Atlas / MCP servers / indragiek / Uniprof

UniprofCAUTION

mcp/indragiek/uniprof

Universal CPU profiler designed for humans and AI agents

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
1 0r · 1w · 0d
Transport
stdio
License
MIT
Stars
407
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

uniprof simplifies CPU profiling for humans and AI agents. Profile any application without code changes or added dependencies.

# Profile and analyze any app in one step
npx uniprof python script.py

Table of Contents

  • Supported Platforms
  • System Requirements
  • Installation
  • MCP Server
  • Quick Start
  • Host vs. Container Modes
  • Compiling with Debug Information
  • Documentation
  • Credits
  • License

Supported Platforms

uniprof implements a common interface over multiple profilers that specialize in different platforms and runtimes. It automatically detects which profiler to use based on the command being executed, runs the profiler, transforms the varying output formats into a single format, and runs statistical analysis on the data to identify hotspots.

\* Linux only for host mode

System Requirements

tl;dr: macOS or Linux with Docker installed

uniprof is designed to run

Read from source at commit 08e1fb4ebeebOBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add uniprof -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "uniprof": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
run_profilerwrite
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (6 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/commands/visualize.ts:124
const serverUrl = `http://127.0.0.1:${actualPort}`;
MEDIUMObfuscation / stealth · obf.anti_debug · CWE-506, CWE-94
src/commands/record.ts:463
wPrintInfo('This is due to ptrace restrictions (ptrace_scope is not 0).');
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/dotnet/Test
Test
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/dotnet/Test.dll
Test.dll
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/jvm/Test.class
Test.class
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/jvm/test.jar
test.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/test-perf-script.txt.gz
test-perf-script.txt.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.symlink · CWE-1104
AGENTS.md
AGENTS.md
Why it matters. link not followed
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/platforms/base-platform.ts:90
const projectHash = crypto.createHash('md5').update(cwd).digest('hex').substring(0, 8);
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/platforms/beam.ts:348
const projectHash = crypto.createHash('md5').update(cwd).digest('hex').substring(0, 8);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@typescript/native-preview
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:47
Profiling tools are often non-trivial to set up correctly and can require [elevated privileges](https://www.kernel.org/doc/html/v6.16/admin-guide/perf-security.html). To simplify set up and provide be
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/platforms/dotnet.md:300
# Or run with elevated permissions (host mode)
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/platforms/python.md:172
py-spy requires elevated permissions on macOS. Solutions:
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/platforms/ruby.md:58
Note: Host mode often requires elevated permissions.
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/platforms/dotnet.md:264
# Update PATH if needed
Why it matters. instructs the agent to persist itself in the user's environment
INFOInventory / provenance · inv.oversize · CWE-1104
tests/fixtures/test-simple.trace.zip
tests/fixtures/test-simple.trace.zip
Why it matters. 1433458 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
tests/fixtures/test-ticks.json
tests/fixtures/test-ticks.json
Why it matters. 1324275 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 08e1fb4ebeebfull audit observations/trust-audit/mcp-server/indragiek__uniprof.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0108e1fb4ebeebCAUTIONB85first audit
06

Questions

What is the Uniprof MCP server?

Universal CPU profiler designed for humans and AI agents

What tools does Uniprof expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Uniprof safe to connect to an agent?

With care. The audit graded it B (85/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Uniprof need?

No credential environment variables were found in its source, so it appears to need none.

How does Uniprof run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as uniprof at 0.3.4.

How current is this page?

The grade is for one exact copy of the source (08e1fb4ebeeb), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement