Atlas / MCP servers / hazyresearch / Minions

MinionsBLOCK

mcp/hazyresearch/minions

Big & Small LLMs working together

Verdict
BLOCK
Grade
F
Trust score
46 /100
Exposed tools
4 3r · 1w · 0d
Transport
—
License
MIT
Stars
1,361
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://discord.gg/jfJyxXwFVa)

What is this? Minions is a communication protocol that enables small on-device models to collaborate with frontier models in the cloud. By only reading long contexts locally, we can reduce cloud costs with minimal or no quality degradation. This repository provides a demonstration of the protocol. Get started below or see our paper and blogpost below for more information.

Paper: Minions: Cost-efficient Collaboration Between On-device and Cloud Language Models

Minions Blogpost: https://hazyresearch.stanford.edu/blog/2025-02-24-minions

Secure Minions Chat Blogpost: https://hazyresearch.stanford.edu/blog/2025-05-12-security

Table of Contents

Looking for Secure Minions Chat? If you're interested in our end-to-end encrypted and chat system, please see the Secure Minions Chat README for detailed setup and usage instructions.
  • Setup
  • Step 1: Clone and Install
  • Step 2: Install a Local Model Server
  • Step 3: Set Cloud LLM API Keys
  • Minions Demo Application
  • Minions WebGPU App
  • Example Code
  • Minion (Singular)
  • Minions (Plural)
  • Python Notebook
  • Docker Support
  • Command Line Interface
  • Secure Minions Local-Remote Protocol
  • Secure Minions Chat
  • Apps
  • Inference Estimator
  • [Co
Read from source at commit a7ab56fae171OBSERVED · 2026-09-24
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add minions-webgpu --env A2A_JWT_SECRET=${A2A_JWT_SECRET} --env AI_GATEWAY_API_KEY=${AI_GATEWAY_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AZURE_OPENAI_API_KEY=${AZURE_OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "minions-webgpu": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "A2A_JWT_SECRET": "${A2A_JWT_SECRET}",
        "AI_GATEWAY_API_KEY": "${AI_GATEWAY_API_KEY}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "AZURE_OPENAI_API_KEY": "${AZURE_OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (4)

3 read · 1 write · 0 destructive.

ToolRiskDescription
addwriteAdd two numbers and return the result.
dividereadDivide a by b and return the result. Returns error if b is zero.
multiplyreadMultiply two numbers and return the result.
subtractreadSubtract b from a and return the result.
04

Trust audit

BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (8 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
minions/minion_rlm.py:360
exec(compile(combined_code, "<rlm_repl>", "exec"), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
minions/minion_rlm.py:461
exec(compile(combined, "<rlm_repl_final>", "exec"), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
minions/minions.py:234
exec(code, exec_globals)  # first execution, with example usage
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
minions/minions_mcp.py:310
exec(code, exec_globals)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
apps/minions-a2a/run_server.py:149
logger.info(f"Added API key: {args.api_key}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
minions/clients/distributed_inference.py:73
self.logger.info(f"  - API key present: {bool(self.api_key)}")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app.py:2234
help="URL of the distributed inference server (e.g., http://192.168.1.100:8080)",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
secure/utils/crypto_utils.py:301
>>> token = "eyJhbGciOiJSUzI1NiIs..."
MEDIUMSupply chain · supply.git_dep · CWE-829, CWE-1357
setup.py:43
"csm-mlx": ["csm-mlx @ git+https://github.com/senstella/csm-mlx.git"],
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
apps/minions-a2a/examples/webapp/run_webapp.py:407
__import__(module)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
apps/minions-a2a/a2a_minions/client_factory.py:96
return f"{provider}:{hashlib.md5(config_str.encode()).hexdigest()}"
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
apps/minions-a2a/examples/webapp/app.py:402
print(f"   API Key: {args.api_key}")
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
apps/minions-a2a/examples/webapp/run_webapp.py:349
print(f"🔑 API Key:       {api_key}")
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
apps/minions-a2a/tests/unit/test_auth.py:220
print(f"Created token: {token}")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/minions-a2a/tests/run_unit_tests.py:14
sys.path.insert(0, os.path.abspath(os.path.join(os.path.dirname(__file__), '../../..')))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/minions-a2a/tests/unit/test_converters.py:271
"name": "../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/minions-doc-search/local_rag_document_search.py:41
sys.path.append(os.path.join(os.path.dirname(__file__), '../../minions'))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/minions-docker/docker-compose.minion.yml:8
context: ../../
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/minions-docker/docker-compose.minion.yml:45
context: ../../
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/minions-docker/README.md:32
# Access API directly: http://127.0.0.1:5000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/minions-docker/README.md:42
# Access API directly: http://127.0.0.1:5000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/minions-docker/README.md:104
curl http://127.0.0.1:5000/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/minions-docker/README.md:109
curl -X POST http://127.0.0.1:5000/start_protocol \
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
apps/minions-a2a/tests/integration/run_integration_tests.py:589
pdf_content = """JVBERi0xLjMKJZOMi54gUmVwb3J0TGFiIEdlbmVyYXRlZCBQREYgZG9jdW1lbnQgaHR0cDovL3d3dy5yZXBvcnRsYWIuY29tCjEgMCBvYmoKPDwKL0YxIDIgMCBSCj4+CmVuZG9iagoyIDAgb2JqCjw8Ci9CYXNlRm9udCAvSGVsdmV0aWNhIC9
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
apps/minions-a2a/a2a_minions/converters.py:195
content_bytes = base64.b64decode(file_info["bytes"])

Gates applied: no_behavioural_pass.

Audited 2026-09-24 · audit v0.4.1 · source sha a7ab56fae171full audit observations/trust-audit/mcp-server/hazyresearch__minions.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-24a7ab56fae171BLOCKF46first audit
06

Questions

What is the Minions MCP server?

Big & Small LLMs working together

What tools does Minions expose?

4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Minions safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (46/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Minions need?

It reads A2A_JWT_SECRET, AI_GATEWAY_API_KEY, ANTHROPIC_API_KEY, AZURE_OPENAI_API_KEY, CEREBRAS_API_KEY, COHERE_API_KEY, CO_API_KEY, DASHSCOPE_API_KEY, DEEPSEEK_API_KEY, EXA_API_KEY, FIRECRAWL_API_KEY and GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (a7ab56fae171), read on 2026-09-24. The repository is watched and re-audited when it changes.

Advertisement