MinionsBLOCK
Big & Small LLMs working together
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://discord.gg/jfJyxXwFVa)
What is this? Minions is a communication protocol that enables small on-device models to collaborate with frontier models in the cloud. By only reading long contexts locally, we can reduce cloud costs with minimal or no quality degradation. This repository provides a demonstration of the protocol. Get started below or see our paper and blogpost below for more information.
Paper: Minions: Cost-efficient Collaboration Between On-device and Cloud Language Models
Minions Blogpost: https://hazyresearch.stanford.edu/blog/2025-02-24-minions
Secure Minions Chat Blogpost: https://hazyresearch.stanford.edu/blog/2025-05-12-security
Table of Contents
Looking for Secure Minions Chat? If you're interested in our end-to-end encrypted and chat system, please see the Secure Minions Chat README for detailed setup and usage instructions.
- Setup
- Step 1: Clone and Install
- Step 2: Install a Local Model Server
- Step 3: Set Cloud LLM API Keys
- Minions Demo Application
- Minions WebGPU App
- Example Code
- Minion (Singular)
- Minions (Plural)
- Python Notebook
- Docker Support
- Command Line Interface
- Secure Minions Local-Remote Protocol
- Secure Minions Chat
- Apps
- Inference Estimator
- [Co
a7ab56fae171OBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add minions-webgpu --env A2A_JWT_SECRET=${A2A_JWT_SECRET} --env AI_GATEWAY_API_KEY=${AI_GATEWAY_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AZURE_OPENAI_API_KEY=${AZURE_OPENAI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"minions-webgpu": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"A2A_JWT_SECRET": "${A2A_JWT_SECRET}",
"AI_GATEWAY_API_KEY": "${AI_GATEWAY_API_KEY}",
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"AZURE_OPENAI_API_KEY": "${AZURE_OPENAI_API_KEY}"
}
}
}
}Exposed tools (4)
3 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add | write | Add two numbers and return the result. |
divide | read | Divide a by b and return the result. Returns error if b is zero. |
multiply | read | Multiply two numbers and return the result. |
subtract | read | Subtract b from a and return the result. |
Trust audit
BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(compile(combined_code, "<rlm_repl>", "exec"), namespace)
exec(compile(combined, "<rlm_repl_final>", "exec"), namespace)
exec(code, exec_globals) # first execution, with example usage
exec(code, exec_globals)
logger.info(f"Added API key: {args.api_key}")self.logger.info(f" - API key present: {bool(self.api_key)}")help="URL of the distributed inference server (e.g., http://192.168.1.100:8080)",
>>> token = "eyJhbGciOiJSUzI1NiIs..."
"csm-mlx": ["csm-mlx @ git+https://github.com/senstella/csm-mlx.git"],
__import__(module)
return f"{provider}:{hashlib.md5(config_str.encode()).hexdigest()}"print(f" API Key: {args.api_key}")print(f"🔑 API Key: {api_key}")print(f"Created token: {token}")sys.path.insert(0, os.path.abspath(os.path.join(os.path.dirname(__file__), '../../..')))
"name": "../../../etc/passwd",
sys.path.append(os.path.join(os.path.dirname(__file__), '../../minions'))
context: ../../
context: ../../
# Access API directly: http://127.0.0.1:5000
# Access API directly: http://127.0.0.1:5000
curl http://127.0.0.1:5000/health
curl -X POST http://127.0.0.1:5000/start_protocol \
pdf_content = """JVBERi0xLjMKJZOMi54gUmVwb3J0TGFiIEdlbmVyYXRlZCBQREYgZG9jdW1lbnQgaHR0cDovL3d3dy5yZXBvcnRsYWIuY29tCjEgMCBvYmoKPDwKL0YxIDIgMCBSCj4+CmVuZG9iagoyIDAgb2JqCjw8Ci9CYXNlRm9udCAvSGVsdmV0aWNhIC9
content_bytes = base64.b64decode(file_info["bytes"])
Gates applied: no_behavioural_pass.
a7ab56fae171full audit observations/trust-audit/mcp-server/hazyresearch__minions.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | a7ab56fae171 | BLOCK | F | 46 | first audit |
Questions
What is the Minions MCP server?
Big & Small LLMs working together
What tools does Minions expose?
4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Minions safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (46/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Minions need?
It reads A2A_JWT_SECRET, AI_GATEWAY_API_KEY, ANTHROPIC_API_KEY, AZURE_OPENAI_API_KEY, CEREBRAS_API_KEY, COHERE_API_KEY, CO_API_KEY, DASHSCOPE_API_KEY, DEEPSEEK_API_KEY, EXA_API_KEY, FIRECRAWL_API_KEY and GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (a7ab56fae171), read on 2026-09-24. The repository is watched and re-audited when it changes.