viboplrBLOCK
Plugin-first desktop music player for macOS and Windows — local library, streaming services, lyrics, and radio. Built with Tauri 2, React, and Rust.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The music player you can just talk to, built by talking to an AI.
Viboplr is a free, open-source desktop music player for macOS and Windows, and it is AI-native in both directions:
- Driven by AI. A built-in MCP server lets Claude, or any AI assistant, run your music library. Ask it to build playlists, fix tags, organise folders, download tracks, or tell you what you played most last March.
- Built by AI. Every line of code was written by an AI coding assistant (Claude Code). The human role is tech lead and product owner: decide what to build, define how it behaves, review, test, and push back until it's right. The story →
Under the hood it's a Tauri 2 app with a Rust backend and a React frontend. It plays audio and video from local folders and Subsonic/Navidrome servers, and works as an orchestrator: a plugin system connects streaming providers, metadata services, lyric databases and image sources, while the core handles playback, the library and the UI. Its SQLite library starts fast, plays instantly and searches big collections in milliseconds.
AI Control (MCP)
Viboplr ships its own MCP server, so an AI assistant gets real, typed tools for your music library instead of screen-scraping. Turn on Settings → AI control, press Copy config (Claude Desktop) or Copy command (Claude Code), and paste it into your client.
"Tag everything by Boards of Canada as ambient, and file the compilations under Various Artists." "Sort the loose files in my Music folder into Artist/Album." "Make me a playlist of songs I loved and haven't played this year."
- Listen: search, play, queue, skip, start radio, like, and drive the window and views
- Curate: create and edit playlists, edit tags in bulk, rename listening history
- Ask: read-only SQL over the library and play history ("what did I play most last March?"), lyrics, bios, and reviews
- **Care for
0b75cea2867eOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add viboplr -- npx -y [email protected]
{
"mcpServers": {
"viboplr": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (14)
13 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
download | read | Download |
ffmpeg | read | Audio/video transcoding and format conversion |
fictional-tool | read | A fake dependency for testing the dependency UI (debug only) |
get_state | read | Simulation settings |
info | read | Info |
legacy | read | Declares nothing |
list_playlists | read | The scraped playlists |
roadie | read | Installs, runs and updates helper services such as slskd, each only after you approve it |
rqbit | read | BitTorrent downloads (one-shot, no client to configure) |
search | read | Search |
search_catalog | read | Search the fake catalog |
similar | read | Similar |
status | write | Sync state |
yt-dlp | read | YouTube video/audio downloading |
Trust audit
BLOCKgrade F · trust 30/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (13 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (9 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const factory = new Function("api", "window", "globalThis", "self", "document", code);const factory = new Function("api", "window", "globalThis", "self", "document", init.code);eval(js: string): Promise<void>;
exec(
| `POST /query` | `{sql, params?, limit?}` — **ad-hoc read-only SQL** (SQLite) for analytics the endpoints can't express (plays per year, liked-but-never-played, joins over history). One SELECT per caorder, first `status: "ok"` wins; consult/upsert the info-value cache
<script defer src='https://static.cloudflareinsights.com/beacon.min.js' data-cf-beacon='{"token": "cbb978698d3744cca00a24f8cac8bc3c"}'></script>ASPNETCORE_URLS: http://0.0.0.0:8080
["Δcpu", 9],
["ΔwsCPU", 9],
["ΔwsGPU", 9],
? "ΔwsCPU/ΔwsGPU = dwm.exe's (Desktop Window Manager) rise over the baseline. Compositing is billed to DWM's"
: "ΔwsCPU/ΔwsGPU = WindowServer's rise over the baseline. Compositing is billed to WindowServer's own",
| `VPS_SSH_PRIVATE_KEY` | The private key (full contents, including header/footer lines) whose public key is in the VPS user's `~/.ssh/authorized_keys` | `-----BEGIN OPENSSH PRIVATE KEY-----` ... |
bit-perfect.webm
gapless.webm
home.webm
lyrics.webm
mini-player.webm
plugin.payload.txt
mkdir -p ~/.ssh
chmod 700 ~/.ssh
printf '%s\n' "$SSH_PRIVATE_KEY" > ~/.ssh/deploy_key
chmod 600 ~/.ssh/deploy_key
ssh-keyscan -p "$PORT" -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null
Gates applied: no_behavioural_pass.
0b75cea2867efull audit observations/trust-audit/mcp-server/outcast1000__viboplr.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0b75cea2867e | BLOCK | F | 30 | first audit |
Questions
What is the viboplr MCP server?
Plugin-first desktop music player for macOS and Windows — local library, streaming services, lyrics, and radio. Built with Tauri 2, React, and Rust.
What tools does viboplr expose?
14 in total: 13 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is viboplr safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (30/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does viboplr need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (0b75cea2867e), read on 2026-10-08. The repository is watched and re-audited when it changes.