
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
pitch-mcp
Advanced tools
MCP server for real-time pitch detection and score alignment. Listens to a singer via microphone and reports their current position in a score and whether they are singing in tune.
Covers three goals:
Supports both offline analysis of pre-recorded audio and real-time microphone input.
| Tool | Description |
|---|---|
analyze_recording | Offline: analyse a WAV file against a reference MusicXML score |
load_score | Load a MusicXML score into a named session; returns a session_id |
start_monitoring | Open the microphone and begin real-time pitch detection |
get_current_position | Poll the current score position and pitch accuracy |
stop_monitoring | Stop the microphone and return a session summary |
list_capabilities | Return server metadata: pitch backend, microphone availability |
health_check | Check that runtime dependencies (librosa, sounddevice/portaudio) are available |
cd pitch-mcp
uv sync
For real-time monitoring (start_monitoring), PortAudio is required:
# Ubuntu / Debian
sudo apt install libportaudio2
Quick install: on Ubuntu/Debian/Linux Mint, bash install.sh handles uv and the optional
libportaudio2 install for you — see SETUP.md for the full non-technical walkthrough.
Ready-made client configs (Claude Desktop, Cursor, Windsurf, Continue, Zed) are in
examples/. If something goes wrong, check TROUBLESHOOTING.md.
uv run pitch-mcp
| Variable | Default | Description |
|---|---|---|
PITCH_BACKEND | librosa | Pitch detection algorithm: librosa or crepe |
crepe requires a manual TensorFlow install (~500 MB) and downloads ~50 MB of model weights on first use. The default librosa backend (pYIN algorithm) works well for singing voice with no extra setup.
// Offline analysis of a recording
{
"tool": "analyze_recording",
"arguments": {
"wav_path": "/path/to/recording.wav",
"musicxml_path": "/path/to/score.mxl",
"part_name": "Soprano"
}
}
// Real-time session
{"tool": "load_score", "arguments": {"musicxml_path": "/path/to/score.mxl", "part_name": "Alto"}}
// → returns {"session_id": "abc123"}
{"tool": "start_monitoring", "arguments": {"session_id": "abc123"}}
{"tool": "get_current_position", "arguments": {"session_id": "abc123"}}
// → returns measure, beat, expected pitch, detected pitch, accuracy
{"tool": "stop_monitoring", "arguments": {"session_id": "abc123"}}
Audio must be 16-bit PCM WAV. MP3 and FLAC are not supported.
# Unit tests (no microphone or audio required)
VIRTUAL_ENV= .venv/bin/pytest tests/ -v
# Integration tests (offline analysis against a committed fixture pair)
VIRTUAL_ENV= .venv/bin/pytest tests/ -v -m integration
# Manual tests (real microphone required — skip in CI)
VIRTUAL_ENV= .venv/bin/pytest tests/ -v -m manual
112 of the 118 total tests are unit tests, run against mocks and synthetic (in-memory) WAV data —
none require real audio hardware or pre-recorded fixtures. The other 6 are marked integration
(4 — offline analysis against the committed tests/fixtures/ pair) or manual (2 — full
real-microphone session lifecycle) and are excluded from a plain pytest tests/ run by
tests/conftest.py; select them explicitly with -m integration / -m manual.
libportaudio2 — required for real-time microphone input (start_monitoring)| Phase | Status |
|---|---|
| Phase A — offline analysis | Complete. DTW-based alignment (dtaidistance); 112 unit tests plus 4 -m integration tests against a committed fixture pair (tests/fixtures/) |
| Phase B — real-time monitoring | Complete. Position tracking is audio-driven (matches detected pitch, not just elapsed time); tempo_bpm override supported. Covered by unit tests with mocked sounddevice; full-lifecycle -m manual tests exist for real-microphone verification but require real hardware to run |
FAQs
MCP server for real-time pitch detection and score alignment using microphone input
We found that pitch-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.