Atlas / MCP servers / xzq-xu / JVM

JVMCAUTION

mcp/xzq-xu/jvm

This is an implementation project of a JVM-based MCP (Model Context Protocol) server. The project aims to provide a standardized MCP server implementation for the JVM platform, enabling AI models to better interact with the Java ecosystem.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
21 20r · 1w · 0d
Transport
—
License
MIT
Stars
90
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

[](https://mseep.ai/app/xzq-xu-jvm-mcp-server)

A lightweight JVM monitoring and diagnostic MCP (Multi-Agent Communication Protocol) server implementation based on native JDK tools. Provides AI agents with powerful capabilities to monitor and analyze Java applications without requiring third-party tools like Arthas.

Hosted deployment

A hosted deployment is available on Fronteir AI.

Features

  • Zero Dependencies: Uses only native JDK tools (jps, jstack, jmap, etc.)
  • Lightweight: Minimal resource consumption compared to agent-based solutions
  • High Compatibility: Works with all Java versions and platforms
  • Non-Intrusive: No modifications to target applications required
  • Secure: Uses only JDK certified tools and commands
  • Remote Monitoring: Support for both local and remote JVM monitoring via SSH

Core Capabilities

Basic Monitoring

  • Java process listing and identification
  • JVM basic information retrieval
  • Memory usage monitoring
  • Thread information and stack trace analysis
  • Class loading statistics
  • Detailed class structure information

Advanced Features

  • Method call path analysis
  • Class decompilation
  • Method search and inspection
  • Method invocation monitoring
  • Logger level management
  • System resource dashboard

System Requirements

  • Python 3.6+
  • JDK
Read from source at commit d33931f23b89OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add jvm-mcp-server --env ARTHAS_SSH_PASSWORD=${ARTHAS_SSH_PASSWORD} --env SSH_KEY=${SSH_KEY} --env SSH_PASSWORD=${SSH_PASSWORD} -- uvx jvm-mcp-server
claude-desktop
{
  "mcpServers": {
    "jvm-mcp-server": {
      "command": "uvx",
      "args": [
        "jvm-mcp-server"
      ],
      "env": {
        "ARTHAS_SSH_PASSWORD": "${ARTHAS_SSH_PASSWORD}",
        "SSH_KEY": "${SSH_KEY}",
        "SSH_PASSWORD": "${SSH_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (21)

20 read · 1 write · 0 destructive.

ToolRiskDescription
decompile_classread反编译指定类的源码
get_class_inforead获取类信息
get_dashboardread获取系统实时数据面板
get_indexread获取特定 Elasticsearch 索引的详细信息
get_jcmd_outputread执行 jcmd 子命令
get_jmx_gc_histogramread通过 JMX/GC.class_histogram 获取 GC 类直方图
get_jmx_memory_inforead通过 JMX/GC.heap_info 获取内存信息
get_jmx_thread_dumpread通过 JMX/Thread.print 获取线程堆栈信息
get_jstat_outputread执行 jstat 监控命令
get_jvm_inforead获取JVM基础信息
get_jvm_statusread获取JVM整体状态报告
get_logger_inforead获取logger信息
get_memory_inforead获取内存使用情况
get_stack_traceread获取指定线程的堆栈信息
get_stack_trace_by_methodread获取方法的调用路径
get_thread_inforead获取指定进程的线程信息
list_indicesread列出所有 Elasticsearch 索引
list_java_processesread列出所有Java进程
search_methodread查看类的方法信息
set_logger_levelwrite设置logger级别
watch_methodread监控方法的调用情况
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (9)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.coverage
.coverage
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coverage
.coverage
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cursorindexingignore
.cursorindexingignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.flake8
.flake8
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWContainer / deploy · priv.container · CWE-250, CWE-16
README.md:250
#XQ|4. **In Docker**: Ensure the container has sufficient permissions (--privileged or mount /proc)
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:64
curl -LsSf https://astral.sh/uv/install.sh | sh  # Linux/macOS
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README_zh.md:56
curl -LsSf https://astral.sh/uv/install.sh | sh  # Linux/macOS

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d33931f23b89full audit observations/trust-audit/mcp-server/xzq-xu__jvm.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d33931f23b89CAUTIONB89first audit
06

Questions

What is the JVM MCP server?

This is an implementation project of a JVM-based MCP (Model Context Protocol) server. The project aims to provide a standardized MCP server implementation for the JVM platform, enabling AI models to better interact with the Java ecosystem.

What tools does JVM expose?

21 in total: 20 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is JVM safe to connect to an agent?

With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does JVM need?

It reads ARTHAS_SSH_PASSWORD, SSH_KEY and SSH_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (d33931f23b89), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement