Atlas / MCP servers / xiaolaa2 / Ableton Copilot

Ableton CopilotSAFE

mcp/xiaolaa2/ableton-copilot

An MCP server built on ableton-js enables AI assistants to control Ableton Live in real time, including Arrangement View operations such as song management, track control, MIDI editing, and audio recording, along with other capabilities.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
37 14r · 18w · 5d
Transport
stdio
License
MIT
Stars
94
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server built on ableton-js for real-time interaction and control with Ableton Live's Arrangement View, dedicated to assisting music producers in their music production.

🎯 Note

As a music producer, I have some understanding of using Ableton for music creation. During the creative process, we often need to handle various tedious operations, such as humanizing note properties, merging notes, recording one track to another audio track, etc. Previously, we could only rely on the functions provided by the host DAW for these operations. However, with the emergence of large language models and MCP, we now have the possibility to let AI help us with automation. Although it's still not realistic for AI to directly generate notes or create a complete song (it can't generate a good-sounding song), having AI assist us with auxiliary operations presents a new possibility.

🎥 Demo

This is a simple demonstration video of MIDI operations.

https://github.com/user-attachments/assets/8d635c4c-a1f2-44be-93ae-062038d14c71

🚀 Features

🎵 Song Control

  • Get basic song information (root note, scale name, tempo, song length, etc.)
  • Get a list of all tracks
  • Create MIDI, audio, and return tracks
  • Delete and duplicate tracks

🎹 Track Management

  • Get all clips in a track
  • Create empty MIDI clips in the arrangement view tracks
  • Create audio clips in tracks based on provided sample file paths
  • Set track properties (mute, color, name, arm, solo, etc.)
  • Duplicate MIDI clips to specified tracks

🎼 Clip Oper

Read from source at commit 89676262e15dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add ableton-copilot-mcp -- npx -y @xiaolaa2/[email protected]
claude-desktop
{
  "mcpServers": {
    "ableton-copilot-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@xiaolaa2/[email protected]"
      ]
    }
  }
}
03

Exposed tools (37)

14 read · 18 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_notes_to_clipwriteAdd notes to clip by clip id
create_clips_batchwriteBatch version of create_midi_clip - creates multiple empty MIDI clips across one or more tracks in one call. Each entry is isolated - one failure doesn
create_midi_clipwriteCreates an empty MIDI clip on the track and returns the created clip information
create_trackwritecreate track and return raw track
crop_clipreadCrops the clip. The region that is cropped depends on whether the clip is looped or not. If looped, the region outside of the loop is removed. If not looped, the region outside the start and end markers is removed.
delete_clipdestructivedelete clip by id
delete_devicedestructivedelete device by index, start from 0
delete_trackdestructivedelete track by index
duplicate_clip_loopreadMakes the loop twice as long and duplicates notes and envelopes. Duplicates the clip start/end range if the clip is not looped.
duplicate_clip_to_trackreadduplicate clip to track and return the duplicated clip information
duplicate_trackreadduplicate midi or audio track by index
get_application_infowriteGet Ableton Live application information. To get specific properties, set the corresponding property name to true in the properties parameter. If no properties are specified, returns all available information.
get_clip_propertieswriteGet clip properties by clip id. To get specific properties, set the corresponding property name to true in the properties parameter.
get_device_propertieswriteget device properties. To get specific properties, set the corresponding property name to true in the properties parameter
get_operation_historiesreadget mcp tools operation histories by page
get_snapshot_by_history_idreadget snapshot by history id
get_song_propertieswriteget song properties. To get specific properties, set the corresponding property name to true in the properties parameter.
get_song_view_propertieswriteget song view properties. To get specific properties, set the corresponding property name to true in the properties parameter.
get_track_overviewreadOne-call summary of what
get_track_propertieswriteget track properties. To get specific properties, set the corresponding property name to true in the properties parameter
get_track_sendsreadGet a track
init_ableton_jsreadInitialize ableton-js and copy its MIDI scripts to Ableton Live
list_resourcesreadList Ableton live Browser resources of specified type
modify_clip_noteswriteModify clip notes by clip id
modify_device_parameter_valuewriteset device parameter value, only support built-in Live devices
read_notes_from_clipsreadBatch-read all notes from multiple clips in one call instead of looping get_clip_notes. Always reads the whole clip (no from_pitch/from_time/time_span/pitch_span filtering). Each entry is isolated - one bad clip_id doesn
record_by_time_rangereadOpens Ableton
remove_clip_notesdestructiveRemove clip notes by clip id
remove_notes_by_idsdestructiveRemove notes by clip id and note ids
replace_clip_notesreadReplace all notes in the clip with new notes
rollback_by_history_idreadrollback to the state before the operation corresponding to the history_id was executed, currently supports Note operations
set_clips_propertywritebatch set clip property
set_song_propertywriteset song basic properties
set_song_view_propertywriteset song view properties
set_track_sendwriteSet a track
set_tracks_propertywritebatch set tracks property
write_notes_to_clipswriteBatch-write notes to multiple clips in one call instead of one add_notes_to_clip/replace_clip_notes round-trip per clip. mode:
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_clip, delete_device, delete_track, remove_clip_notes, remove_notes_by_ids
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.yarnrc.yml
.yarnrc.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/decorators/tool.ts:5
import { ableton } from '../../ableton.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/decorators/tool.ts:7
import { OperationStatus } from '../../entities/OperationHistory.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/decorators/tool.ts:8
import { createOperationHistory, updateOperationHistoryById } from '../../utils/snapshot-utils.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/decorators/tool.ts:9
import { logger } from '../../main.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/decorators/tool.ts:10
import PerformanceMonitor from '../../utils/performance-monitor.js'
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/sql.js, async-mutex, reflect-metadata, sql.js, typeorm, winston, winston-daily-rotate-file
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 89676262e15dfull audit observations/trust-audit/mcp-server/xiaolaa2__ableton-copilot.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0789676262e15dSAFEB89first audit
06

Questions

What is the Ableton Copilot MCP server?

An MCP server built on ableton-js enables AI assistants to control Ableton Live in real time, including Arrangement View operations such as song management, track control, MIDI editing, and audio recording, along with other capabilities.

What tools does Ableton Copilot expose?

37 in total: 14 read-only, 18 that write, and 5 that can delete or overwrite (delete_clip, delete_device, delete_track, remove_clip_notes, remove_notes_by_ids). Every one is listed on this page with its risk.

Is Ableton Copilot safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Ableton Copilot need?

No credential environment variables were found in its source, so it appears to need none.

How does Ableton Copilot run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @xiaolaa2/ableton-copilot-mcp at 0.9.0.

How current is this page?

The grade is for one exact copy of the source (89676262e15d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement