Atlas / MCP servers / joonlab / machines-as-tools

machines-as-toolsBLOCK

mcp/joonlab/machines-as-tools

기기를 도구로 (Machines as Tools) — Claude Code 세션 하나가 남는 맥을 MCP 도구로 쓰는 구조. 원격 실행기 mm + MCP 서버 multimac(도구 19개) + 실측 문서

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
17 16r · 1w · 0d
Transport
—
License
MIT
Stars
1
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English summary. Three Macs cannot run one Claude Code session at the same time: a session is a single process appending to a single transcript. But Claude's reasoning runs on the server, and what actually eats a machine's RAM is the tools the session drives — browsers, builds, renders, scans. So this repo keeps one session in charge and registers spare Macs as MCP tools (19 of them, served by an MCP server called multimac on top of a shell wrapper mm). The rule of thumb is a cost ladder: deterministic shell work first (no LLM), a cheap lean worker with a short brief second, a stronger model third, and a full conversation fork only as a last resort. Measured on a laptop (M5 Max 128GB), an always-on home Mac (M3 Max 64GB) and a MacBook Air (M2 8GB), 2026-10-08 to 10-09; dollar figures are API-price equivalents. | Measurement | Before → After | |---|---| | Same summarization task: full conversation fork → ~1,000-char brief + Haiku worker | $2.14 → $0.0146 (about 147×) | | Fan-out to 3 Macs: Workflow proxy agents → mm batch | 36 s, ~220k proxy tokens → 6.2 s, 0 proxy tokens | | Remote worker context: default config → lean config | 95,209 → 26,934 tokens ($0.3119 → $0.0283) | | ssh round trip: new connection → ControlMaster reuse | 0.2–0.3 s → 0.04 s |

한 줄

에이전트를 늘리기 전에, 기기를 도구로. 세션은 하나로 두고, 남는 기기는 그 세션의 도구로 등록한다.

영상 (71초)

[](media/machines-as-tools_71s.mp4)

media/machines-as-tools_71s.mp4 — 71초짜리 한국어 컨셉 영상이다. 음악과 효과음이 깔리고 내레이션은 없다. 개인용 비공개 영상 킷(motion-reel)으로 만들었고, 리뷰어 두 명이 따로 검토한 뒤 고쳐서 품질 게이트를 통과했다. 이 영상도 이 저장소의 render 도구로 홈맥에서 렌더했다.

왜 만들었나

나는 노트북 한 대에 Claude Code 프로세스를 100개 넘게 띄워 두고 일한다. 그러다 무거운 작업을 한 기기에서 겹쳤다. 영상 렌더 워커 8개(약 9GB)와 병렬 claude -p 여러 개를 함께 돌렸고, 그 결과 커널 패닉을 두 번(2026-06-19, 2026-09-27) 겪었다. 그동안 집에 있는 64GB 맥과 맥북에어는 거의 놀고 있었다.

마침 공개 오픈소스 [OpenRig](https://github.com/mvschwar

Read from source at commit 717ca8831a9bOBSERVED · 2026-10-08
02

Exposed tools (17)

16 read · 1 write · 0 destructive.

ToolRiskDescription
auto_capabilitiesread능력 레지스트리(능력 → 기기 우선순위)와
auto_dispatchread능력 이름으로 작업을 보내면 후보 기기 상태(free%·load1·claude 수)를 1초 안에 재고 첫 통과 기기에서 mm 을 실행한다. 판정 LLM 0.
batchread여러 작업을 여러 맥에서 동시에 실행하고 요약표만 돌려준다(전체 결과는 표에 적힌 results 폴더의 <id>.out).
browserread원격 맥의 cmux browser 를 세부 조작한다(클릭·입력·스크린샷 등). args 는 `cmux browser` 뒤에 올 인자 목록.
close_tabread원격 맥의 브라우저 탭(surface:N)을 닫는다. surface:N 형식만 받는다.
helloread\
mine_scanread[T0 · LLM 0 · 수 초] 세션 기록이 동기화된 기기(설정 hands.mine.host, 기본 첫 can_ask 기기)에서
mine_sessionsread[T0 스캔 + T1 haiku 동시 작업자 · 실측 약 40초 · 0.30~0.35달러(15후보·3묶음)]
render_checkread렌더 보내기 전 점검(LLM 0, 몇 초): 렌더 기기의 node·ffmpeg·playwright chromium·python 모듈·킷 유무와 메모리 게이트 판정,
render_remoteread렌더 프로젝트(index.html 있는 폴더)를 heavy 역할 원격 기기에서 렌더하고 결과 파일만 이 맥으로 회수한다. LLM 비용 0.
research_reporeadGitHub 레포 하나를 조사해 보고서(md)+trace.json 을 출력 폴더(설정 hands.research.out_dir, 기본 저장소 밖)에 쓰고 10줄만 돌려준다.
research_reportsread지금까지 만든 research 보고서 목록(최신순)을 돌려준다. LLM 0, 비용 0.
runwrite원격(또는 이 맥) 셸 명령을 실행한다. LLM 비용 0. 빌드·렌더·집계·파일 처리처럼 할 일이 정해진 작업용.
statusread설정된 모든 맥의 메모리 여유(free%)·claude 프로세스 수·부하·코어 수를 한 화면으로 본다. 무거운 일을 보내기 전에 쓴다.
verify_checkread장부 전체를 재검사한다(LLM 0, 비용 0, 1초 미만). 파일이 바뀌거나 사라진 행은 unknown,
verify_judgeread산출물(파일 1~수 개, 총 2MB 이하)을 판정 기기(can_ask·judge 역할)의 «새» 작업자가 기준에 따라 pass|fail|unsure 로
verify_statusread«지금 이 파일들 + 이 기준»에 유효한 최신 판정을 돌려준다(LLM 0). 해시가 하나라도 다르면 unknown →
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
hands/auto/auto.py:69
cm = Path(os.path.expanduser(s.get("control_dir", "~/.ssh/cm")))
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
hands/render/render.py:89
cm = Path(os.path.expanduser(s.get("control_dir", "~/.ssh/cm")))
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
lib/config.py:60
"control_dir": "~/.ssh/cm",
Why it matters. touches a credential store
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
hands/render/render.py:111
return f"{base}-{hashlib.md5(str(project).encode()).hexdigest()[:6]}"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
media/machines-as-tools_71s.mp4
media/machines-as-tools_71s.mp4
Why it matters. 5120332 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 717ca8831a9bfull audit observations/trust-audit/mcp-server/joonlab__machines-as-tools.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08717ca8831a9bBLOCKD69first audit
05

Questions

What is the machines-as-tools MCP server?

기기를 도구로 (Machines as Tools) — Claude Code 세션 하나가 남는 맥을 MCP 도구로 쓰는 구조. 원격 실행기 mm + MCP 서버 multimac(도구 19개) + 실측 문서

What tools does machines-as-tools expose?

17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is machines-as-tools safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does machines-as-tools need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (717ca8831a9b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement