← MCP servers · engasnm111

lnwjud

BLOCKgrade F · trust 48/100

lnwjud — local AI-agent runtime & MCP gateway

ai agentsai toolsautomationchatgptclaudecodexdesktop automationdeveloper tools

Overview

From the repository's own README, as read at the audited commit.

<p align="center">  <img src="assets/logo/logo-256x256.png" width="160" alt="lnwjud logo" /></p><h1 align="center">lnwjud</h1><p align="center">  <strong>Cross-platform local AI-agent runtime and MCP gateway</strong><br />  <em>253 total tool definitions for local files, Git, processes, Windows automation, WSL, browser control, durable goal continuation, context capsules, indexing, observability, ECC integration, and extensibility; 241 are advertised by default and all 253 when Codex delegation plus Agent Swarm is enabled.</em></p><p align="center">  <em>อ่านที่เหลือใน Readme ได้เลยครับ ติดปัญหาทักมาได้ใน <a href="https://url.in.th/rEZiG"><strong>Line</strong></a> ได้ตลอดครับ / กําลังพัฒนาให้เรื่อยๆครับ ท่านที่ถามหาช่องสนับสนุนค่ากาแฟ แปะลิงก์ไว้ให้แล้วครับ ขอบคุณครับ — <a href="https://easydonate.app/abcz"><strong>Donate</strong></a></em></p><p align="center">  <a href="https://github.com/engasnm111/lnwjud/releases/latest"><img alt="GitHub Release" src="https://img.shields.io/github/v/release/engasnm111/lnwjud" /></a>  <a href="LICENSE"><img alt="License" src="https://img.shields.io/badge/license-MIT-blue.svg" /></a>  <img alt="Platform" src="https://img.shields.io/badge/platform-Windows%20%7C%20macOS%20%7C%20Linux-0078D4" />  <img alt="Node" src="https://img.shields.io/badge/Node.js-24.x-339933" />  <img alt="MCP" src="https://img.shields.io/badge/MCP-253%20tools-6f42c1" /></p><h2 align="center">Download lnwjud</h2><p align="center">Choose your platform and download the current v5.2.0 release directly.</p><table align="center">  <tr>    <td align="center" width="33%">      <a href="https://github.com/engasnm111/lnwjud/releases/latest/download/lnwjud-Setup-5.2.0.exe">        <img src="assets/download/download-windows.svg" width="300" alt="Download lnwjud for Windows" />      </a><br />      <sub><a href="https://github.com/engasnm111/lnwjud/releases/latest/download/lnwjud-Portable-5.2.0.exe">Portable x64</a></sub>    </td>    <td align="center" width="33%">      <a

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add fixture-node-vite --env APPLE_API_KEY=${APPLE_API_KEY} --env CONTROL_PLANE_API_KEY=${CONTROL_PLANE_API_KEY} --env LNWJUD_CHECKPOINT_KEY_BASE64=${LNWJUD_CHECKPOINT_KEY_BASE64} --env LNWJUD_E2E_EPHEMERAL_SECRETS=${LNWJUD_E2E_EPHEMERAL_SECRETS} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "fixture-node-vite": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "APPLE_API_KEY": "${APPLE_API_KEY}",
        "CONTROL_PLANE_API_KEY": "${CONTROL_PLANE_API_KEY}",
        "LNWJUD_CHECKPOINT_KEY_BASE64": "${LNWJUD_CHECKPOINT_KEY_BASE64}",
        "LNWJUD_E2E_EPHEMERAL_SECRETS": "${LNWJUD_E2E_EPHEMERAL_SECRETS}"
      }
    }
  }
}

Exposed tools (84) 65 read · 17 write · 2 destructive

Blast radius: 2 tools can delete or overwrite. An agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
READMEreadProject docs
SmokereadSmoke
accessibilityreadAccessibility
advance_goal_iterationreadAdvance one bounded review/improvement iteration under the durable goal lease. It never sends browser messages or creates an autonomous ChatGPT UI loop and cannot exceed maxIterations.
breadd
clipboardwriteRead or write the host clipboard (text or PNG image as base64). Use get_text/get_image to read and set_text to write.
codex_runwriteDelegate an instruction to the local Codex CLI in the Active Project. Starting Codex requires explicit chat confirmation and host approval in standard mode; trusted Full Bypass skips those lnwjud application checks without forging userConfirmed.
codex_statusreadReport local Codex installation and capabilities without credential inspection.
codex_stopwriteStop an owned Codex task process after explicit chat confirmation in standard mode. Trusted Full Bypass skips the lnwjud confirmation gate; task ownership still applies.
codex_task_listreadList local Codex task handles owned by this client, including launches whose response was cancelled.
codex_task_logsreadRead bounded logs for an owned Codex task.
codex_task_statusreadRead status for an owned Codex task.
context_pressurereadEstimate local durable-context pressure from the goal snapshot and latest capsule. This never claims exact ChatGPT/provider context usage when the host does not expose it.
copy_filereadCopy a file or directory within one workspace, creating missing destination parents.
create_context_capsulewriteCreate and publish a bounded immutable context capsule from authoritative durable goal state for compact/resume or handoff. Stores decisions/results, not private chain-of-thought, and never opens, clicks, types into, or creates a ChatGPT browser conversation.
delete_filedestructivedelete
demoreadFirst line Second line
dom_cdpreadBrowser
file_dialogwriteOpen a host-native file open/save dialog and return the chosen path(s). The dialog does not read or write files itself; use the guarded file tools afterwards.
get_context_capsulereadRead one immutable durable context capsule by ID.
get_goalreadRead the latest durable goal snapshot without changing state or returning a lease token.
get_goal_planreadRead the user-facing plan projection, acceptance criteria, intent revision, and bounded-iteration policy from authoritative durable goal state. This is a projection, not a second workflow engine.
git_diffreadReturn a bounded read-only Git diff. For writes use the git tool.
git_logreadReturn bounded structured Git history. For writes use the git tool.
git_statuswriteInspect parsed read-only Git status. For writes (init, add, commit, remote, push, rm, clean, reset) use the git tool.
hangreadHang tool
healthreadHealth
health_checkreadHealth
input_eventreadInput
list_checkpointswriteList encrypted pre-mutation checkpoints for one workspace without returning saved file content.
list_context_capsulesreadList bounded context-capsule lineage for one durable goal.
list_delivery_receiptsreadList bounded durable dispatch receipts for a goal.
list_goalswriteList a bounded set of durable goals owned by the current stable MCP client, optionally filtered by workspace/status.
list_recovery_itemsreadList trusted Recovery Trash entries for one workspace, including deleted items, binary pre-replacement backups, original paths, timestamps, payload availability, and the local Recovery Trash root.
mcp_describereadConnect to one local MCP server (if needed) and return its tool names, descriptions, and input schemas. This operation only inspects the child tool catalog.
mcp_listreadList local MCP servers discovered from Cursor, Claude Desktop, and lnwjud settings. This inspection is read-only and does not flatten child tools into the lnwjud catalog.
notificationreadShow a host-native desktop notification when a notification session is available. Use to tell the user when a long task finishes.
pingreadPing tool
ponytailreadbundled primary
ponytail-reviewreadbundled review
process_listreadList managed process handles owned by this client in a workspace, including launches whose response was cancelled.
process_logsreadRead bounded logs for an owned process handle. Prefer one bounded log read after meaningful progress rather than repeated status polling.
process_statusreadRead one status snapshot for an owned process handle. Do not tight-poll this tool; use project_* for normal project verification, or shell background + durable task_id for work expected to exceed ~5 minutes.
process_stopwriteStop an owned managed process tree after explicit chat confirmation in standard mode. Trusted Full Bypass skips the lnwjud confirmation gate; exact process ownership still applies.
project_snapshotreadReturn a bounded project snapshot without source contents.
read_filereadRead a workspace file as UTF-8 text or as an image/binary payload. Absolute host paths do not require workspaceId. For large files or an unknown location, prefer search_text first and then read_file_page for the relevant range instead of reading the whole file.
read_file_pagereadpage
read_file_page_continuereadContinue read_file_page from the next deterministic line chunk only when more surrounding context is needed; avoid re-reading earlier pages.
read_filesreadRead up to twenty bounded workspace files in parallel. Absolute paths do not require workspaceId. For large files, locate text with search_text and page with read_file_page instead of loading entire files.
read_many_filesreadRead many workspace files in parallel while preserving one result or error per requested path.
reconcile_goalswritePreview or apply exact durable-goal reconciliation after runtime liveness checks.
record_delivery_receiptreadRecord or advance a durable dispatch receipt with explicit ambiguous-delivery states. Blind retries are rejected by lifecycle/state and newer user intent can retire stale deliveries.
remote_readreadRead remote data
restore_checkpointreadRestore a reviewed pre-mutation checkpoint. Standard mode requires explicit confirmation; trusted Full Bypass skips the lnwjud confirmation gate. A new rollback checkpoint is created before replacing current content when the target is inside a recoverable workspace.
revise_goal_intentreadRecord accepted newer user steering by incrementing userIntentRevision under the current lease. Older pending delivery receipts are retired so stale generated actions cannot outrank newer user instructions.
schema_error_demoreadoutput schema error fixture
search_allreadSearch text and filenames across one or all registered workspaces with automatic economy filters or an explicit includeIgnored override.
search_fileswriteSearch workspace filenames with automatic context-economy filters; set includeIgnored for an explicit full path search. Absolute path does not require workspaceId.
shellreadShell
skills_listreadList the union of bundled skills and every discovered machine-global or active-workspace skill from Cursor, Claude, Agents, Codex, the Codex plugin cache, GitHub workspace roots, and lnwjud settings. Nested and symlinked skill collections are included. Filter with query or source.
system_inforeadRead-only system information: OS, CPU, memory, disks, battery, uptime, and top processes by memory. Use for environment checks and diagnostics.
tool_batchwriteExecute multiple MCP tools with parallel, dependency-aware, timeout, cancellation, and partial-result handling.
ui_target_actionreadAct on one mark from a current vision_annotated_capture observation. The observation ID, optional hash, TTL, workspace owner, and current Accessibility element are checked before the action is sent.
update_goal_acceptancewriteUpdate explicit durable acceptance criteria with evidence. finish_goal(status=completed) remains blocked until every criterion is completed.
update_goal_planwriteAtomically replace the user-facing durable goal plan through the current lease and revision fence. It only updates plan state; it does not execute plan steps by itself.
validatereadValidate fixture
visionreadVision
vision_annotated_capturewriteCapture a local host screen/region/window and return a short-lived Set-of-Marks observation with numbered bounds, a content hash, and an annotated PNG when the host capture provider is ready. This tool only observes; use ui_target_action for a separately gated action.
web_fetchdestructiveFetch an http/https URL (GET/POST/PUT/DELETE/HEAD) with bounded size and timeout. In standard mode every POST, PUT, or DELETE requires explicit chat confirmation and host approval; trusted Full Bypass skips lnwjud approval. dry_run remains safe. Returns status, headers, and text or base64 body.
windowreadWindow
workspace_contextreadAggregate ranked workspace context with snippets, symbols, Git/test relevance, economy metadata, and continuation; automatic discovery can be explicitly expanded.
workspace_context_continuereadContinue a workspace_context result without discarding unreturned candidates.
workspace_full_scanwriteEnumerate workspace files with full access by default; set includeIgnored false to use the persistent automatic index.
workspace_full_scan_continuereadContinue a workspace_full_scan result page.
workspace_indexreadBuild or refresh the persistent workspace index using automatic context filters unless ignored paths are explicitly included.
workspace_index_statusreadReturn persistent index metadata and lossless watcher queue telemetry.
workspace_index_stopwriteStop a workspace watcher after draining all queued path updates.
workspace_index_watchreadWatch all workspace paths and incrementally re-index only changed paths with configurable debounce/concurrency.
workspace_inforeadReturn the configured workspace summary.
workspace_listreadList registered project workspaces available to lnwjud. Legacy explicitly registered drive roots may also appear as kind=machine_root.
workspace_registerreadRegister an existing project directory by absolute path. parentWorkspaceId is optional and retained only for legacy machine-root-relative registration. Idempotent for the same path.
workspace_snapshotreadReturn workspace identity and project snapshot metadata without source contents.
workspace_treereadList a bounded workspace tree. Absolute path does not require workspaceId.
wsl_fsreadTranslate paths and inspect metadata between a registered Windows workspace and WSL without exposing raw \\\\wsl$ read/write access.

Details

Source
engasnm111/lnwjud
npm
fixture-node-vite@1.1.1
Transports
stdio · streamable-http
Credentials it reads
APPLE_API_KEYCONTROL_PLANE_API_KEYLNWJUD_CHECKPOINT_KEY_BASE64LNWJUD_E2E_EPHEMERAL_SECRETSLNWJUD_STDIO_FULL_BYPASS_ALLLNWJUD_TEST_WINDOWS_SECRET_MIGRATORLNWJUD_WINDOWS_SECRET_MIGRATOR
License
MIT
Stars
166 · pushed 0d ago

Trust audit

Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/shared/src/agent-policy.ts:90
if (['id_rsa', 'id_ed25519', 'credentials', 'credentials.json', 'secrets.json', 'service-account.json'].includes(basename)) return true;
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/workspace/src/secret-policy.ts:3
const PRIVATE_KEY_PREFIXES = ['id_rsa', 'id_ed25519'];
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
scripts/verify-release.ps1:44
($normalized -match '(^|/)(.+\.(pem|key)|id_rsa.*|id_ed25519.*|\.ssh/.*|\.aws/.*|credentials\.json)$')
Why it matters. touches a credential store
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
apps/desktop/src/main/crash-recovery.ts:1
import { appendFileSync, closeSync, mkdirSync, openSync, readFileSync, readSync, statSync, writeFileSync } from 'node:fs';
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
apps/desktop/src/main/native-i18n.ts:1
import type { UiLocale, UpdateStatus } from '@lnwjud/ipc-contracts';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
apps/desktop/tests/guided-tunnel-setup-ui.test.ts:156
const secret = 'sk-fixture-raw-secret-must-not-render';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
apps/desktop/tests/tunnel-profile.test.ts:87
'  api_key: "sk-plaintext-must-not-remain"',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
apps/desktop/tests/tunnel-profile.test.ts:121
api_key: 'literal-must-not-remain',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mcp-server/src/opaque-approval-summary.test.ts:36
password: 'super-secret-password',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mcp-server/src/opaque-approval-summary.test.ts:37
nested: { apiKey: 'super-secret-api-key', a: 1 },
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
packages/mcp-server/src/ecc-memory-vault.test.ts:54
await expect(vault.save({ workspaceRoot, scope: 'project', title: 'credential', body: 'ghp_123456789012345678901234567890' }))
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_file, web_fetch
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
apps/desktop/tests/legacy-secret-migration.test.ts:48
await exec(powershell, ['-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'Bypass', '-File', path.join(repositoryRoot, 'scripts/build-windows-secret-migrator.ps1')], { windowsHide: true, timeout: p
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
apps/desktop/tests/legacy-secret-migration.test.ts:52
const fixture = await exec(powershell, ['-NoProfile', '-NonInteractive', '-Command',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/application/src/workspace-index.ts:249
const gitBlobSha = createHash('sha1').update(`blob ${content.byteLength}\0`).update(content).digest('hex');
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/workspace/src/secret-policy.test.ts:5
it.each(['.env', '.env.local', 'server.pem', 'private.key', 'id_ed25519', '.ssh\\id_ed25519', '.aws\\credentials', 'credentials.json'])('denies %s', (relativePath) => {
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/e2e/tools-doctor.e2e.ts:203
const sourceHelper = path.join(desktopRoot, '../../native/windows-secret-migrator/bin/win-x64/lnwjud-windows-secret-migrator.exe');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/e2e/tools-doctor.e2e.ts:205
await promisify(execFile)(powershell, ['-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'Bypass', '-File', path.join(desktopRoot, '../../scripts/build-windows-secret-migrator.ps1')], { windowsHide
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/e2e/tools-doctor.e2e.ts:242
LNWJUD_WINDOWS_SECRET_MIGRATOR: path.join(desktopRoot, '../../native/windows-secret-migrator/bin/win-x64/lnwjud-windows-secret-migrator.exe'),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/electron-builder.yml:29
- from: ../../.agents/skills/lnwjud-scheduled-continuation
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/electron-builder.yml:31
- from: ../../.agents/skills/ponytail
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
FULL_README.md:264
- Adds **Remote MCP via ngrok + OAuth** as the recommended easy ChatGPT connection path: lnwjud keeps its local Streamable HTTP MCP on loopback (normally `http://127.0.0.1:18765/mcp`), runs a separate
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
FULL_README.md:401
| Local MCP client / dashboard diagnostics | Loopback Streamable HTTP | lnwjud Desktop | Defaults to `http://127.0.0.1:18765/mcp`; actual URL is shown in the UI |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
FULL_README.md:482
5. **Member connection:** open the published custom lnwjud app in ChatGPT and press **Connect**. For the exact supported ChatGPT OAuth callback paths, the browser is handed once to a random short-live
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
FULL_README.md:486
The public ngrok URL is not the raw loopback MCP endpoint: requests must pass OAuth and bearer-token validation at the separate gateway. Do not publish `http://127.0.0.1:<port>/mcp` directly through a

Gates applied: no_behavioural_pass.

Audited 2026-09-17 · audit v0.4.0 · source sha b218af0638c4 · full audit: observations/trust-audit/mcp-server/engasnm111__lnwjud.json · Report an issue or request a re-scan

Audit history

DateSourceVerdictGradeScoreChange
2026-09-17b218af0638c4BLOCKF48first audit

Alternatives

Other servers in the same categories, safer ones first.

Questions

What is the lnwjud MCP server?

lnwjud — local AI-agent runtime & MCP gateway

What tools does lnwjud expose?

84 in total: 65 read-only, 17 that write, and 2 that can delete or overwrite (delete_file, web_fetch). Every one is listed on this page with its risk.

Is lnwjud safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (48/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does lnwjud need?

It reads APPLE_API_KEY, CONTROL_PLANE_API_KEY, LNWJUD_CHECKPOINT_KEY_BASE64, LNWJUD_E2E_EPHEMERAL_SECRETS, LNWJUD_STDIO_FULL_BYPASS_ALL, LNWJUD_TEST_WINDOWS_SECRET_MIGRATOR and LNWJUD_WINDOWS_SECRET_MIGRATOR from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does lnwjud run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as fixture-node-vite at 1.1.1.

How current is this page?

The grade is for one exact copy of the source (b218af0638c4), read on 2026-09-17. The repository is watched and re-audited when it changes.

Provenance: OBSERVED · read 2026-09-17 · job trust-audit-2026-09-17