
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
patchwork-deepmind
Advanced tools
MCP server for the Behringer DeepMind 12 synthesizer. Gives AI agents real-time control over synth parameters via MIDI NRPN, plus edit-buffer snapshots via SysEx.
npm install patchwork-deepmind
Add to your MCP client config (Claude Desktop, VS Code, etc.):
{
"mcpServers": {
"deepmind12": {
"command": "npx",
"args": ["patchwork-deepmind"]
}
}
}
| Tool | Description |
|---|---|
set_param | Set a parameter by name (normalized 0–1) |
set_params | Batch-set multiple parameters in one call |
describe_param | Look up a parameter's NRPN, range, and enum values |
describe_nrpn | Search/list raw NRPN parameters |
snapshot_state | Read current patch state via SysEx edit-buffer dump |
send_nrpn | Send a raw NRPN message by number and value |
The MCP tools give an agent the ability to control the synth, but not the knowledge of what sounds good — which parameters interact, what value ranges are musical, or how to approach building a specific type of sound.
The skills/deepmind-parameter-guide/ folder is a portable agent skill that provides this. It's organized as a compact index with drill-down sections by synth area (oscillators, filter, envelopes, LFOs, effects, etc.), so an agent loads only the context it needs.
To install the skill, copy it into your project's .claude/skills/ directory:
# From the cloned repo:
cp -r skills/deepmind-parameter-guide .claude/skills/
# Or from the installed npm package:
cp -r $(npm explore patchwork-deepmind -- pwd)/skills/deepmind-parameter-guide .claude/skills/
The skill is self-contained — no dependencies on this repo.
The server runs as a stdio-based MCP process — no network involved. Your MCP client (Claude Desktop, VS Code, etc.) spawns it as a subprocess and communicates over stdin/stdout. The server auto-detects the DeepMind's USB-MIDI port on startup and performs a SysEx handshake to confirm the connection.
Once connected, you can talk to your agent naturally:
"Give me a warm pad with slow filter movement and a long reverb tail"
"Make the attack slower and add some chorus"
"Snapshot the current patch so I can see what all the values are"
The agent uses the MCP tools to translate these into NRPN messages and SysEx commands in real time. You hear changes immediately on the synth.
| Variable | Default | Description |
|---|---|---|
MIDI_IN | auto-detect | MIDI input port index or exact name |
MIDI_OUT | auto-detect | MIDI output port index or exact name |
MIDI_PORT | — | Shared hint (partial name) used when MIDI_IN/MIDI_OUT are unset |
MIDI_CH | 0 | MIDI channel (0–15, where 0 = channel 1) |
MIDI_IN / MIDI_OUT env vars to select the correct port by index or name.npm install
npm run build
npm test
Issues and PRs welcome.
MIT
FAQs
DeepMind 12 MCP server (DeepMind-first)
We found that patchwork-deepmind demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.