Atlas / MCP servers / neosun100 / TranslateGemma

TranslateGemmaCAUTION

mcp/neosun100/translategemma

🌍 TranslateGemma - Local AI Translation Service with Web UI, REST API & MCP. 55 languages, all-in-one Docker image with embedded models. Powered by Google's TranslateGemma.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
9 9r ¡ 0w ¡ 0d
Transport
—
License
MIT
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | įŽ€äŊ“中文 | įšéĢ”ä¸­æ–‡ | æ—ĨæœŦčĒž

🌍 Local AI Translation Service with Web UI, REST API & MCP Integration 55 languages, smart chunking, streaming output. Powered by Google's TranslateGemma.

[](https://hub.docker.com/r/neosun/translategemma) [](https://www.python.org/) [](LICENSE) [](https://developer.nvidia.com/cuda-toolkit)

✨ Highlights

  • 🌐 Web UI - Beautiful, responsive translation interface
  • 🔌 REST API - Full-featured API with streaming support
  • 🤖 MCP Integration - Works with Claude Desktop & AI assistants
  • 🌍 55 Languages - Full TranslateGemma language support
  • 📚 Smart Chunking - Handle unlimited text length (chunk_size=100)
  • ⚡ Streaming Output - Real-time translation progress
  • đŸŗ All-in-One Docker - 82GB image with all 6 models embedded
  • đŸŽ¯ Multi-Model - 4B/12B/27B with Q4/Q8 quantization

đŸŽŦ Quick Start

Option 1: Docker All-in-One (Recommended)

# Pull the all-in-one image (82GB, includes all models)
docker pull neosun/translategemma:v1.0.0-allinone

# Run with GPU
docker run -d --gpus '"device=0"' \
-p 8022:8022 \
-e MODEL_NAME=27b \
-e QUANTIZATION=8 \
--name translategemma \
neosun/translategemma:v1.0.0-allinone

# Access Web UI
open http://localhost:8022

Option 2: Docker with Model Download

# Pull lightweight image (10GB)
docker pull neosun/translategemma:latest

# Run (models download on first use)
docker run -d --gpus '"device=0"' \
-p 8022:8022 \
-v ~/.cache/translate/models:/root/.cache/translate/models \
--name translategemma \
neosun/translategemma:latest

Option 3: Docker Compose

Read from source at commit 9b5c03708db8OBSERVED ¡ 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add translategemma-cli --env TOKENIZERS_PARALLELISM=${TOKENIZERS_PARALLELISM} -- uvx translategemma-cli
claude-desktop
{
  "mcpServers": {
    "translategemma-cli": {
      "command": "uvx",
      "args": [
        "translategemma-cli"
      ],
      "env": {
        "TOKENIZERS_PARALLELISM": "${TOKENIZERS_PARALLELISM}"
      }
    }
  }
}
03

Exposed tools (9)

9 read ¡ 0 write ¡ 0 destructive.

ToolRiskDescription
get_configread
get_gpu_statusread
list_languagesread
list_modelsread
release_gpuread
switch_modelread
translate_batchread
translate_fileread
translate_textread
04

Trust audit

CAUTIONgrade B ¡ trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMInformation disclosure ¡ disclose.log_secret ¡ CWE-209, CWE-532
translategemma_cli/cli.py:370
console.print(token, end="")
MEDIUMInformation disclosure ¡ disclose.log_secret ¡ CWE-209, CWE-532
translategemma_cli/cli.py:445
print(token, end="", flush=True)
MEDIUMNetwork egress ¡ net.raw_ip ¡ CWE-200, CWE-319
start.sh:105
echo -e "  ${CYAN}Web UI:${NC}     http://0.0.0.0:$PORT"
MEDIUMNetwork egress ¡ net.raw_ip ¡ CWE-200, CWE-319
start.sh:106
echo -e "  ${CYAN}API Docs:${NC}   http://0.0.0.0:$PORT/docs"
MEDIUMNetwork egress ¡ net.raw_ip ¡ CWE-200, CWE-319
start.sh:107
echo -e "  ${CYAN}Health:${NC}     http://0.0.0.0:$PORT/health"
LOWSupply chain ¡ supply.unpinned ¡ CWE-829, CWE-1357
requirements-dev.txt
pytest, pytest-cov, black, ruff
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-09 ¡ audit v0.4.1 ¡ source sha 9b5c03708db8full audit observations/trust-audit/mcp-server/neosun100__translategemma.json ¡ Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-099b5c03708db8CAUTIONB89first audit
06

Questions

What is the TranslateGemma MCP server?

🌍 TranslateGemma - Local AI Translation Service with Web UI, REST API & MCP. 55 languages, all-in-one Docker image with embedded models. Powered by Google's TranslateGemma.

What tools does TranslateGemma expose?

9 in total: 9 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is TranslateGemma safe to connect to an agent?

With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does TranslateGemma need?

It reads TOKENIZERS_PARALLELISM from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (9b5c03708db8), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement