Atlas / MCP servers / xixihhhh / HotClip

HotClipCAUTION

mcp/xixihhhh/hotclip

免费开源的 AI 剪辑 / 直播切片工具:长视频、直播回放、播客一键切成爆款竖屏短视频,直发抖音/快手/B站/小红书/视频号——AI 找高光金句、弹幕热度进爆点判断、自动加字幕、横屏转竖屏,本地运行无水印不上传 | Free open-source Opus Clip alternative, 100% local: AI clips long videos & livestream VODs into viral 9:16 shorts for TikTok & YouTube Shorts. No credits, no watermark, no uploads. Win/macOS/L

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
3 3r · 0w · 0d
Transport
—
License
AGPL-3.0
Stars
301
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

长视频、直播回放一键切成爆款竖屏短视频

简体中文 | English | 官网 | 下载 | FAQ | 反馈

AI 自动找爆点(附理由) · 横屏转竖屏 9:16 · 自动加动态字幕 · 去气口剪口头禅

无水印 · 无积分制 · 不限时长 · 素材不上传 · 连注册都不用

本地转写现支持分段保存、停止与续跑;逐句稿提供跨句全文搜索、长稿虚拟列表,以及可试听、确认和撤销的局部时间校准。开启全场画面扫描后,搜索还会命中已确认的画面描述和屏显文字,并可直接跳到对应时刻。导出自动改善不同语言的字幕阅读节奏。可选 Qwen3-ASR 本地服务与模型评估命令见 语音与长稿使用指南。

搜索没有精确命中时,逐句稿可主动开启「相近台词」:查找仅差一个字的识别结果,并明确标为近似命中,试听确认后再选段。

搜到就能选段:台词和画面命中按时间统一浏览,可按来源筛选、定位命中字词、试听上下文,再带着完整句进入选段窗口。估算时间明确标注;长稿选段按需渲染,确认加入候选后支持撤销和重做。

多人对谈开启说话人识别后,逐句稿工作台可按 S1 / S2 等说话人筛选;搜索、相近台词和选段预览会同步收窄范围。

导出与取消

导出页会显示素材检查、字幕翻译、文案生成、多版准备、编码和文件整理阶段。准备阶段即可取消,停止清理结束后可以直接重试;重复启动不会覆盖正在运行的任务。进度在文件整理完成前最高显示 99%。关闭烧录字幕、只打开 SRT 导出时,也会保留逐字稿供字幕文件使用。

常规剪切、跳剪、音频成片、合集与动态字幕编码先写目标目录内的独立临时文件,成功关闭编码器后才替换目标。失败或取消的这次编码不会把已有目标文件截断;同一批此前完成的切片

Read from source at commit 0241906b1b3dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add hotclip --env HOTCLIP_LLM_API_KEY=${HOTCLIP_LLM_API_KEY} --env HOTCLIP_VISION_API_KEY=${HOTCLIP_VISION_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "hotclip": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "HOTCLIP_LLM_API_KEY": "${HOTCLIP_LLM_API_KEY}",
        "HOTCLIP_VISION_API_KEY": "${HOTCLIP_VISION_API_KEY}"
      }
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
clip_videoread全托管切片:把一个本地长视频(播客/直播回放/课程)转写、AI 找爆点并导出为可发布的竖屏短视频(烧字幕/跳剪/表情信号),返回输出目录与每条切片的标题/评分/时间码。未提供 subtitlePath 时,首次运行会自动下载本地 ASR 模型。需要环境变量 HOTCLIP_LLM_BASE_URL/HOTCLIP_LLM_MODEL(以及非本地端点的 HOTCLIP_LLM_API_KEY)。
detect_highlightsread只找爆点不出片:转写并用 LLM 挑出爆点候选,返回每条的时间码/标题/钩子/评分/理由/AI复评意见 JSON。适合先审后剪的流程。需要 HOTCLIP_LLM_* 环境变量。
transcribe_videoread字幕接入或本地转写:提供 subtitlePath 时导入已有字幕并估算字词时间;否则用端侧 ASR(SenseVoice,首次自动下载)把视频/音频转成带时间戳的逐句稿。结果有缓存,同一文件二次调用秒回。不需要 LLM 配置。
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (20)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
src/core/caption-overlay/payload.ts
payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/cli/index.ts:31
--asr-url http://127.0.0.1:8766   可选 Qwen3 本地服务
LOWInventory / provenance · inv.binary · CWE-1104
src/core/__tests__/fixtures/fixture-model.tar.bz2
fixture-model.tar.bz2
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/__tests__/align.test.ts:3
import type { TranscriptWord } from "../../shared/api-types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/__tests__/automation-history.test.ts:5
import type { AutomationTask } from "../../shared/api-types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/__tests__/boundary.test.ts:2
import { adjustClipBoundary, adjustCandidateBoundary } from "../../shared/boundary";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/__tests__/boundary.test.ts:3
import type { Transcript } from "../../shared/api-types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/__tests__/caption-overlay.test.ts:4
import type { TranscriptWord } from "../../shared/api-types";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-speech.md:23
默认引擎仍为 SenseVoice。Qwen3-ASR 0.6B / 1.7B 是用户管理的可选服务;HotClip 不自动安装 Python、不自动启动服务,也不将素材发送到远程地址。模型首次由服务加载时下载并缓存在本机。协议仅接受 `http://127.0.0.1:<端口>` 或 `http://[::1]:<端口>`,拒绝重定向。
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-speech.md:35
启动后,在“转写引擎”中选择 Qwen3-ASR,填写 `http://127.0.0.1:8766` 并“检查连接”。界面会显示实际加载的模型、设备和对齐器状态。`--model 1.7B` 选择更大的模型;`--port` 可改端口。省略 `--aligner` 可减少模型加载,转写字词时间将明确标为估算,编辑阶段的 Qwen 校准不可用。停止客户端任务会中止等待;服务可能仍在完成当前推理,忙
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-speech.md:40
pnpm cli transcribe recording.mp4 --engine qwen3 --asr-url http://127.0.0.1:8766 --json
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/cli/__tests__/cli.test.ts:93
expect(parseCliArgs(["transcribe", "source.mp4", "--engine", "qwen3", "--asr-url", "http://127.0.0.1:8766", "--restart-transcription"])).toMatchObject({ engineId: "qwen3", localServiceUrl: "http://127
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tools/qwen-speech-server.py:79
pcm = np.frombuffer(base64.b64decode(body["pcm"], validate=True), dtype="<f4").copy()
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/core/__tests__/v14-survival.test.ts:107
expect(csv.startsWith("")).toBe(true);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@ffprobe-installer/ffprobe, @tailwindcss/vite, ffmpeg-static, onnxruntime-node, react, react-dom, react-icons, sherpa-onnx-node
Why it matters. 24 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.en.md:355
**[v0.15.1](https://github.com/xixihhhh/hotclip/releases/tag/v0.15.1)** (2026-08-24) "Work survives, publishing teaches": **hardware-accelerated export** (VideoToolbox / NVENC / QSV with transparent x
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.en.md:365
- **[v0.12.0](https://github.com/xixihhhh/hotclip/releases/tag/v0.12.0)** (2026-08-05) "Pick sharper, open louder": **flash-forward cold opens** (flash the most explosive 0.3-1s, then cut back; auto-c
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/local-speech.md:81
**Model requests** have deadlines covering both response headers and body: text analysis gets 3 minutes for remote services or 5 minutes for loopback services, shared across parameter fallback and emp
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
resources/fonts/SourceHanSansSC-Bold.otf
resources/fonts/SourceHanSansSC-Bold.otf
Why it matters. 16963428 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0241906b1b3dfull audit observations/trust-audit/mcp-server/xixihhhh__hotclip.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-080241906b1b3dCAUTIONB84first audit
06

Questions

What is the HotClip MCP server?

免费开源的 AI 剪辑 / 直播切片工具:长视频、直播回放、播客一键切成爆款竖屏短视频,直发抖音/快手/B站/小红书/视频号——AI 找高光金句、弹幕热度进爆点判断、自动加字幕、横屏转竖屏,本地运行无水印不上传 | Free open-source Opus Clip alternative, 100% local: AI clips long videos & livestream VODs into viral 9:16 shorts for TikTok & YouTube Shorts. No credits, no watermark, no uploads. Win/macOS/L

What tools does HotClip expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is HotClip safe to connect to an agent?

With care. The audit graded it B (84/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does HotClip need?

It reads HOTCLIP_LLM_API_KEY and HOTCLIP_VISION_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (0241906b1b3d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement