# ElevenLabs MCP Server

> ElevenLabs MCP Server is an officially published MCP server from ElevenLabs. Anomity scores its risk at 45 out of 100 (medium). It matches 1 dangerous capability combination.

- **Canonical URL:** https://catalog.anomity.ai/mcp/elevenlabs-mcp-server
- **Kind:** MCP server
- **Publisher:** ElevenLabs
- **Trust level:** official
- **Risk score:** 45/100 (medium)
- **Website:** https://elevenlabs.io/docs/api-reference/mcp
- **Documentation:** https://elevenlabs.io/docs/api-reference/mcp
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/mcp/elevenlabs-mcp-server

## Description

ElevenLabs' official server exposes text-to-speech, voice cloning, and audio processing to agents, letting an assistant generate narration or transform audio as part of a larger workflow.

Declared capabilities are outbound network access, credential access for the API key, and filesystem writes for the audio files it produces. The distinctive risk is not technical but content-shaped: voice cloning under agent control means a model can be asked to synthesise a specific person's voice as a side effect of some larger task. Whatever policy your organisation has about synthetic voice should be enforced at the key, because the agent will not apply it on its own.

## Why it scored 45

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Published by the vendor | -40 | trust offset |  |
| 2 high-risk capabilities: credentials:access, filesystem:write | +20 | critical |  |
| Credential theft risk (high) | +15 | high | Filesystem write combined with credentials access can plant persistent credential stealers. |

Clamped result: **45/100**, band **medium**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |
| `credentials:access` | Credentials access | Reads provider API keys, OAuth tokens, or other secrets from the host keychain or environment. |
| `filesystem:write` | Filesystem write | Can create, edit, or delete files on the host system. High-impact capability — anything from helpful edits to planting persistence. |

## Dangerous combinations matched

### Credential theft risk (high)

Filesystem write combined with credentials access can plant persistent credential stealers.

Capabilities: `filesystem:write`, `credentials:access`

## Related MCP servers

- [MiniMax MCP Server](https://catalog.anomity.ai/mcp/minimax-mcp-server) — risk 45 (medium)
- [Blender MCP](https://catalog.anomity.ai/mcp/blender-mcp) — risk 100 (critical)
- [Airtable MCP Server](https://catalog.anomity.ai/mcp/airtable-mcp-server) — risk 45 (medium)
- [Cloudflare MCP Server](https://catalog.anomity.ai/mcp/cloudflare-mcp-server) — risk 45 (medium)
- [MongoDB MCP Server](https://catalog.anomity.ai/mcp/mongodb-mcp-server) — risk 45 (medium)
- [Neon MCP Server](https://catalog.anomity.ai/mcp/neon-mcp-server) — risk 45 (medium)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
