Atlas / MCP servers / outcast1000 / viboplr

viboplrBLOCK

mcp/outcast1000/viboplr

Plugin-first desktop music player for macOS and Windows — local library, streaming services, lyrics, and radio. Built with Tauri 2, React, and Rust.

Verdict
BLOCK
Grade
F
Trust score
30 /100
Exposed tools
14 13r · 1w · 0d
Transport
—
License
GPL-3.0
Stars
3
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The music player you can just talk to, built by talking to an AI.

Viboplr is a free, open-source desktop music player for macOS and Windows, and it is AI-native in both directions:

  • Driven by AI. A built-in MCP server lets Claude, or any AI assistant, run your music library. Ask it to build playlists, fix tags, organise folders, download tracks, or tell you what you played most last March.
  • Built by AI. Every line of code was written by an AI coding assistant (Claude Code). The human role is tech lead and product owner: decide what to build, define how it behaves, review, test, and push back until it's right. The story →

Under the hood it's a Tauri 2 app with a Rust backend and a React frontend. It plays audio and video from local folders and Subsonic/Navidrome servers, and works as an orchestrator: a plugin system connects streaming providers, metadata services, lyric databases and image sources, while the core handles playback, the library and the UI. Its SQLite library starts fast, plays instantly and searches big collections in milliseconds.

AI Control (MCP)

Viboplr ships its own MCP server, so an AI assistant gets real, typed tools for your music library instead of screen-scraping. Turn on Settings → AI control, press Copy config (Claude Desktop) or Copy command (Claude Code), and paste it into your client.

"Tag everything by Boards of Canada as ambient, and file the compilations under Various Artists." "Sort the loose files in my Music folder into Artist/Album." "Make me a playlist of songs I loved and haven't played this year."
  • Listen: search, play, queue, skip, start radio, like, and drive the window and views
  • Curate: create and edit playlists, edit tags in bulk, rename listening history
  • Ask: read-only SQL over the library and play history ("what did I play most last March?"), lyrics, bios, and reviews
  • **Care for
Read from source at commit 0b75cea2867eOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add viboplr -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "viboplr": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (14)

13 read · 1 write · 0 destructive.

ToolRiskDescription
downloadreadDownload
ffmpegreadAudio/video transcoding and format conversion
fictional-toolreadA fake dependency for testing the dependency UI (debug only)
get_statereadSimulation settings
inforeadInfo
legacyreadDeclares nothing
list_playlistsreadThe scraped playlists
roadiereadInstalls, runs and updates helper services such as slskd, each only after you approve it
rqbitreadBitTorrent downloads (one-shot, no client to configure)
searchreadSearch
search_catalogreadSearch the fake catalog
similarreadSimilar
statuswriteSync state
yt-dlpreadYouTube video/audio downloading
04

Trust audit

BLOCKgrade F · trust 30/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (13 observation(s))
Network
declared (6 observation(s))
Shell
declared (9 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/hooks/usePlugins.ts:2233
const factory = new Function("api", "window", "globalThis", "self", "document", code);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/pluginWorker/runtime.ts:133
const factory = new Function("api", "window", "globalThis", "self", "document", init.code);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/types/plugin.ts:1158
eval(js: string): Promise<void>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/types/plugin.ts:1844
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/viboplr-control/SKILL.md:61
| `POST /query` | `{sql, params?, limit?}` — **ad-hoc read-only SQL** (SQLite) for analytics the endpoints can't express (plays per year, liked-but-never-played, joins over history). One SELECT per ca
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/now-playing-view-spec.md:98
order, first `status: "ok"` wins; consult/upsert the info-value cache
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/lib/features.mjs:179
<script defer src='https://static.cloudflareinsights.com/beacon.min.js' data-cf-beacon='{"token": "cbb978698d3744cca00a24f8cac8bc3c"}'></script>
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/aptabase/docker-compose.yml:21
ASPNETCORE_URLS: http://0.0.0.0:8080
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/perf-probe.mjs:730
["Δcpu", 9],
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/perf-probe.mjs:733
["ΔwsCPU", 9],
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/perf-probe.mjs:734
["ΔwsGPU", 9],
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/perf-probe.mjs:783
? "ΔwsCPU/ΔwsGPU = dwm.exe's (Desktop Window Manager) rise over the baseline. Compositing is billed to DWM's"
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/perf-probe.mjs:784
: "ΔwsCPU/ΔwsGPU = WindowServer's rise over the baseline. Compositing is billed to WindowServer's own",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
README.md:255
| `VPS_SSH_PRIVATE_KEY` | The private key (full contents, including header/footer lines) whose public key is in the VPS user's `~/.ssh/authorized_keys` | `-----BEGIN OPENSSH PRIVATE KEY-----` ... |
LOWInventory / provenance · inv.binary · CWE-1104
docs/assets/media/bit-perfect.webm
bit-perfect.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/assets/media/gapless.webm
gapless.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/assets/media/home.webm
home.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/assets/media/lyrics.webm
lyrics.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/assets/media/mini-player.webm
mini-player.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.suspicious_name · CWE-1104
src-tauri/tests/fixtures/plugin-signing/plugin.payload.txt
plugin.payload.txt
Why it matters. member named after an attack tool
Fix. remove or justify
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/deploy-umami.yml:35
mkdir -p ~/.ssh
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/deploy-umami.yml:36
chmod 700 ~/.ssh
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/deploy-umami.yml:37
printf '%s\n' "$SSH_PRIVATE_KEY" > ~/.ssh/deploy_key
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/deploy-umami.yml:38
chmod 600 ~/.ssh/deploy_key
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/deploy-umami.yml:40
ssh-keyscan -p "$PORT" -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null
Why it matters. touches a credential store

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0b75cea2867efull audit observations/trust-audit/mcp-server/outcast1000__viboplr.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-080b75cea2867eBLOCKF30first audit
06

Questions

What is the viboplr MCP server?

Plugin-first desktop music player for macOS and Windows — local library, streaming services, lyrics, and radio. Built with Tauri 2, React, and Rust.

What tools does viboplr expose?

14 in total: 13 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is viboplr safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (30/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does viboplr need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (0b75cea2867e), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement