the local StrudelEngine, which runs in a sandboxed child process (no browser required) |
validate_pattern_runtime | read | Validate pattern with runtime error checking (monitors Strudel console for errors) |
Trust audit
CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- none-observed
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (15)
apiKey: 'invalid-api-key-12345'
effect
SafePath.test.ts
.eslintrc.cjs
text: () => 'new Function("return 1")'['Function', `Function('return process')(); s('bd')`],expect(result.errors).toContain('Use of eval() or Function() is not allowed');const result = validator.validate('new Function("return s(\\"bd*4\\")")');expect(result.errors).toContain('Use of eval() or Function() is not allowed');const escape = await service.exportAudio(page, { duration: 300, filename: '../../../../tmp/pwned' });import { StrudelController } from '../../StrudelController.js';import { IsolatedStrudelEngine } from '../../services/IsolatedStrudelEngine.js';import { AudioAnalyzer } from '../../AudioAnalyzer';import { AudioCaptureService } from '../../services/AudioCaptureService';@google/generative-ai, @modelcontextprotocol/sdk, @tonejs/midi, google-auth-library, playwright, @types/jest, @types/node, @typescript-eslint/eslint-plugin
Gates applied: no_behavioural_pass.
0cab11a8cb56full audit observations/trust-audit/mcp-server/williamzujkowski__strudel.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 0cab11a8cb56 | CAUTION | B | 84 | first audit |
Questions
What is the Strudel MCP server?
A Model Context Protocol (MCP) server that gives Claude direct control over Strudel.cc for AI-assisted music generation and live coding.
What tools does Strudel expose?
28 in total: 20 read-only, 7 that write, and 1 that can delete or overwrite (effect). Every one is listed on this page with its risk.
Is Strudel safe to connect to an agent?
With care. The audit graded it B (84/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Strudel need?
It reads GEMINI_API_KEY and STRUDEL_SECRET_PROBE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Strudel run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @williamzujkowski/live-coding-music-mcp at 4.0.0.
How current is this page?
The grade is for one exact copy of the source (0cab11a8cb56), read on 2026-10-06. The repository is watched and re-audited when it changes.