The artifact exists.
Audionaut 1.6.4 has release files for macOS, Windows, and Linux. The Linux AppImage downloaded successfully and matched the SHA-256 digest published by GitHub. Its AppImage runtime answered without installing the application.[2]
That check proves the release file exists and its wrapper starts on one Linux host. It does not prove audio-device support, project compatibility, MCP setup, editing behavior, or export quality.
The thin adapter is the right shape.
The MCP server does not contain a second audio engine. Each tool maps to one Audionaut command, adds --json and --quiet, then returns the command's result envelope. The server exposes editing verbs for importing, splitting, moving, fading, time changes, analysis, stem separation, and export.[3]
This keeps the GUI, command line, and agent on one command path. It also makes the boundary inspectable. Tool schemas name paths, units, limits, and known errors instead of asking a model to invent command syntax.
The useful unit of agent control is not the prompt. It is the reversible application transaction.
Open and closed projects need different routes.
If the project is open, Audionaut routes the command to the running application. The command works on the visible document, including unsaved changes. The result enters undo history as one step, and Project.json stays untouched.[1]
If the project is closed, the command reads and writes the project file. If the application holds the project but cannot be reached, the command fails instead of falling back to a stale file. If the person changes the document while the command runs, Audionaut drops the result and asks the agent to retry. Recording blocks commands. Playback blocks export.[1]
These are product decisions, not protocol guarantees. The MCP security guidance treats local servers as code execution risks and recommends sandboxing and consent for sensitive operations. A local transport does not make a tool harmless.[4]
Copy the custody pattern.
- Map each agent tool to one application command.
- Route open documents through the live application state.
- Commit the whole command as one native undo transaction.
- Fail closed when live state cannot be reached.
- Reject a result when the person changed the document during the command.
- Keep save, publish, and destructive export decisions visible.
The signal console below explains those routes and drafts a test card. It does not connect to Audionaut, edit audio, register an MCP server, or prove the behavior on your machine.