musicbrainz-mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited musicbrainz-mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server for MusicBrainz, the open music encyclopedia. It gives Claude live access to MusicBrainz metadata — artists, releases, recordings, labels, works, and more — plus Cover Art Archive images, and (optionally) lets you submit your own tags, ratings, and collection edits.
Developed and maintained by AI (Claude Code). Use at your own discretion.
Read (no credentials required):
| Tool | What it does |
|---|---|
musicbrainz_search | Search any entity type with a Lucene query; returns ranked matches + MBIDs |
musicbrainz_lookup | Look up an entity by MBID, with inc subqueries for linked data |
musicbrainz_browse | List all entities linked to another (e.g. every release by an artist) |
musicbrainz_cover_art | Cover Art Archive image URLs for a release / release-group |
musicbrainz_resolve | Turn a pasted musicbrainz.org URL into its entity |
musicbrainz_healthcheck | Verify connectivity and whether OAuth writes are configured |
Write (OAuth, confirm-gated):
| Tool | What it does |
|---|---|
musicbrainz_submit_tags | Apply user tags to an entity on your account |
musicbrainz_submit_rating | Set your 0–100 rating for an entity |
musicbrainz_modify_collection | Add/remove entities in one of your collections |
Each write makes no network call without confirm: true; it returns a dry-run preview first.
This is a Node MCP server (stdio). Point your MCP host at it:
{
"mcpServers": {
"musicbrainz": {
"command": "npx",
"args": ["-y", "musicbrainz-mcp"]
}
}
}Reads work immediately. MusicBrainz asks clients to make at most one request per second — the server throttles itself to stay within that limit, so large browses are paced automatically.
urn:ietf:wg:oauth:2.0:oob).tag, rating, and collection scopes to obtain a refresh token..env):MUSICBRAINZ_OAUTH_CLIENT_ID=...
MUSICBRAINZ_OAUTH_CLIENT_SECRET=...
MUSICBRAINZ_OAUTH_REFRESH_TOKEN=...npm install
npm run build
npm testSee CLAUDE.md for architecture and docs/MUSICBRAINZ-API.md for the pinned API shapes.
MIT. Data from MusicBrainz, licensed under CC0 / CC BY-NC-SA.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.