FilmLab
REMOTE · MCP-LAB.THEFILMRADAR.COM · SCANNED OCT 5
AI film lab for filmmakers: generate and review images/clips with input provenance, cost preflight
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability76
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 32442 tokens (~345/item across 94 items; 93 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management3
- Stability check failed: schema churn in the 1 day we've observed: 0 tool removals, 1 breaking changes, 0 auth/transport breaks, 4 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- Manipulation not yet verified: none of the 95 captured unit(s) of tool text has been judged yet, so we will not certify text no model has read as clean.Unverified
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
How do I install the FilmLab MCP server?
FilmLab is a hosted endpoint at https://mcp-lab.thefilmradar.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp-lab.thefilmradar.com
claude mcp add --transport http com-thefilmradar-filmlab 'https://mcp-lab.thefilmradar.com/mcp'
{
"mcpServers": {
"com-thefilmradar-filmlab": {
"url": "https://mcp-lab.thefilmradar.com/mcp"
}
}
} {
"servers": {
"com-thefilmradar-filmlab": {
"type": "http",
"url": "https://mcp-lab.thefilmradar.com/mcp"
}
}
} [mcp_servers.com-thefilmradar-filmlab] url = "https://mcp-lab.thefilmradar.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-thefilmradar-filmlab": {
"type": "remote",
"url": "https://mcp-lab.thefilmradar.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-thefilmradar-filmlab --url 'https://mcp-lab.thefilmradar.com/mcp' --transport streamable-http
mcp_servers:
com-thefilmradar-filmlab:
url: "https://mcp-lab.thefilmradar.com/mcp" {
"McpServers": {
"com-thefilmradar-filmlab": {
"Transport": "http",
"Url": "https://mcp-lab.thefilmradar.com/mcp"
}
}
} assistant mcp add com-thefilmradar-filmlab -t streamable-http -u 'https://mcp-lab.thefilmradar.com/mcp'
{
"mcpServers": {
"com-thefilmradar-filmlab": {
"type": "http",
"url": "https://mcp-lab.thefilmradar.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 5 Oct 26 0
- Stability: unverified → fail ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “lab_whoami” rewrote its description, which is the text the model reads security
- 4 Oct 26 +40
- Transport: unverified → pass ▲ security
- Injection markers: unverified → pass ▲ security
- First check of Judged manipulation: unverified security
- Authorization: Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. security
- MCP protocol: unverified → pass ▲ functional
- Schema quality: unverified → 100 ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: fail functional
- First check of Schema quality: excellent functional
- First check of Schema quality: fail functional
- First check of Capabilities: pass functional
- First check of Destructive annotations: 100 functional
- First check of Tool coverage: 100 functional
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 17 Aug 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 7 Oct 2026 · Probed https://mcp-lab.thefilmradar.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=thefilmradar.com | CN=WE1,O=Google Trust Services,C=US | 6 Sept 2026 | 5 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | e40c48743b6b9189133ceb0cd0ece3c0 |
| SANs: thefilmradar.com, mcp-lab.thefilmradar.com, *.mcp-lab.thefilmradar.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp-lab.thefilmradar.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| thefilmradar.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="OAuth", resource_metadata="https://mcp-lab.thefilmradar.com/.well-known/oauth-protected-resource/mcp", scope="filmlab:read filmlab:write"
Bearer realm="OAuth", resource_metadata="https://mcp-lab.thefilmradar.com/.well-known/oauth-protected-resource/mcp", scope="filmlab:read filmlab:write" Protected resource metadata
| Document | https://mcp-lab.thefilmradar.com/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp-lab.thefilmradar.com/mcp |
| Authorisation server | https://mcp-lab.thefilmradar.com |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp-lab.thefilmradar.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp-lab.thefilmradar.com/mcp | HTTPS enforced | 301 | https://mcp-lab.thefilmradar.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
lab_verkettung Render Clip Chains ~642
Render several clips as CHAINS: within a scene one after another (continuity), across scenes in parallel (speed) — the plan follows scene_ref of each job in order. aktion: plan (free: shows the chains) · preis (free: same checks as a real start; returns preis_geschaetzt_credits and `reicht` against balance, project cap and an active auto run — nothing is created) · starten (COSTS CREDITS, ONLY after the person confirmed the price from aktion=preis). Each clip is charged when it starts; an active lab_auto_lauf cap applies. The FIRST clip of every chain needs an approved start image (keyframe checkpoint, as in lab_animate) unless ohne_keyframe; later clips derive from the chain. Sending starten twice returns the running chain (wiederverwendet: true) instead of paying twice. Transition between clips of a chain (uebergang): schnitt (default) = hard cut to a NEW camera angle — the next clip does NOT start from the last frame; its prompt begins with the previous clip's end state (wardrobe, props, place, light), characters and location come from each job's own character_refs/location_id. durchgehend = the last frame becomes the start image — only for one unbroken take. Follow a started chain with lab_get_job(job_id): result.zusammenfassung (laeuft/fertig/abgebrochen), result.ketten (status and grund per chain) and result.clips (keyed by clip index: video_id, status, fehler_klasse). Job status done only means nothing runs any more — check result.zusammenfassung.abgebrochen before reporting success. A failure stops only its own chain. Dispatch rule: continuous scene → one chain with schnitt; one unbroken motion → a single clip ≤ 15 s, else durchgehend; separate scenes, time jumps, costume changes or montage → separate scenes (parallel). Over ~3 minutes total: suggest narrowing the scope first.
| Name | Type | Req | Description |
|---|---|---|---|
| aktion | string | yes | plan and preis are free; starten costs credits |
| jobs | array | yes | One entry per clip, IN ORDER — the same fields as lab_animate (prompt, scene_ref, tool, duration_seconds, resolution, character_refs, location_id, source_image_id …). scene_ref decides the chains: co… |
| modus | string | – | hybrid (default): chain within scenes; parallel: every clip alone; sequenziell: one chain over everything |
| ohne_keyframe | boolean | – | Skip the keyframe checkpoint on purpose. By default a paid clip only starts from a start image the user has approved (lab_review_asset verdict: accepted) — look at the frame first, then spend on the… |
| project_id | string | yes | Project id (from lab_list_projects) |
| uebergang | string | – | Transition at each cut inside a chain; default schnitt |
No output schema declared.
No examples provided.
lab_vfx VFX Operation ~615
Run a VFX operation on an image already in the project gallery — the same pipeline the Resolve bridge uses. inpaint (clean plate: what is inside the box disappears, the surroundings close over it) · replace (same path, other intent: something new goes into the box) · relight (no box — the light changes across the whole frame; by default the scene stays exactly as it is, licht_weg 'iclight' instead repaints the background and may change the scenery) · mask (no box — you describe what should be cut out and get the matte back). inpaint/replace need `box` AND `prompt`; relight needs `light_preset` or `prompt` and REJECTS a box; mask needs `prompt` and REJECTS a box too. `box` is given in FRACTIONS of the image (0..1), not pixels — the worker builds the mask. inpaint/replace start at 5 credits per run on the reference area (larger areas cost more); relight costs 4 flat per image (licht_weg 'iclight': from 9, by area); mask costs 1, flat per request. Returns immediately with an operation_id; poll lab_vfx_status until status is done|failed. NOT offered here: composite, move, color_grade — the server knows them and has no consumer for them.
| Name | Type | Req | Description |
|---|---|---|---|
| box_breite | number | – | Box width as a fraction of image width |
| box_hoehe | number | – | Box height as a fraction of image height |
| box_x | number | – | Box left edge as a fraction of image width (0..1) |
| box_y | number | – | Box top edge as a fraction of image height (0..1) |
| image_id | string | yes | Id of the source image in the project gallery (from lab_list_assets / lab_generate) |
| licht_weg | string | – | relight only. kontext (default): only the light changes, scene, people and framing stay. iclight: the background is repainted from the light description — the scenery may change |
| light_preset | string | – | relight only. There is no 'bottom' — the server does not carry one |
| operation | string | yes | inpaint: Die rote Werkzeugkiste wird durch eine Holzkiste auf der Werkbank ersetzt. | replace: Derselbe Weg, andere Absicht: in die Box kommt etwas Neues. | relight: Keine Box: die Lichtrichtung wand… |
| project_id | string | yes | Project id (from lab_list_projects) |
| prompt | string | – | inpaint/replace: what should be seen there instead — required. mask: what should be cut out (e.g. 'the red toolbox') — required. relight: optional, replaces the preset |
No output schema declared.
No examples provided.
lab_vfx_status VFX Status ~74
Poll a VFX operation started with lab_vfx. status is pending|processing|done|failed; when done, result_url carries the finished image. Call repeatedly until done|failed — an image run usually takes under 30 seconds.
| Name | Type | Req | Description |
|---|---|---|---|
| operation_id | string | yes | The operation_id returned by lab_vfx |
No output schema declared.
No examples provided.
lab_voice_clone Clone Voice ~498
Clone a voice from real audio or video material into a project (fal.ai minimax voice-clone) — the source for lab_voice_tts and for lab_dub's voice_id+dub_text path. SYNCHRONOUS: the clone runs inside the request and can take a while to return; there is no job_id to poll. The source needs a clean speech track of workable length — too short or silent material is rejected before anything is spent. Voice cloning from real material is consent-sensitive: only clone voices you have the right to use, and the Fish Audio path requires you to say so explicitly.
| Name | Type | Req | Description |
|---|---|---|---|
| einwilligung | boolean | – | Consent of the person whose voice is being uploaded. Required on the fish_audio path, which refuses without it before anything is charged. This is not the moderation gate: that one reads the label fo… |
| get_cost | boolean | – | `true` reports the price and your balance WITHOUT cloning anything and without spending quota. A clone is billed per clone (a MiniMax clone costs far more than a Fish clone — ask with get_cost) — the… |
| name | string | yes | A label for this cloned voice, shown in lab_list_voices — needed to tell several clones of one project apart later. |
| project_id | string | yes | Project id (from lab_list_projects) — positive integer as string |
| provider | string | – | Which voice house clones it. Omit to stay on the default path — an existing workflow does not change vendor just because another one exists. The choice sticks to the voice: whichever house made it is… |
| sample_audio_url | string | yes | URL of the source audio or video the voice is cloned from. Needs a real, sufficiently long speech track — material without one is rejected before anything is spent. |
No output schema declared.
No examples provided.
lab_voice_tts Speak in Cloned Voice ~333
Speak text in a project's cloned voice (via lab_voice_clone) — SYNCHRONOUS, returns a ready audio_url, no job_id. The voice house is whichever one cloned this voice; you do not pick it here. Consent-sensitive like the clone itself: only speak text you have the right to put in that voice's mouth.
| Name | Type | Req | Description |
|---|---|---|---|
| get_cost | boolean | – | Price this call instead of running it: returns the estimate and the balance, charges nothing, produces no audio. Worth doing before a long passage, because both houses bill by the size of the text, n… |
| project_id | string | yes | Project id (from lab_list_projects) — positive integer as string |
| provider | string | – | Cross-check, not a choice: the house that cloned this voice is the one that speaks with it, because a voice id from one house means nothing to the other. Pass it only to assert what you believe the v… |
| text | string | yes | The line(s) to speak in this voice. |
| voice_id | string | yes | A cloned voice's id (lab_cloned_voices.id, from lab_voice_clone or lab_list_voices) — positive integer as string, NOT the raw provider voice id. |
No output schema declared.
No examples provided.
lab_wellenform Waveform ~260
Read the sound of a clip (video_id), an audio track (audio_id) or an uploaded file (project_id + asset_key from lab_add_media) as numbers: peak level 0..1 per channel, 16 values per second, up to 60 s per page. Use it to find where music or speech starts, where silence is (below `stille_unter`), and whether a cut lands on a beat or mid-word — before you move cut points. Continue with `weiter_von_s` for the next page. Read-only, free.
| Name | Type | Req | Description |
|---|---|---|---|
| asset_key | string | – | Storage key of an uploaded sound or video file (from lab_add_media). Needs project_id |
| audio_id | string | – | Audio track id (from lab_list_audio). Give exactly one of video_id, audio_id, asset_key |
| bis_s | number | – | End of the page; at most 60 s after von_s |
| project_id | string | – | Project the asset_key belongs to — required with asset_key |
| video_id | string | – | Generated video id — its own soundtrack. Give this OR audio_id |
| von_s | number | – | Start of the page in seconds (default 0) |
No output schema declared.
No examples provided.
lab_whoami Who Am I ~103
Who is connected: the FilmLab account (email, user id, name, tier, credits) and how this connection signed in (oauth, oauth_geraet, bridge_key, legacy service user, or anonym). For a device sign-in it also lists the device limits (projects, credits, end date). Call it when results look like someone else's — two clients signed in with two accounts see different projects. Works without an account. Read-only, free.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
lab_widerruf Record Correction ~232
Record a correction in the FilmOS knowledge layer when the user contradicts something you asserted from it. Use this the moment a contradiction is stated — not at the end of the session, and not instead of accepting the correction in your answer. It stores the claim AND what is actually true, owned by the user who said it, so lab_wissen surfaces it first next time. It does not delete anything: a deleted false claim returns with the next ingestion, a corrected one does not. Quote the user's own wording for `korrektur` where you can.
| Name | Type | Req | Description |
|---|---|---|---|
| behauptung | string | yes | The claim that is wrong, as it was stated |
| korrektur | string | yes | What is actually true — the user's wording where possible |
| quelle | string | yes | The source_slug the wrong claim came from — take it from a lab_wissen hit. A source that does not exist is refused, not silently stored. |
| thema | string | yes | Short topic, so the correction is findable later |
| url | string | – | Source URL of the claim, if a hit carried one |
No output schema declared.
No examples provided.
lab_wissen Ask Knowledge Layer ~191
Ask the FilmOS knowledge layer — measured craft knowledge from vetted sources, with the KNOWN CORRECTIONS first: documented false assumptions plus what is actually true. Call this before asserting a craft fact you did not measure yourself in this session. Every hit carries its source and its usage_policy; quote within that policy and name the source. An empty result means nothing matched — it never means the claim is true.
| Name | Type | Req | Description |
|---|---|---|---|
| anzahl | integer | – | How many knowledge hits at most (default 8). Corrections come on top. |
| frage | string | yes | The question, in the language the sources are written in |
| mindest_autoritaet | number | – | Authority floor. Defaults to 0.85 — expert voices only. Below that the corpus holds forum members: useful as context, not as the ground for a craft claim. Lower it only deliberately, and say so in th… |
No output schema declared.
No examples provided.
lab_wortzeiten Spoken words ~317
Every spoken word with its start and end time, for a clip (video_id), an audio track (audio_id) or an uploaded file (project_id + asset_key). Use it to cut pauses without cutting into a word, to time captions, or to land a graphic on an exact word — instead of guessing seconds from the waveform. Up to 20 min of sound per source; the first call transcribes (Fish Audio, about 0.36 USD per audio hour, booked to the operator, not your credits), every later call for the same sound is served from the cache for free. Returns at most 300 s of words per page; continue with `weiter_von_s`. Speech recognition spells names the way they sound — check names before you put them on screen.
| Name | Type | Req | Description |
|---|---|---|---|
| asset_key | string | – | Storage key of an uploaded sound or video file (from lab_add_media). Needs project_id |
| audio_id | string | – | Audio track id (from lab_list_audio) |
| bis_s | number | – | End of the page; at most 300 s after von_s |
| project_id | string | – | Project the asset_key belongs to — required with asset_key |
| sprache | string | – | Spoken language (default de) — the same list the backend accepts |
| video_id | string | – | Generated video id — its own soundtrack. Give exactly one of video_id, audio_id, asset_key |
| von_s | number | – | Start of the page in seconds (default 0) |
No output schema declared.
No examples provided.
lab_zielgruppe Audience & Markets ~388
Read or set a project's audience (zielgruppe) and target markets (zielmaerkte). With project_id only: read. Set zielgruppe 'kinder' or 'jugendliche' whenever the project is made for children, families or teenagers — do it BEFORE creating characters or generating. That switches on blocks for the whole project: the adult mode is off even for unlocked accounts, real people are refused (likeness photos, voice clones, lipsync with a consent id, digital doubles as characters), generation stops instead of running unchecked when the content check is down, and the export must mark the whole film as AI. Setting it fails with a readable conflict while a digital double sits in the cast — take it out first. An empty string clears the audience. zielmaerkte (ISO country codes of the researched European countries plus 'EU'; 'UK' is accepted for GB) blocks nothing: it adds a checklist per country of what the customer must observe when delivering there (age rating scale, national AI label, registration duties for creator channels, advertising rules, warnings). The list replaces the previous one; an empty list clears it. The answer always carries zielgruppe, zielmaerkte, zielgruppe_regeln (the active blocks as sentences) and zielmarkt_checkliste — pass the checklist on to the person, it is not legal advice.
| Name | Type | Req | Description |
|---|---|---|---|
| project_id | string | yes | Project id (from lab_list_projects) |
| zielgruppe | string | – | Audience of the project: 'kinder', 'jugendliche' or 'erwachsene'; an empty string clears it. Omit to leave it unchanged |
| zielmaerkte | array | – | Target markets as ISO country codes plus 'EU', e.g. ['DE', 'AT', 'CH']. Replaces the whole list; an empty list clears it. Omit to leave it unchanged |
No output schema declared.
No examples provided.
What is the FilmLab MCP server?
FilmLab is an MCP server listed in the public MCP registry as com.thefilmradar/filmlab. AI film lab for filmmakers: generate and review images/clips with input provenance, cost preflight. This page covers its hosted endpoint (https://mcp-lab.thefilmradar.com/mcp).
Is the FilmLab MCP server safe to use?
FilmLab scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the FilmLab MCP server expose?
FilmLab exposes 111 tools: lab_list_projects, lab_wissen, lab_widerruf, lab_playbook, lab_list_models, and 106 more. Their descriptions and schemas cost roughly 39,090 tokens of context every time the server is loaded.
Does the FilmLab MCP server require authentication?
Yes. FilmLab asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the FilmLab MCP server still maintained?
FilmLab is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.