Atlas / MCP servers / mcpmux / mcp-mux

mcp-muxCAUTION

mcp/mcpmux/mcp-mux

Configure MCP servers once, connect every AI client through a single local gateway

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
20 15r · 4w · 1d
Transport
stdio · streamable-http
License
GPL-3.0
Stars
24
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](LICENSE) [](https://github.com/mcpmux/mcp-mux/releases) [](https://github.com/mcpmux/mcp-mux/actions/workflows/ci.yml)

One app to manage all your MCP servers across every AI client.

[Website](https://mcpmux.com) · [Download](https://mcpmux.com/download) · [Discover Servers](https://mcpmux.com) · [Features](https://mcpmux.com/features) · [Discord](https://discord.gg/b4RDmwAHAN)

The Problem

Cursor, Claude Desktop, VS Code, Windsurf — they all support MCP, but each one needs its own config file. None of them talk to each other.

┌─────────────────────────────────────────────────────────────────────────┐
│  Today: every client manages MCP servers independently                  │
│                                                                         │
│  Cursor       → config.json    → github, slack, db  + API keys         │
│  Claude       → config.json    → github, slack, db  + API keys  (dupe) │
│  VS Code      → settings.json  → github, slack, db  + API keys  (dupe) │
│  Windsurf     → config.json    → github, slack, db  + API keys  (dupe) │
│                                                                         │
│  ⚠ 4 config files  ·  4 copies of every API key  ·  all plain text     │
└─────────────────────────────────────────────────────────────────────────┘

Add a server? Edit four files. Rotate an API key? Edit four files. New machine? Start from scratch.

And those API keys? Sitting in **plain-text

Read from source at commit 863ef98cb0f1OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add stub-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "stub-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (20)

15 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
DefaultwriteDefault feature set for new clients
GitHubreadGitHub MCP server
MemorywriteNotes and recall your AI can read and write across every app.
NotionreadNotion MCP server
OriginalreadTest desc
SlackreadSlack MCP server
addwriteAdd two numbers together
echoreadEcho back the input message (requires auth)
errorreadIntentionally throw an error
get_envreadGet environment variable value
get_timereadGet the current server time
list-and-call-mereadE2E tool proving list==call
mcpmux_bind_current_workspacewriteMap the current folder to a feature set so it persists (re-run to rebind).
mcpmux_list_all_toolsreadBrowse every tool available in a Space, unfiltered.
mcpmux_list_feature_setsreadSee the feature sets defined in the Space.
mcpmux_list_spacesreadList all Spaces so the AI can target one by id.
mcpmux_manage_feature_setdestructiveCreate, update, or delete a custom feature set of chosen tools.
mcpmux_search_toolsreadFind tools by keyword without pulling the whole catalog.
slow_taskreadSimulate a slow operation
whoamireadGet information about the authenticated client
04

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (7 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/desktop/src-tauri/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/mcpmux-core/src/branding.rs:191
format!("http://127.0.0.1:{}{}", port, oauth_callback_path())
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/mcpmux-core/src/branding.rs:208
if url.starts_with("http://127.0.0.1:") && url.contains(path) {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/mcpmux-core/src/branding.rs:302
assert!(uri.starts_with("http://127.0.0.1:"));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/mcpmux-core/src/branding.rs:305
assert_eq!(uri, "http://127.0.0.1:9876/oauth2redirect");
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
mcpmux_manage_feature_set
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/e2e/mocks/stub-mcp-server/http-oauth-server.ts:233
console.log(`[oauth-server] Issued access token: ${access_token.substring(0, 20)}...`);
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/e2e/mocks/stub-mcp-server/http-oauth-server.ts:267
console.log(`[oauth-server] Refreshed token: ${new_access_token.substring(0, 20)}...`);
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/e2e/mocks/stub-mcp-server/http-oauth-server.ts:434
console.log(`[oauth-server] MCP endpoint: http://localhost:${PORT}/mcp (requires Bearer token)`);
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/e2e/specs/streamable-http.wdio.ts:371
console.log('[test] Got access token:', token.substring(0, 20) + '...');
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/e2e/specs/streamable-http.wdio.ts:381
console.log('[test] Token obtained, length:', token.length);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/src-tauri/src/commands/logs.rs:189
"../../../Windows",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/src-tauri/src/commands/logs.rs:225
"../../..",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/src/components/ConfigEditorModal.tsx:9
import USER_SPACE_CONFIG_SCHEMA from '../../../../schemas/user-space.schema.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/src/features/registry/RegistryPage.tsx:10
import { useRegistryStore } from '../../stores/registryStore';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/desktop/src/features/registry/RegistryPage.tsx:372
import type { FilterDefinition } from '../../types/registry';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/daemon/tests/daemon.rs:108
let health_url = format!("http://127.0.0.1:{port}/health");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/desktop/package.json
@monaco-editor/react, @tauri-apps/api, @tauri-apps/plugin-dialog, @tauri-apps/plugin-opener, @tauri-apps/plugin-process, @tauri-apps/plugin-updater, immer, lucide-react
Why it matters. 28 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @playwright/test, @testing-library/jest-dom, @testing-library/react, @testing-library/user-event, @types/cors, @types/express, @vitejs/plugin-react
Why it matters. 29 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/ui/package.json
clsx, lucide-react, tailwind-merge, @eslint/js, @types/react, @types/react-dom, eslint, eslint-plugin-react-hooks
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
tests/e2e/mocks/mock-bundle-api/package.json
express, cors, @types/express, @types/cors, tsx
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
tests/e2e/mocks/stub-mcp-server/package.json
@modelcontextprotocol/sdk, zod, express, @types/express, tsx
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
crates/mcpmux-gateway/DI_PATTERN.md:192
// Load JWT secret from keychain
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 863ef98cb0f1full audit observations/trust-audit/mcp-server/mcpmux__mcp-mux.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09863ef98cb0f1CAUTIONB81first audit
06

Questions

What is the mcp-mux MCP server?

Configure MCP servers once, connect every AI client through a single local gateway

What tools does mcp-mux expose?

20 in total: 15 read-only, 4 that write, and 1 that can delete or overwrite (mcpmux_manage_feature_set). Every one is listed on this page with its risk.

Is mcp-mux safe to connect to an agent?

With care. The audit graded it B (81/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does mcp-mux need?

No credential environment variables were found in its source, so it appears to need none.

How does mcp-mux run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as stub-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (863ef98cb0f1), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement