JVMCAUTION
This is an implementation project of a JVM-based MCP (Model Context Protocol) server. The project aims to provide a standardized MCP server implementation for the JVM platform, enabling AI models to better interact with the Java ecosystem.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
[](https://mseep.ai/app/xzq-xu-jvm-mcp-server)
A lightweight JVM monitoring and diagnostic MCP (Multi-Agent Communication Protocol) server implementation based on native JDK tools. Provides AI agents with powerful capabilities to monitor and analyze Java applications without requiring third-party tools like Arthas.
Hosted deployment
A hosted deployment is available on Fronteir AI.
Features
- Zero Dependencies: Uses only native JDK tools (jps, jstack, jmap, etc.)
- Lightweight: Minimal resource consumption compared to agent-based solutions
- High Compatibility: Works with all Java versions and platforms
- Non-Intrusive: No modifications to target applications required
- Secure: Uses only JDK certified tools and commands
- Remote Monitoring: Support for both local and remote JVM monitoring via SSH
Core Capabilities
Basic Monitoring
- Java process listing and identification
- JVM basic information retrieval
- Memory usage monitoring
- Thread information and stack trace analysis
- Class loading statistics
- Detailed class structure information
Advanced Features
- Method call path analysis
- Class decompilation
- Method search and inspection
- Method invocation monitoring
- Logger level management
- System resource dashboard
System Requirements
- Python 3.6+
- JDK
d33931f23b89OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add jvm-mcp-server --env ARTHAS_SSH_PASSWORD=${ARTHAS_SSH_PASSWORD} --env SSH_KEY=${SSH_KEY} --env SSH_PASSWORD=${SSH_PASSWORD} -- uvx jvm-mcp-server{
"mcpServers": {
"jvm-mcp-server": {
"command": "uvx",
"args": [
"jvm-mcp-server"
],
"env": {
"ARTHAS_SSH_PASSWORD": "${ARTHAS_SSH_PASSWORD}",
"SSH_KEY": "${SSH_KEY}",
"SSH_PASSWORD": "${SSH_PASSWORD}"
}
}
}
}Exposed tools (21)
20 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
decompile_class | read | 反编译指定类的源码 |
get_class_info | read | 获取类信息 |
get_dashboard | read | 获取系统实时数据面板 |
get_index | read | 获取特定 Elasticsearch 索引的详细信息 |
get_jcmd_output | read | 执行 jcmd 子命令 |
get_jmx_gc_histogram | read | 通过 JMX/GC.class_histogram 获取 GC 类直方图 |
get_jmx_memory_info | read | 通过 JMX/GC.heap_info 获取内存信息 |
get_jmx_thread_dump | read | 通过 JMX/Thread.print 获取线程堆栈信息 |
get_jstat_output | read | 执行 jstat 监控命令 |
get_jvm_info | read | 获取JVM基础信息 |
get_jvm_status | read | 获取JVM整体状态报告 |
get_logger_info | read | 获取logger信息 |
get_memory_info | read | 获取内存使用情况 |
get_stack_trace | read | 获取指定线程的堆栈信息 |
get_stack_trace_by_method | read | 获取方法的调用路径 |
get_thread_info | read | 获取指定进程的线程信息 |
list_indices | read | 列出所有 Elasticsearch 索引 |
list_java_processes | read | 列出所有Java进程 |
search_method | read | 查看类的方法信息 |
set_logger_level | write | 设置logger级别 |
watch_method | read | 监控方法的调用情况 |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (9)
.coverage
.DS_Store
.coverage
.cursorindexingignore
.flake8
.DS_Store
#XQ|4. **In Docker**: Ensure the container has sufficient permissions (--privileged or mount /proc)
curl -LsSf https://astral.sh/uv/install.sh | sh # Linux/macOS
curl -LsSf https://astral.sh/uv/install.sh | sh # Linux/macOS
Gates applied: no_behavioural_pass.
d33931f23b89full audit observations/trust-audit/mcp-server/xzq-xu__jvm.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d33931f23b89 | CAUTION | B | 89 | first audit |
Questions
What is the JVM MCP server?
This is an implementation project of a JVM-based MCP (Model Context Protocol) server. The project aims to provide a standardized MCP server implementation for the JVM platform, enabling AI models to better interact with the Java ecosystem.
What tools does JVM expose?
21 in total: 20 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is JVM safe to connect to an agent?
With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does JVM need?
It reads ARTHAS_SSH_PASSWORD, SSH_KEY and SSH_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (d33931f23b89), read on 2026-10-07. The repository is watched and re-audited when it changes.