Audio File Mcp App — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Audio File Mcp App (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP App for playing and inspecting local audio files in an MCP host.

Renders an in-conversation UI with playback, metadata, loudness, and a spectrogram.
File metadata, loudness statistics, the current playhead position, and any selected region are also exposed back to the model, so follow-up tasks can refer to what the user is actually hearing and looking at.
(LUFS), Loudness Range (LRA), True Peak (dBTP), Sample Peak, and RMS.
(400 ms) and Short-Term (3 s) LUFS, plus sample-peak and RMS at the cursor position.
shaded along a tonal ramp using a low/mid/high band-energy ratio, so bright/dark regions read at a glance as bright/dark sound.
Inferno colour scale; time-frequency reassignment sharpens transients and tonal partials beyond what a plain STFT shows.
playback loops over it, and the region's start/end are passed back to the model alongside the file's loudness and playhead state.
The server runs locally over stdio. Every install path below configures the same command: npx -y @counterpoint-studio/audio-file-mcp-app.
Easiest: grab the latest .mcpb from the Releases page and double-click it. Claude Desktop has Node bundled, so no extra runtime is needed.
Or add the server by hand to claude_desktop_config.json:
{
"mcpServers": {
"audio-file": {
"command": "npx",
"args": ["-y", "@counterpoint-studio/audio-file-mcp-app"]
}
}
}Or add to .vscode/mcp.json (workspace) or your user mcp.json:
{
"servers": {
"audio-file": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@counterpoint-studio/audio-file-mcp-app"]
}
}
}Paste this deep link into your browser (Goose Desktop must be installed; the custom URI scheme can't be a real link in a GitHub README):
goose://extension?id=audio-file&name=Audio%20File%20MCP%20App&cmd=npx&arg=-y&arg=%40counterpoint-studio%2Faudio-file-mcp-appOr run goose configure → Add Extension → Command-line Extension and enter npx -y @counterpoint-studio/audio-file-mcp-app.
npx @modelcontextprotocol/inspector npx -y @counterpoint-studio/audio-file-mcp-appAsk the host to show you a local audio file by its absolute path. For example:
"Show me /Users/me/Music/track.wav"The host calls the display_audio_file tool, which renders the in-app UI with waveform, spectrogram, loudness metrics, and playback transport.
Tested and known to work in:
The Codex app has been tested too, but its MCP App support is currently broken.
pnpm install
pnpm run build:dsp # emsdk required; see WASM-BUILD.md
pnpm run serve # runs the server with tsx, no compile step
pnpm testpnpm run build:dist produces the publishable layout under dist/ (dist/mcp-app.html + dist/server/).
pnpm version <bump> # bumps package.json + tags
pnpm publish --access public # publishes to npm
pnpm run build:mcpb # produces dist/audio-file-mcp-app-<version>.mcpb
gh release create v<version> dist/*.mcpb # attaches the bundle to a GitHub release
mcp-publisher login github && mcp-publisher publish # updates the MCP Registry listingmcp-publisher is a Go binary; install it via brew install mcp-publisher or per the registry quickstart. It reads server.json from the repo root — keep its version in sync with package.json before publishing.
ISC © Counterpoint Studio OÜ
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.