Atlas / MCP servers / zth0828 / MiniMax AI

MiniMax AISAFE

mcp/zth0828/minimax-ai

A unified Model Context Protocol server for MiniMax CLI (mmx)

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 8r · 0w · 0d
Transport
stdio
License
MIT
Stars
31
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/zth0828-mmx-mcp-server)

一个统一的 MiniMax 全模态 MCP Server,基于 mmx CLI 封装,支持文本、搜索、图像理解、图像生成、语音合成、视频生成、音乐生成和配额查询。

English README

快速开始(一句话配置)

如果你使用的是 Claude Code、OpenCode 或其他支持 MCP 的 AI CLI 工具,直接把下面这段话丢给 AI:

帮我安装并配置 mmx-mcp-server: 1. 全局安装 mmx-cli(npm install -g mmx-cli) 2. 克隆 https://github.com/zth0828/mmx-mcp-server 到任意目录,执行 npm install && npm run build 3. 在我的 MCP 配置文件(如 ~/.claude/settings.json)里添加 mmx server,指向构建产物 dist/index.js 4. 向我要 MiniMax API Key,并通过 env.MINIMAX_API_KEY 注入 5. 完成后告诉我配置结果

手动安装

1. 安装 mmx CLI(如果尚未安装)

npm install -g mmx-cli

验证安装:

mmx --version

2. 安装并构建 MCP Server

git clone https://github.com/zth0828/mmx-mcp-server.git
cd mmx-mcp-server
npm install
npm run build

3. 配置 API Key

在 MCP 客户端配置(如 ~/.claude/settings.json)中添加:

方式一:环境变量传 API Key(推荐)

{
"mcpServers": {
"mmx": {
"command": "node",
"args": ["/path/to/mmx-mcp-server/dist/index.js"],
"env": {
"MINIMAX_API_KEY": "sk-xxxxx"
}
}
}
}

方式二:命令行参数传 API Key

适合不方便写 env 的 MCP 客户端:

{
"mcpServers": {
"mmx": {
"command": "node",
"args": [
"/path/to/mmx-mcp-server/dist/index.js",
"--api-key",
"sk-xxxxx"
]
}
}
}

方式三:依赖 mmx CLI 本地登录

如果前两种方式都没配,Server 会自动回退到 mmx CLI 自身的认证状态(需提前执行 mmx auth login --api-key sk-xxxxx)。这种方式仅适合本机使用。

自定义输出目录(可选)

默认情况下,生成的图片、视频、音乐、语音会自动保存到 当前工作目录 下的子文件夹:

  • mmx_image/ — 图片
  • mmx_video/ — 视频
  • mmx_music/ — 音乐
  • mmx_speech/ — 语音

如果你希望统一放到其他位置,可以通过环境变量 MMX_OUTPUT_DIR 修改:

{
"mcpServers": {
"mmx": {
"command": "node",
"args": ["/path/to/mmx-mcp-server/dist/index.js"],
"env": {
"MINIMAX_API_KEY": "sk-xxxxx",
Read from source at commit 8419b77e1e2dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mmx-mcp-server --env MCP_MINIMAX_API_KEY=${MCP_MINIMAX_API_KEY} --env MINIMAX_API_KEY=${MINIMAX_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mmx-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MCP_MINIMAX_API_KEY": "${MCP_MINIMAX_API_KEY}",
        "MINIMAX_API_KEY": "${MINIMAX_API_KEY}"
      }
    }
  }
}
03

Exposed tools (8)

8 read · 0 write · 0 destructive.

ToolRiskDescription
mmx_image_generatereadGenerate images with MiniMax. If no output path is provided, images are saved to the default output directory (e.g. ./mmx_image) and their file paths are returned.
mmx_music_generatereadGenerate music with MiniMax. Supports instrumental or vocal music. If lyrics and style are provided, generates a song. If no output path is provided, the audio file is saved to the default output directory (e.g. ./mmx_music).
mmx_quota_showreadShow MiniMax usage quotas and remaining limits for each model or service.
mmx_searchreadSearch the web using MiniMax. Returns search results with titles, snippets, and URLs. Use this when you need up-to-date information, facts, news, or references from the internet.
mmx_speech_synthesizereadSynthesize speech with MiniMax TTS. Converts text into an audio file. If no output path is provided, the file is saved to the default output directory (e.g. ./mmx_speech).
mmx_text_chatreadChat with MiniMax text models. Supports system prompts and optional JSON mode. Use this for general reasoning, writing, coding help, or structured output.
mmx_video_generatereadGenerate video with MiniMax from a text prompt. If no output path is provided, the video is saved to the default output directory (e.g. ./mmx_video) and its file path is returned.
mmx_vision_describereadAnalyze an image with a custom instruction using MiniMax Vision. Useful for: UI/UX critique, extracting text, identifying objects, evaluating designs, or answering specific questions about the image.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/node, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 8419b77e1e2dfull audit observations/trust-audit/mcp-server/zth0828__minimax-ai.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-088419b77e1e2dSAFEB89first audit
06

Questions

What is the MiniMax AI MCP server?

A unified Model Context Protocol server for MiniMax CLI (mmx)

What tools does MiniMax AI expose?

8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is MiniMax AI safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does MiniMax AI need?

It reads MCP_MINIMAX_API_KEY and MINIMAX_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MiniMax AI run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mmx-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (8419b77e1e2d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement