
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
producer-pal
Advanced tools
AI music production assistant for Ableton Live via the Model Context Protocol (MCP).
Run the Producer Pal MCP bridge to connect any MCP client to Ableton Live:
npx producer-pal
This starts a stdio-to-HTTP bridge that enables MCP clients (Claude Desktop, Claude Code, Gemini CLI, Codex CLI, VS Code with Cline, LM Studio, etc.) to communicate with the Producer Pal Max for Live device running in Ableton Live.
Producer_Pal.amxd
and add it to a MIDI track in Ableton LiveVersion Note: The npm package version is independent of the Max for Live device version. Always use the latest of both.
Add Producer Pal to your MCP client's server configuration. The command is
npx producer-pal with optional arguments -y (for auto-install).
Configuration examples:
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS)
or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"producer-pal": {
"command": "npx",
"args": ["-y", "producer-pal"]
}
}
}
claude mcp add producer-pal npx producer-pal
Edit ~/.gemini/settings.json:
{
"mcpServers": {
"producer-pal": {
"command": "npx",
"args": ["-y", "producer-pal"]
}
}
}
Edit ~/.codex/config.toml:
[mcp_servers.producer-pal]
command = "npx"
args = ["-y", "producer-pal"]
Edit Settings → Program → Integrations → mcp.json:
{
"mcpServers": {
"producer-pal": {
"command": "npx",
"args": ["-y", "producer-pal", "-s"]
}
}
}
The -s flag enables small model mode. See the
LM Studio guide for details.
Edit cline_mcp_settings.json:
{
"mcpServers": {
"producer-pal": {
"command": "npx",
"args": ["-y", "producer-pal"]
}
}
}
Use the command npx producer-pal with optional argument -y for auto-install.
Consult your client's documentation for MCP server configuration syntax.
-s / --small-model-mode - Enable
small model mode
(simplifies tool interface for smaller LLMs and automatically enables it on
the device)Optional environment variables can be configured through your MCP client:
MCP_SERVER_ORIGIN - URL for the Max for Live device (default:
http://localhost:3350)SMALL_MODEL_MODE - Enable small model mode (default: false). Equivalent to
the -s flag above.ENABLE_LOGGING - Enable file logging (default: false)VERBOSE_LOGGING - Detailed debug logs (default: false)Example with environment variables:
{
"mcpServers": {
"producer-pal": {
"command": "npx",
"args": ["-y", "producer-pal"],
"env": {
"MCP_SERVER_ORIGIN": "http://localhost:3350",
"ENABLE_LOGGING": "true"
}
}
}
}
Note for Claude Desktop users: The
.mcpb extension bundle
provides an easier setup alternative to npx producer-pal.
For complete documentation, setup guides, and usage examples, visit:
Source code and development:
https://github.com/adamjmurray/producer-pal
MIT License - see LICENSE
FAQs
Stdio-to-HTTP bridge for Producer Pal MCP server
We found that producer-pal demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.