
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@counterpoint-studio/audio-file-mcp-app
Advanced tools
An MCP app for inspecting audio files in audio workflows. Playback, metadata, statistics
An MCP App for playing and inspecting local audio files in an MCP host.

Renders an in-conversation UI with playback, metadata, loudness, a spectrogram, and an optional annotation-lane timeline.
File metadata, loudness statistics, the current playhead position, any selected region, and the annotation lanes active at the playhead are also exposed back to the model, so follow-up tasks can refer to what the user is actually hearing and looking at.
The server runs locally over stdio. Every install path below configures the
same command: npx -y @counterpoint-studio/audio-file-mcp-app.
Easiest: grab the latest .mcpb from the
Releases page
and double-click it. Claude Desktop has Node bundled, so no extra runtime
is needed.
Or add the server by hand to claude_desktop_config.json:
{
"mcpServers": {
"audio-file": {
"command": "npx",
"args": ["-y", "@counterpoint-studio/audio-file-mcp-app"]
}
}
}
audiofile-mcp-appnpx-y and @counterpoint-studio/audio-file-mcp-appOr add to .vscode/mcp.json (workspace) or your user mcp.json:
{
"servers": {
"audio-file": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@counterpoint-studio/audio-file-mcp-app"]
}
}
}
Paste this deep link into your browser (Goose Desktop must be installed; the custom URI scheme can't be a real link in a GitHub README):
goose://extension?id=audio-file&name=Audio%20File%20MCP%20App&cmd=npx&arg=-y&arg=%40counterpoint-studio%2Faudio-file-mcp-app
Or run goose configure → Add Extension → Command-line Extension and
enter npx -y @counterpoint-studio/audio-file-mcp-app.
npx @modelcontextprotocol/inspector npx -y @counterpoint-studio/audio-file-mcp-app
Ask the host to show you a local audio file by its absolute path. For example:
"Show me
/Users/me/Music/track.wav"
The host calls the display_audio_file tool, which renders the in-app UI
with waveform, spectrogram, loudness metrics, and playback transport.
display_audio_file accepts an optional annotations object describing lanes
to draw on the timeline (or an annotationsPath pointing at a JSON file with
the same { "lanes": [...] } shape — handy for large payloads):
{
"annotations": {
"lanes": [
{
"label": "Delay tails",
"color": "#e6007e",
"spans": [{ "start": 8, "end": 24 }],
"envelope": [
{ "time": 8, "value": 0 },
{ "time": 24, "value": 1 }
]
}
]
}
}
Times are in seconds on the audio's own timeline. label, color, and
envelope are optional; a lane with an envelope fades its span opacity along
the envelope curve, and uncoloured lanes use a light-accent fill. Overlapping
spans in a lane are truncated at the next span's start so rows never overlap.
The model can author annotations to point out sections, mark events, or
visualise an analysis it just ran.
Tested and known to work in:
pnpm install
pnpm run build:dsp # emsdk required; see WASM-BUILD.md
pnpm run serve # runs the server with tsx, no compile step
pnpm test
pnpm run build:dist produces the publishable layout under dist/
(dist/mcp-app.html + dist/server/).
pnpm version <bump> # bumps package.json + tags
pnpm publish --access public # publishes to npm
pnpm run build:mcpb # produces dist/audio-file-mcp-app-<version>.mcpb
gh release create v<version> dist/*.mcpb # attaches the bundle to a GitHub release
mcp-publisher login github && mcp-publisher publish # updates the MCP Registry listing
mcp-publisher is a Go binary; install it via
brew install mcp-publisher or per the
registry quickstart.
It reads server.json from the repo root — keep its version in sync with
package.json before publishing.
ISC © Counterpoint Studio OÜ
FAQs
An MCP app for inspecting audio files in audio workflows. Playback, metadata, statistics
We found that @counterpoint-studio/audio-file-mcp-app demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.