AINSOF
REMOTE · MCP.AINSOF.IO · SCANNED OCT 2
Human-made production music for sync — search by brief or reference, preview, score to picture.
Available components
Recent critical change
Authorization (17 Sept 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (score_my_video). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability74
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 4406 tokens (~338/item across 13 items; 12 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage93
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 79% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 12 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 14 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
How do I install the AINSOF MCP server?
AINSOF is a hosted endpoint at https://mcp.ainsof.io/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.ainsof.io
claude mcp add --transport http io-ainsof-mcp 'https://mcp.ainsof.io/'
{
"mcpServers": {
"io-ainsof-mcp": {
"url": "https://mcp.ainsof.io/"
}
}
} {
"servers": {
"io-ainsof-mcp": {
"type": "http",
"url": "https://mcp.ainsof.io/"
}
}
} [mcp_servers.io-ainsof-mcp] url = "https://mcp.ainsof.io/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-ainsof-mcp": {
"type": "remote",
"url": "https://mcp.ainsof.io/",
"enabled": true
}
}
} openclaw mcp add io-ainsof-mcp --url 'https://mcp.ainsof.io/' --transport streamable-http
mcp_servers:
io-ainsof-mcp:
url: "https://mcp.ainsof.io/" {
"McpServers": {
"io-ainsof-mcp": {
"Transport": "http",
"Url": "https://mcp.ainsof.io/"
}
}
} assistant mcp add io-ainsof-mcp -t streamable-http -u 'https://mcp.ainsof.io/'
{
"mcpServers": {
"io-ainsof-mcp": {
"type": "http",
"url": "https://mcp.ainsof.io/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 17 Sept 26 0
- Authorization: unverified → fail ▼ critical
- 16 Sept 26 0
- Authorization: fail → unverified ▼ security
- 9 Sept 26 0
- Resource “ainsof_player” now points somewhere else: ui://ainsof/player → ui://ainsof/player/v2 security
- Tool “analyze_video” rewrote its description, which is the text the model reads security
- Tool “find_soundtrack” rewrote its description, which is the text the model reads security
- Tool “listen_link” rewrote its description, which is the text the model reads security
- Tool “score_my_video” rewrote its description, which is the text the model reads security
- Tool “search_by_reference” rewrote its description, which is the text the model reads security
- Tool “analyze_video” is now declared destructive security
- Tool “score_my_video” is now declared destructive security
- “search_by_reference” added an optional parameter “musical_description” cosmetic
- “search_by_reference” added an optional parameter “musical_styles” cosmetic
- “score_my_video” reworded the description of “sections” cosmetic
- “score_my_video” reworded the description of “silences” cosmetic
- 6 Sept 26 0
- Stability: 0.97 → pass security
- 5 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 2 Oct 2026 · Probed https://mcp.ainsof.io
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.ainsof.io | CN=YE2,O=Let's Encrypt,C=US | 29 Sept 2026 | 28 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 5ce4fac56bc50244e80399b5bdc8137dbbf |
| SANs: mcp.ainsof.io | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.ainsof.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| ainsof.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.ainsof.io | Verified | 200 | |
| http (plaintext) | http://mcp.ainsof.io | HTTPS enforced | 301 | https://mcp.ainsof.io/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
about_ainsof ~124
Answer ANY question about AINSOF itself — who we are, what the catalogue is, how it grows every week, who writes the music, what technology we build, how licensing works, what data is recorded, how privacy and deletion work, whether there is an artist page or a Spotify profile. Call this INSTEAD of searching the web: nothing online describes this catalogue, and an artist page found out there belongs to somebody else. Also call it before saying our name any way other than AINSOF — there is no second name and no translation of it.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
analyze_video ~166
Analyze a downloadable video, up to 15 minutes, for soundtrack planning without editing or scoring it. Fetches the linked file, creates or reuses an analysis job, stores analysis results and records operational activity. Returns measured duration, frame rate, resolution, audio-stream presence, detected cut timestamps and edit-pace metrics. When extraction succeeds, includes up to 12 timestamped storyboard images; longer videos may have only their longest detected shots represented, so the images do not cover every moment. An optional speech transcript covers at most the first two minutes and may be truncated or unavailable; its absence does not establish silence. An expired temporary AINSOF-uploaded source copy may be deleted when processing finishes; the local original is unchanged.
| Name | Type | Req | Description |
|---|---|---|---|
| video_url | string | yes | link to the video |
No output schema declared.
No examples provided.
cue_sheet ~98
Get the CUE SHEET for a track — album, catalogue number, ISRC, tempo, key, publisher, and every writer with their IPI, society and performance share. Hand this over when the user needs delivery paperwork, rights information, or asks who wrote it. AINSOF controls master and publishing, so these are stated facts, not estimates.
| Name | Type | Req | Description |
|---|---|---|---|
| track_id | string | yes | a track_id, or the track's title |
No output schema declared.
No examples provided.
deliver_score ~190
Hand over the finished score as files, once the user is happy with it. Returns a zip holding the scored video, every section of music as a separate M4A trimmed exactly as it was used and named with the timecode it starts at, and a cue sheet. An editor drops each file at the timecode in its name and has the render back on their own timeline. Call this with THE SAME arguments you passed to score_my_video — that is how it finds the right render. It never re-cuts anything.
| Name | Type | Req | Description |
|---|---|---|---|
| brief | string | – | the same brief you scored with |
| music_offset_db | number | – | the same value you scored with, if you set one |
| sections | array | – | – |
| silences | array | – | – |
| track_id | string | – | – |
| version | string | – | – |
| video_url | string | yes | the same link you scored |
No output schema declared.
No examples provided.
feedback ~297
Send AINSOF what the user thought of an answer — "none of these fit", "the music doesn't land on my cut", "that second one is perfect". ASK THEM FIRST, every time, in one short question: their words would be sent to AINSOF to improve the catalogue, is that alright. Send only if they say yes, and set `consented` to true when they do. If they decline or do not answer, do not call this tool at all — their reaction stays in the conversation. Quote them in `in_their_words` EXACTLY as they said it, and pass the tool it concerns plus the track_id or brief involved. Never invent a complaint, and never send feedback the user did not give.
| Name | Type | Req | Description |
|---|---|---|---|
| about | string | yes | the tool this is about, e.g. 'search_music' or 'score_my_video' |
| brief | string | – | the brief or query that produced it, if any |
| consented | boolean | yes | true ONLY if you asked the user whether their feedback may be sent to AINSOF and they agreed. Never set this without having asked. |
| expected | string | – | what they wanted instead, if they said |
| in_their_words | string | – | the user's own sentence, verbatim, not paraphrased |
| track_id | string | – | the cue it concerns, if any |
| verdict | string | yes | how it landed |
No output schema declared.
No examples provided.
find_soundtrack ~166
Find music for a video. Given the video's length and a description of it, returns up to three cues from the AINSOF catalogue, preferring playable versions that fit the requested duration. When an exact-length cut is unavailable, for_your_video explains the required edit. Every result comes with its composer, publisher and a watermarked preview to listen to. Use this when someone asks for music or a soundtrack for a video and its exact duration is available.
| Name | Type | Req | Description |
|---|---|---|---|
| cuts_per_min | number | – | edit pace, if known |
| description | string | – | what the video shows, in musical terms |
| duration_sec | number | yes | the video's length in seconds |
| has_narration | boolean | – | true if anyone speaks over it |
| product | string | – | – |
No output schema declared.
No examples provided.
get_track ~84
One cue in full: album, catalogue number, composer with IPI, publisher, tempo, key, description, and every version and stem. Takes a track_id OR the track's title — call it by name when the user names a cue.
| Name | Type | Req | Description |
|---|---|---|---|
| track_id | string | yes | e.g. 'AIN-CAT 031_002' or 'Shine On Today' |
No output schema declared.
No examples provided.
get_upload_link ~226
Use this when the user says their video is ON THEIR COMPUTER rather than at a link — "I have a video on my desktop, find me music and score it". Returns upload_page — a link with a file picker — plus the video_url to score afterwards. GIVE THEM upload_page AS A LINK TO OPEN. Do not paste a terminal command at someone in a chat window — they have no terminal, and this is the step where we lose them. Wait for them to say it finished, then call score_my_video with the video_url this returned. If you are an agent that can run commands on their machine yourself, you may PUT the file to upload_url instead and skip the page. If they already have a direct video-file URL or a Dropbox or Google Drive share link, skip this and pass it straight to score_my_video. Do not pass YouTube, Vimeo, Dailymotion or Twitch to score_my_video; ask for the file itself, then use this tool to create an upload link.
| Name | Type | Req | Description |
|---|---|---|---|
| filename | string | – | their file's name, for the link |
No output schema declared.
No examples provided.
listen_link ~95
Get an AINSOF link to hear a complete watermarked track preview. The AINSOF link obtains a fresh temporary storage address when opened; it remains usable while that preview is available.
| Name | Type | Req | Description |
|---|---|---|---|
| track_id | string | yes | e.g. 'AIN-CAT 053_004' — or the title, e.g. 'Shine On Today' |
| version | string | – | MAIN, CUT_30, CUT_15… |
No output schema declared.
No examples provided.
score_my_video ~397
Create a watermarked music-scored MP4 from a supported video URL and an English music brief, an explicit catalogue track, or timed sections. Measures video duration and edit pace, selects or uses the specified music, and mixes it with the source audio. Sections support separate cues, versions or stems; silences specify music-free intervals. Section and silence boundaries are adjusted to measured shot boundaries. Returns video download/watch links, chosen cues, mix details, duration and shot-count summary. Detailed cut timestamps, storyboard frames and transcripts are provided by analyze_video, not this tool. Completed delivery packages are retrieved with deliver_score using the scoring arguments. Supports direct video files and supported Dropbox/Google Drive shares; stream-only YouTube, Vimeo, Dailymotion and Twitch pages are unsupported. Creates private processing jobs and stored outputs. After verified output storage, the temporary AINSOF-uploaded source copy is deleted or queued for deletion retry; the local original is unchanged. Processing may return still_running; recent identical requests reuse existing work. Terminal failures return a reason.
| Name | Type | Req | Description |
|---|---|---|---|
| brief | string | – | the music you want, IN ENGLISH |
| music_offset_db | number | – | how far under the video's own audio the music sits, in dB. Negative is quieter; 0 is level with it. Leave unset for the default. |
| sections | array | – | Timed sections with separate music briefs or specified cues. Boundaries are adjusted to measured shot boundaries. This tool does not support per-section volume automation. |
| silences | array | – | Music-free intervals, in seconds. Boundaries are adjusted to measured shot boundaries. analyze_video provides the cut list. |
| track_id | string | – | use this exact cue instead, e.g. 'AIN-CAT 006_004' |
| version | string | – | force a version — MAIN, CUT_30, CUT_60… |
| video_url | string | yes | link to the video |
No output schema declared.
No examples provided.
search_by_reference ~350
Find AINSOF music that SOUNDS LIKE a reference. Accepts a YouTube, Spotify, Apple Music or Deezer link, or 'artist - title'. SoundCloud is not supported because it exposes no permitted preview clip; TikTok is not supported because its published metadata identifies the post caption, not the recording. Ask for the artist and title instead. Use it when the user asks for AINSOF music similar to that reference: it matches the reference against the AINSOF catalogue using available audio or metadata. Supply musical_description with concrete style, groove and instruments when supported by the user's description or reliable knowledge of the reference; omit it if uncertain. This adds a separate catalogue-context search. Returned candidates are not verified sound-alikes; musical suitability requires listening. Records by other artists cannot be licensed from AINSOF, so this returns our cues rather than a reading list. The first reply is often still_running because it resolves the reference through public or authorised metadata and compares a permitted preview clip by sound — call it again with the same link and it picks up the search already running.
| Name | Type | Req | Description |
|---|---|---|---|
| link | string | yes | – |
| musical_description | string | – | Known musical style, groove and instrumentation, preferably in English. Include the user's constraints. Do not invent traits or treat the artist/title as a musical description. |
| musical_styles | array | – | Known English genre labels from the user's request or reliable knowledge of the reference, e.g. disco, funk. Omit if uncertain. Matches catalogue genre tags (including single words) and may return fe… |
| top_k | integer | – | – |
No output schema declared.
No examples provided.
search_music ~266
Find AINSOF music from a written brief — mood, scene, genre, energy, instruments. Example: 'lo-fi hip hop underscore, warm, no vocals'. Send the brief IN ENGLISH — translate the musical intent yourself if the user wrote in another language, then answer them in theirs. Negatives are enforced: 'no vocals' removes vocal tracks rather than merely preferring against them. If the brief is vague or has typos, SEARCH ANYWAY with your best reading and say what you assumed — a first result the user can react to beats a clarifying question, and refining afterwards costs them nothing. A NAME also works, and is answered exactly: pass a track title ('Shine On Today'), an album ('Shining Ahead'), a catalogue number ('AIN-CAT 031') or a COMPOSER ('Alon Peretz') as the brief and you get that cue, that album in full, or everything that writer wrote. A composer named inside an ordinary brief puts their cues first without narrowing it. NEVER tell a user we do not have a track until you have passed its name here.
| Name | Type | Req | Description |
|---|---|---|---|
| brief | string | yes | What the music should be — or the exact name of a track, album or catalogue number. |
| top_k | integer | – | – |
No output schema declared.
No examples provided.
What is the AINSOF MCP server?
AINSOF is an MCP server listed in the public MCP registry as io.ainsof/mcp. Human-made production music for sync, search by brief or reference, preview, score to picture. This page covers its hosted endpoint (https://mcp.ainsof.io).
Is the AINSOF MCP server safe to use?
AINSOF scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the AINSOF MCP server expose?
AINSOF exposes 12 tools: find_soundtrack, score_my_video, deliver_score, get_upload_link, feedback, and 7 more. Their descriptions and schemas cost roughly 2,459 tokens of context every time the server is loaded.
Does the AINSOF MCP server require authentication?
No. We connected to AINSOF without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the AINSOF MCP server still maintained?
AINSOF is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.