FastMCP server for Music Assistant — control MA from Claude Code, Codex, Cursor, and other AI agents
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio · streamable-http · http counts 3 tools · 0 res
· 0 prompts
permission surface via code analysis
tools
-
call_tool
-
ma_app_action
-
ma_app_state
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed commit 00b1708 · analyzer v33 · 1w ago
skills & prompt files 3
danger signals1
- dynamic code execution eval()/exec() trudenboy-ma-provider-mcp-00b1708/tests/test_command_policy.py :54
exec(compile(ast.fix_missing_locations(module), str(source_path), "exec"), namespace) # noqa: S102
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 114
filesystem 12
- fs trudenboy-ma-provider-mcp-00b1708/provider/debug/log_reader.py :36
from pathlib import Path - fs trudenboy-ma-provider-mcp-00b1708/provider/dynamic_serialization.py :12
from pathlib import Path - fs (weak) trudenboy-ma-provider-mcp-00b1708/scripts/check_method_order.py :20
from pathlib import Path - fs (weak) trudenboy-ma-provider-mcp-00b1708/tests/conftest.py :23
import shutil - fs (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_architecture.py :6
from pathlib import Path - fs (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_command_parity.py :5
from pathlib import Path - fs (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_command_policy.py :6
from pathlib import Path - fs (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_docs.py :6
import shutil - fs (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_dynamic_serialization.py :8
from pathlib import Path - fs (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_openclaw_bundle.py :17
from pathlib import Path - fs (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_provider_commands_debug.py :8
from pathlib import Path - fs (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_strings_json.py :6
from pathlib import Path
shell / exec 1
- shell (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_docs.py :7
import subprocess
network 12
- net trudenboy-ma-provider-mcp-00b1708/provider/catalog_resource.py :7
from urllib.parse import urlencode - net trudenboy-ma-provider-mcp-00b1708/provider/connect/actions.py :7
from urllib.parse import quote, urlsplit - net trudenboy-ma-provider-mcp-00b1708/provider/connect/handlers.py :18
from urllib.parse import urlsplit - net trudenboy-ma-provider-mcp-00b1708/provider/http_bridge.py :5
MA's main webserver is aiohttp. This bridge translates a single aiohttp - net trudenboy-ma-provider-mcp-00b1708/provider/origins.py :42
from urllib.parse import urlsplit - net trudenboy-ma-provider-mcp-00b1708/provider/resource_authorization.py :10
from urllib.parse import urlsplit - net (weak) trudenboy-ma-provider-mcp-00b1708/tests/conftest.py :35
Captures every dynamic-route registration so tests can drive them through aiohttp. - net (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_connect_wizard.py :21
from urllib.parse import parse_qs, urlsplit - net (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_e2e_http.py :17
from aiohttp.test_utils import TestClient, TestServer - net (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_meta_discovery.py :8
from urllib.parse import urlencode - net (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_origin.py :10
from aiohttp.test_utils import TestClient, TestServer - net (weak) trudenboy-ma-provider-mcp-00b1708/tests/test_setup_flow.py :11
from aiohttp.test_utils import make_mocked_request
secrets 1
- secrets (weak) trudenboy-ma-provider-mcp-00b1708/tests/integration/test_live_catalog.py :38
token = os.getenv("MA_MCP_TOKEN")
tool registrations 3
- ma_app_state trudenboy-ma-provider-mcp-00b1708/provider/app_music_assistant.py :48
- ma_app_action trudenboy-ma-provider-mcp-00b1708/provider/app_music_assistant.py :55
- call_tool trudenboy-ma-provider-mcp-00b1708/provider/meta_discovery.py :421
declared dependencies 13
- fastmcp@==3.4.7
- prefab-ui@==0.20.2
- pytest@>=9.0
- pytest-asyncio@>=0.24
- pytest-aiohttp@>=1.1
- pytest-cov@>=7.0
- syrupy@>=5.0
- codespell@>=2.4
- music-assistant@@ git+https://github.com/music-assistant/server.git@dev
- ruff@>=0.15,<0.16
- mypy@>=1.19
- pre-commit@>=4.5
- pre-commit-hooks@>=6.0
cursor-plugin 1
- opaque (low) trudenboy-ma-provider-mcp-00b1708/.cursor/rules/coauthor-agent-identity.mdc
bundled .cursor/ plugin descriptor (trudenboy-ma-provider-mcp-00b1708/.cursor/rules/coauthor-agent-identity.mdc) — presence-detected; review the descriptor