mcp-muxCAUTION
Configure MCP servers once, connect every AI client through a single local gateway
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](LICENSE) [](https://github.com/mcpmux/mcp-mux/releases) [](https://github.com/mcpmux/mcp-mux/actions/workflows/ci.yml)
One app to manage all your MCP servers across every AI client.
[Website](https://mcpmux.com) · [Download](https://mcpmux.com/download) · [Discover Servers](https://mcpmux.com) · [Features](https://mcpmux.com/features) · [Discord](https://discord.gg/b4RDmwAHAN)
The Problem
Cursor, Claude Desktop, VS Code, Windsurf — they all support MCP, but each one needs its own config file. None of them talk to each other.
┌─────────────────────────────────────────────────────────────────────────┐ │ Today: every client manages MCP servers independently │ │ │ │ Cursor → config.json → github, slack, db + API keys │ │ Claude → config.json → github, slack, db + API keys (dupe) │ │ VS Code → settings.json → github, slack, db + API keys (dupe) │ │ Windsurf → config.json → github, slack, db + API keys (dupe) │ │ │ │ ⚠ 4 config files · 4 copies of every API key · all plain text │ └─────────────────────────────────────────────────────────────────────────┘
Add a server? Edit four files. Rotate an API key? Edit four files. New machine? Start from scratch.
And those API keys? Sitting in **plain-text
863ef98cb0f1OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add stub-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"stub-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (20)
15 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Default | write | Default feature set for new clients |
GitHub | read | GitHub MCP server |
Memory | write | Notes and recall your AI can read and write across every app. |
Notion | read | Notion MCP server |
Original | read | Test desc |
Slack | read | Slack MCP server |
add | write | Add two numbers together |
echo | read | Echo back the input message (requires auth) |
error | read | Intentionally throw an error |
get_env | read | Get environment variable value |
get_time | read | Get the current server time |
list-and-call-me | read | E2E tool proving list==call |
mcpmux_bind_current_workspace | write | Map the current folder to a feature set so it persists (re-run to rebind). |
mcpmux_list_all_tools | read | Browse every tool available in a Space, unfiltered. |
mcpmux_list_feature_sets | read | See the feature sets defined in the Space. |
mcpmux_list_spaces | read | List all Spaces so the AI can target one by id. |
mcpmux_manage_feature_set | destructive | Create, update, or delete a custom feature set of chosen tools. |
mcpmux_search_tools | read | Find tools by keyword without pulling the whole catalog. |
slow_task | read | Simulate a slow operation |
whoami | read | Get information about the authenticated client |
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
icon.icns
format!("http://127.0.0.1:{}{}", port, oauth_callback_path())if url.starts_with("http://127.0.0.1:") && url.contains(path) {assert!(uri.starts_with("http://127.0.0.1:"));assert_eq!(uri, "http://127.0.0.1:9876/oauth2redirect");
mcpmux_manage_feature_set
.prettierignore
.release-please-manifest.json
console.log(`[oauth-server] Issued access token: ${access_token.substring(0, 20)}...`);console.log(`[oauth-server] Refreshed token: ${new_access_token.substring(0, 20)}...`);console.log(`[oauth-server] MCP endpoint: http://localhost:${PORT}/mcp (requires Bearer token)`);console.log('[test] Got access token:', token.substring(0, 20) + '...');console.log('[test] Token obtained, length:', token.length);"../../../Windows",
"../../..",
import USER_SPACE_CONFIG_SCHEMA from '../../../../schemas/user-space.schema.json';
import { useRegistryStore } from '../../stores/registryStore';import type { FilterDefinition } from '../../types/registry';let health_url = format!("http://127.0.0.1:{port}/health");@monaco-editor/react, @tauri-apps/api, @tauri-apps/plugin-dialog, @tauri-apps/plugin-opener, @tauri-apps/plugin-process, @tauri-apps/plugin-updater, immer, lucide-react
@modelcontextprotocol/sdk, @playwright/test, @testing-library/jest-dom, @testing-library/react, @testing-library/user-event, @types/cors, @types/express, @vitejs/plugin-react
clsx, lucide-react, tailwind-merge, @eslint/js, @types/react, @types/react-dom, eslint, eslint-plugin-react-hooks
express, cors, @types/express, @types/cors, tsx
@modelcontextprotocol/sdk, zod, express, @types/express, tsx
// Load JWT secret from keychain
Gates applied: no_behavioural_pass.
863ef98cb0f1full audit observations/trust-audit/mcp-server/mcpmux__mcp-mux.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 863ef98cb0f1 | CAUTION | B | 81 | first audit |
Questions
What is the mcp-mux MCP server?
Configure MCP servers once, connect every AI client through a single local gateway
What tools does mcp-mux expose?
20 in total: 15 read-only, 4 that write, and 1 that can delete or overwrite (mcpmux_manage_feature_set). Every one is listed on this page with its risk.
Is mcp-mux safe to connect to an agent?
With care. The audit graded it B (81/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does mcp-mux need?
No credential environment variables were found in its source, so it appears to need none.
How does mcp-mux run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as stub-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (863ef98cb0f1), read on 2026-10-09. The repository is watched and re-audited when it changes.