Ableton CopilotSAFE
An MCP server built on ableton-js enables AI assistants to control Ableton Live in real time, including Arrangement View operations such as song management, track control, MIDI editing, and audio recording, along with other capabilities.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP (Model Context Protocol) server built on ableton-js for real-time interaction and control with Ableton Live's Arrangement View, dedicated to assisting music producers in their music production.
🎯 Note
As a music producer, I have some understanding of using Ableton for music creation. During the creative process, we often need to handle various tedious operations, such as humanizing note properties, merging notes, recording one track to another audio track, etc. Previously, we could only rely on the functions provided by the host DAW for these operations. However, with the emergence of large language models and MCP, we now have the possibility to let AI help us with automation. Although it's still not realistic for AI to directly generate notes or create a complete song (it can't generate a good-sounding song), having AI assist us with auxiliary operations presents a new possibility.
🎥 Demo
This is a simple demonstration video of MIDI operations.
https://github.com/user-attachments/assets/8d635c4c-a1f2-44be-93ae-062038d14c71
🚀 Features
🎵 Song Control
- Get basic song information (root note, scale name, tempo, song length, etc.)
- Get a list of all tracks
- Create MIDI, audio, and return tracks
- Delete and duplicate tracks
🎹 Track Management
- Get all clips in a track
- Create empty MIDI clips in the arrangement view tracks
- Create audio clips in tracks based on provided sample file paths
- Set track properties (mute, color, name, arm, solo, etc.)
- Duplicate MIDI clips to specified tracks
🎼 Clip Oper
89676262e15dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ableton-copilot-mcp -- npx -y @xiaolaa2/[email protected]
{
"mcpServers": {
"ableton-copilot-mcp": {
"command": "npx",
"args": [
"-y",
"@xiaolaa2/[email protected]"
]
}
}
}Exposed tools (37)
14 read · 18 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_notes_to_clip | write | Add notes to clip by clip id |
create_clips_batch | write | Batch version of create_midi_clip - creates multiple empty MIDI clips across one or more tracks in one call. Each entry is isolated - one failure doesn |
create_midi_clip | write | Creates an empty MIDI clip on the track and returns the created clip information |
create_track | write | create track and return raw track |
crop_clip | read | Crops the clip. The region that is cropped depends on whether the clip is looped or not. If looped, the region outside of the loop is removed. If not looped, the region outside the start and end markers is removed. |
delete_clip | destructive | delete clip by id |
delete_device | destructive | delete device by index, start from 0 |
delete_track | destructive | delete track by index |
duplicate_clip_loop | read | Makes the loop twice as long and duplicates notes and envelopes. Duplicates the clip start/end range if the clip is not looped. |
duplicate_clip_to_track | read | duplicate clip to track and return the duplicated clip information |
duplicate_track | read | duplicate midi or audio track by index |
get_application_info | write | Get Ableton Live application information. To get specific properties, set the corresponding property name to true in the properties parameter. If no properties are specified, returns all available information. |
get_clip_properties | write | Get clip properties by clip id. To get specific properties, set the corresponding property name to true in the properties parameter. |
get_device_properties | write | get device properties. To get specific properties, set the corresponding property name to true in the properties parameter |
get_operation_histories | read | get mcp tools operation histories by page |
get_snapshot_by_history_id | read | get snapshot by history id |
get_song_properties | write | get song properties. To get specific properties, set the corresponding property name to true in the properties parameter. |
get_song_view_properties | write | get song view properties. To get specific properties, set the corresponding property name to true in the properties parameter. |
get_track_overview | read | One-call summary of what |
get_track_properties | write | get track properties. To get specific properties, set the corresponding property name to true in the properties parameter |
get_track_sends | read | Get a track |
init_ableton_js | read | Initialize ableton-js and copy its MIDI scripts to Ableton Live |
list_resources | read | List Ableton live Browser resources of specified type |
modify_clip_notes | write | Modify clip notes by clip id |
modify_device_parameter_value | write | set device parameter value, only support built-in Live devices |
read_notes_from_clips | read | Batch-read all notes from multiple clips in one call instead of looping get_clip_notes. Always reads the whole clip (no from_pitch/from_time/time_span/pitch_span filtering). Each entry is isolated - one bad clip_id doesn |
record_by_time_range | read | Opens Ableton |
remove_clip_notes | destructive | Remove clip notes by clip id |
remove_notes_by_ids | destructive | Remove notes by clip id and note ids |
replace_clip_notes | read | Replace all notes in the clip with new notes |
rollback_by_history_id | read | rollback to the state before the operation corresponding to the history_id was executed, currently supports Note operations |
set_clips_property | write | batch set clip property |
set_song_property | write | set song basic properties |
set_song_view_property | write | set song view properties |
set_track_send | write | Set a track |
set_tracks_property | write | batch set tracks property |
write_notes_to_clips | write | Batch-write notes to multiple clips in one call instead of one add_notes_to_clip/replace_clip_notes round-trip per clip. mode: |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
delete_clip, delete_device, delete_track, remove_clip_notes, remove_notes_by_ids
.yarnrc.yml
import { ableton } from '../../ableton.js'import { OperationStatus } from '../../entities/OperationHistory.js'import { createOperationHistory, updateOperationHistoryById } from '../../utils/snapshot-utils.js'import { logger } from '../../main.js'import PerformanceMonitor from '../../utils/performance-monitor.js'
@modelcontextprotocol/sdk, @types/sql.js, async-mutex, reflect-metadata, sql.js, typeorm, winston, winston-daily-rotate-file
Gates applied: no_behavioural_pass.
89676262e15dfull audit observations/trust-audit/mcp-server/xiaolaa2__ableton-copilot.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 89676262e15d | SAFE | B | 89 | first audit |
Questions
What is the Ableton Copilot MCP server?
An MCP server built on ableton-js enables AI assistants to control Ableton Live in real time, including Arrangement View operations such as song management, track control, MIDI editing, and audio recording, along with other capabilities.
What tools does Ableton Copilot expose?
37 in total: 14 read-only, 18 that write, and 5 that can delete or overwrite (delete_clip, delete_device, delete_track, remove_clip_notes, remove_notes_by_ids). Every one is listed on this page with its risk.
Is Ableton Copilot safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Ableton Copilot need?
No credential environment variables were found in its source, so it appears to need none.
How does Ableton Copilot run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @xiaolaa2/ableton-copilot-mcp at 0.9.0.
How current is this page?
The grade is for one exact copy of the source (89676262e15d), read on 2026-10-07. The repository is watched and re-audited when it changes.