Atlas / MCP servers / chroneus / Vibetrack

VibetrackBLOCK

mcp/chroneus/vibetrack

Modern experiment tracking that follows you across servers, messengers, and LLMs.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
15 14r · 1w · 0d
Transport
streamable-http
License
NOASSERTION
Stars
29
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Modern experiment tracking.

Key features:

  • Send experiment results elsewhere: Telegram, Slack, Jupyter, Gradio, and MCP.
  • Run locally while receiving experiment data over the network via REST API.
  • Use open formats: experiment data is stored in SQLite and local files.
  • Compare image-to-image results.
  • Use a rich UI to show, hide, delete, and customize runs.
  • TensorBoard SummaryWriter compatible drop-in APIs.
  • Query results through the MCP server.
  • Fast scalar logging; see the benchmark report.

Install

pip install vibetrack          # default with web
pip install vibetrack[all]     # all optional backends+dev; MCP on Python >=3.10

Quick start

TensorBoard-style API

from vibetrack import SummaryWriter

writer = SummaryWriter("runs/exp1", project_folder="my_project")
for step in range(100):
writer.add_scalar("loss", 1.0 / (step + 1), step)
writer.add_scalar("acc", step / 100, step)
writer.close()

See API.md for SummaryWriter and module-level logging examples.

Launch the dashboard

vibetrack --listen 0.0.0.0:6116
# -> Web UI on http://you_server:6116
# -> MCP is also mounted when installed with vibetrack[all] on Python 3.10+

Viewers and destinations syntax


writer = SummaryWriter("runs/exp1", project_folder="my_project")
writer.to("console").to("slack", every="15m")
writer.to("remote", url="http://server:8080", token="devtoken")
writer.add_scalar("loss", 0.5, step=0).to("telegram")

See VIEWERS.md for web, console, Slack, Telegram, Gradio, Jupyter, custom viewers, remote forwarding, credentials, and HTTP ingest.

vibetrack Architecture

flowchart TB
su
Read from source at commit 6798f3d8e6f0OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add vibetrack --env LLM_API_KEY=${LLM_API_KEY} --env SLACK_BOT_TOKEN=${SLACK_BOT_TOKEN} --env VIBETRACK_REMOTE_TOKEN=${VIBETRACK_REMOTE_TOKEN} --env VIBETRACK_TELEGRAM_TOKEN=${VIBETRACK_TELEGRAM_TOKEN} -- uvx vibetrack
claude-desktop
{
  "mcpServers": {
    "vibetrack": {
      "command": "uvx",
      "args": [
        "vibetrack"
      ],
      "env": {
        "LLM_API_KEY": "${LLM_API_KEY}",
        "SLACK_BOT_TOKEN": "${SLACK_BOT_TOKEN}",
        "VIBETRACK_REMOTE_TOKEN": "${VIBETRACK_REMOTE_TOKEN}",
        "VIBETRACK_TELEGRAM_TOKEN": "${VIBETRACK_TELEGRAM_TOKEN}"
      }
    }
  }
}
03

Exposed tools (15)

14 read · 1 write · 0 destructive.

ToolRiskDescription
analyze_scalarreadSummarize a scalar graph: min/max, best step, trend, plateau, events.
compare_hparams_toolreadCompare hyperparameters across experiments side-by-side.
compare_image_lpipsreadCompare two logged images with LPIPS when installed plus pixel metrics.
compare_scalarreadRank experiments by best value for one scalar tag.
find_metric_eventsreadFind notable scalar graph events such as extrema, jumps, and plateau.
get_audioreadGet audio entries (step, path, sample_rate) for a specific tag.
get_experiment_tagsreadGet all available tags for an experiment, grouped by type.
get_histogramsreadGet histogram data for a specific tag in an experiment.
get_hparamsreadGet hyperparameters for an experiment.
get_imagesreadGet image entries (step, path) for a specific tag.
get_scalarsreadGet scalar time-series data for a specific tag in an experiment.
get_textsreadGet text entries for a specific tag in an experiment.
list_experimentsreadList all experiments in the project database.
run_reportwriteGet a human-readable end-of-run digest for one experiment.
summaryreadGet a summary table: last value of each tag per experiment.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (10)

CRITICALObfuscation / stealth · obf.decode_then_exec · CWE-506, CWE-94
vibetrack/viewers/web/vendor/three.min.js:6
atob( ... new function(
Why it matters. decodes a payload and executes it
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
vibetrack/viewers/__init__.py:61
module = importlib.import_module(viewers[name])
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/test_outputs.py:919
resp = _call_app_route(client._app, "/media", path="/etc/passwd")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_media.py:213
filename="../../owned.txt",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/MCP.md:36
http://127.0.0.1:6116/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/MCP.md:141
LLM_BASE_URL=http://127.0.0.1:11434/v1 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/VIEWERS.md:10
# -> Web UI on http://0.0.0.0:6116
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
examples/arch_search_mcp.py:52
MCP_URL = f"http://127.0.0.1:{MCP_PORT}/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
examples/arch_search_mcp.py:54
LLM_BASE_URL = os.getenv("LLM_BASE_URL", "http://127.0.0.1:11434/v1").rstrip("/")
INFOInventory / provenance · inv.oversize · CWE-1104
docs/showcase.gif
docs/showcase.gif
Why it matters. 3770868 bytes not read

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6798f3d8e6f0full audit observations/trust-audit/mcp-server/chroneus__vibetrack.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086798f3d8e6f0BLOCKD69first audit
06

Questions

What is the Vibetrack MCP server?

Modern experiment tracking that follows you across servers, messengers, and LLMs.

What tools does Vibetrack expose?

15 in total: 14 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Vibetrack safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Vibetrack need?

It reads LLM_API_KEY, SLACK_BOT_TOKEN, VIBETRACK_REMOTE_TOKEN and VIBETRACK_TELEGRAM_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Vibetrack run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as vibetrack.

How current is this page?

The grade is for one exact copy of the source (6798f3d8e6f0), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement