MiniMax AISAFE
A unified Model Context Protocol server for MiniMax CLI (mmx)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/zth0828-mmx-mcp-server)
一个统一的 MiniMax 全模态 MCP Server,基于 mmx CLI 封装,支持文本、搜索、图像理解、图像生成、语音合成、视频生成、音乐生成和配额查询。
English README
快速开始(一句话配置)
如果你使用的是 Claude Code、OpenCode 或其他支持 MCP 的 AI CLI 工具,直接把下面这段话丢给 AI:
帮我安装并配置 mmx-mcp-server: 1. 全局安装 mmx-cli(npm install -g mmx-cli) 2. 克隆 https://github.com/zth0828/mmx-mcp-server 到任意目录,执行npm install && npm run build3. 在我的 MCP 配置文件(如~/.claude/settings.json)里添加mmxserver,指向构建产物dist/index.js4. 向我要 MiniMax API Key,并通过env.MINIMAX_API_KEY注入 5. 完成后告诉我配置结果
手动安装
1. 安装 mmx CLI(如果尚未安装)
npm install -g mmx-cli
验证安装:
mmx --version
2. 安装并构建 MCP Server
git clone https://github.com/zth0828/mmx-mcp-server.git cd mmx-mcp-server npm install npm run build
3. 配置 API Key
在 MCP 客户端配置(如 ~/.claude/settings.json)中添加:
方式一:环境变量传 API Key(推荐)
{
"mcpServers": {
"mmx": {
"command": "node",
"args": ["/path/to/mmx-mcp-server/dist/index.js"],
"env": {
"MINIMAX_API_KEY": "sk-xxxxx"
}
}
}
}方式二:命令行参数传 API Key
适合不方便写 env 的 MCP 客户端:
{
"mcpServers": {
"mmx": {
"command": "node",
"args": [
"/path/to/mmx-mcp-server/dist/index.js",
"--api-key",
"sk-xxxxx"
]
}
}
}方式三:依赖 mmx CLI 本地登录
如果前两种方式都没配,Server 会自动回退到 mmx CLI 自身的认证状态(需提前执行 mmx auth login --api-key sk-xxxxx)。这种方式仅适合本机使用。
自定义输出目录(可选)
默认情况下,生成的图片、视频、音乐、语音会自动保存到 当前工作目录 下的子文件夹:
mmx_image/— 图片mmx_video/— 视频mmx_music/— 音乐mmx_speech/— 语音
如果你希望统一放到其他位置,可以通过环境变量 MMX_OUTPUT_DIR 修改:
{
"mcpServers": {
"mmx": {
"command": "node",
"args": ["/path/to/mmx-mcp-server/dist/index.js"],
"env": {
"MINIMAX_API_KEY": "sk-xxxxx",
8419b77e1e2dOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mmx-mcp-server --env MCP_MINIMAX_API_KEY=${MCP_MINIMAX_API_KEY} --env MINIMAX_API_KEY=${MINIMAX_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"mmx-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MCP_MINIMAX_API_KEY": "${MCP_MINIMAX_API_KEY}",
"MINIMAX_API_KEY": "${MINIMAX_API_KEY}"
}
}
}
}Exposed tools (8)
8 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
mmx_image_generate | read | Generate images with MiniMax. If no output path is provided, images are saved to the default output directory (e.g. ./mmx_image) and their file paths are returned. |
mmx_music_generate | read | Generate music with MiniMax. Supports instrumental or vocal music. If lyrics and style are provided, generates a song. If no output path is provided, the audio file is saved to the default output directory (e.g. ./mmx_music). |
mmx_quota_show | read | Show MiniMax usage quotas and remaining limits for each model or service. |
mmx_search | read | Search the web using MiniMax. Returns search results with titles, snippets, and URLs. Use this when you need up-to-date information, facts, news, or references from the internet. |
mmx_speech_synthesize | read | Synthesize speech with MiniMax TTS. Converts text into an audio file. If no output path is provided, the file is saved to the default output directory (e.g. ./mmx_speech). |
mmx_text_chat | read | Chat with MiniMax text models. Supports system prompts and optional JSON mode. Use this for general reasoning, writing, coding help, or structured output. |
mmx_video_generate | read | Generate video with MiniMax from a text prompt. If no output path is provided, the video is saved to the default output directory (e.g. ./mmx_video) and its file path is returned. |
mmx_vision_describe | read | Analyze an image with a custom instruction using MiniMax Vision. Useful for: UI/UX critique, extracting text, identifying objects, evaluating designs, or answering specific questions about the image. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
@modelcontextprotocol/sdk, @types/node, typescript
Gates applied: no_behavioural_pass.
8419b77e1e2dfull audit observations/trust-audit/mcp-server/zth0828__minimax-ai.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 8419b77e1e2d | SAFE | B | 89 | first audit |
Questions
What is the MiniMax AI MCP server?
A unified Model Context Protocol server for MiniMax CLI (mmx)
What tools does MiniMax AI expose?
8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MiniMax AI safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does MiniMax AI need?
It reads MCP_MINIMAX_API_KEY and MINIMAX_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MiniMax AI run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mmx-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (8419b77e1e2d), read on 2026-10-08. The repository is watched and re-audited when it changes.