B
Emerging
89/100
1 day ago

vmlx

vMLX - JANGTQ Uber Compressed MLX Models - L2 Disk Cache (survives restart) + L1 Paged (super fast ttft) + Hybrid SSM Scheduler + Cont Batching + etc!

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

jjang-ai

Source: github_topic

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: VMLX_GEMMA_API_KEY, VMLX_MM3_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 3 credentials: BRAVE_API_KEY, VMLX_CLUSTER_SECRET, VLLM_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretBRAVE_API_KEY
configELECTRON_RENDERER_URL
configVMLINUX_NATIVE_MTP_ALLOW_JANG2K
configVMLX_NATIVE_MTP_ALLOW_JANG2K
configVMLX_REMOTE_DEBUG_PORT
configVMLX_TOOL_STREAM_STALL_TIMEOUT_MS
configVMLINUX_DSV4_TRACE_TIMINGS
configVMLINUX_MIMO_MEDIA_CAPABILITY_REJECT_PCT
configVMLINUX_MIMO_MEDIA_CAPABILITY_MIN_FREE_GB
configVMLX_ALLOW_EXPERIMENTAL_MXFP_AUDIO
configVMLINUX_ALLOW_EXPERIMENTAL_MXFP_AUDIO
configVMLINUX_ALLOW_EXPERIMENTAL_GEMMA4_DIRECT_AUDIO
configVMLX_ALLOW_EXPERIMENTAL_GEMMA4_DIRECT_AUDIO
configVLLM_MLX_MCP_ENABLED_SERVERS
configVLLM_MLX_MCP_DISABLED_SERVERS
configVLLM_MLX_MCP_ENABLED_TOOLS
configVLLM_MLX_MCP_DISABLED_TOOLS
configVMLX_MEMORY_PRESSURE_GUARD
configVMLX_MEMORY_PRESSURE_REJECT_PCT
🔐 secretVMLX_CLUSTER_SECRET
configJANGTQ_MPP_NAX
configDSV4_ACTIVATION_QAT
configDSV4_POOL_QUANT
configVMLX_LOG_REQUEST_FIELDS
configVMLX_RESPONSES_HISTORY_MAX
🔐 secretVLLM_API_KEY
configVMLX_STRICT_BLOCK_DISK_WRITE_FENCE
configVMLINUX_NATIVE_MTP
configVMLINUX_NATIVE_MTP_DEPTH
configVMLINUX_NATIVE_MTP_SAMPLING_POLICY
configVMLINUX_OMNI_BACKEND
configVLLM_MLX_MCP_CONFIG
configVMLINUX_BENCH_PYTHON
configVMLINUX_BENCH_EXTRA_SERVE_ARGS
configVMLINUX_BENCH_EXTRA_PYTHONPATH
configVMLINUX_BENCH_ISOLATED
configVMLX_SRC
configTOKENIZERS_PARALLELISM
configVMLX_DISABLE_TQ_KV
configVMLX_BLOCK_DISK_PENDING_WRITE_BYTES
configVMLX_ZAYA_DISABLE_PREFIX_REUSE
configDSV4_LONG_CTX
configPYTHONWARNINGS
configVMLX_M3_VL
configVMLX_OMNI_BACKEND
configVMLX_PREFILL_KEEP_ALLOC
configJANGTQ_WIRED_LIMIT_GB
configVMLINUX_CONTEXT_OUTPUT_CLAMP
configVMLX_DFLASH2_PREFIX_REUSE
configVMLINUX_MIMO_TEXT_PREFILL_GUARD
configVMLINUX_MIMO_TEXT_PREFILL_REJECT_TOKENS
configVMLINUX_MIMO_TEXT_PREFILL_TOTAL_TOKENS
configVMLX_VLM_IMAGE_CACHE_LIMIT
configVMLX_VLM_IMAGE_CACHE_LIMIT_GB
configVMLX_VLM_IMAGE_CACHE_LIMIT_FREE_FRACTION
configVMLX_VLM_IMAGE_CACHE_LIMIT_FLOOR_GB
configVMLX_VLM_IMAGE_PREFILL_GUARD
configVMLX_METAL_WS_REJECT_PCT
configVMLX_HYBRID_MIN_CHUNK
configVMLX_TIGHT_PROJECTED_STEP_CAP
configVMLX_HYBRID_ONE_SHOT_GUARD_BYTES
configVMLX_DEEP_SPAN_CACHE_CLEAR_TOKENS
configVMLX_DECODE_PRESIZE_HEADROOM
configVMLX_TURN_PEAK_ALLOWANCE_MB
configVMLINUX_MIMO_V2_TOKEN_TRACE
configVMLINUX_MIMO_V2_TOKEN_TRACE_TOPK
configVMLX_TQ_RECOMPRESS_MAX_TOKENS
configVMLX_MTP_CYCLE_FENCE
configVMLINUX_NATIVE_MTP_TRACE
configVMLINUX_MLLM_DECODE_SYNC_EVAL
configVMLINUX_MLLM_PREFILL_TRACE
configVMLINUX_NATIVE_MTP_DEBUG_TOKENS
configVMLINUX_NATIVE_MTP_BURST
configVMLINUX_DECODE_TRACE
configVMLINUX_DECODE_TRACE_EVERY
configVMLINUX_MLLM_TIGHT_MEMORY_DRAIN
configVMLX_DISABLE_SSM_INLINE_CAPTURE
configVMLINUX_MLLM_MEDIA_PREFIX_CACHE
configVMLX_ALLOW_HYBRID_CHUNKED_PREFILL
configVMLINUX_ALLOW_HYBRID_CHUNKED_PREFILL
configVMLINUX_ENABLE_NATIVE_MTP_HYBRID_TEXT_SPLIT
configVMLX_ENABLE_NATIVE_MTP_HYBRID_TEXT_SPLIT
configVMLX_DISABLE_HYBRID_AUTO_CHUNK
configVMLX_TIGHT_PREFILL_ADAPTIVE_GROWTH
configVMLX_DECODE_KV_PRESIZE
configVMLINUX_MLLM_SCHEDULER_TRACE
configVMLX_QWEN_VL
configVMLINUX_OMNI_VIDEO_FPS
configVMLINUX_OMNI_VIDEO_MAX_FRAMES
configVMLINUX_OMNI_VIDEO_DEDUP_MAD
configVMLINUX_OMNI_VIDEO_CONTACT_SHEET
configVMLINUX_OMNI_SESSION_CACHE_DIR
configVMLX_OMNI_ENCODER_DEVICE
configVMLX_CACHE_HASH_DEBUG
configVMLX_PAGED_FRUGAL
configVMLX_DSV4_TERMINAL_ANCHOR_TAIL
configVMLX_RECONSTRUCT_MEMO_MAX_WS_PCT
configVMLX_DSV4_RECONSTRUCT_MEMO
configVMLX_PLD_MAX_TEMP
configVMLX_ALLOW_MLA_KV_QUANT
configVMLX_CACHE_REUSE_BUDGET_FRACTION
configVMLINUX_CACHE_SELECTION_HOT_ADVANTAGE_TOKENS
configVMLX_DISABLE_SSM_PREFIX_RESUME
configVMLX_TQ_DECODE_TIMING
configTWINE
configVMLX_JANG_TOOLS_SOURCE
configVMLINUX_JANG_TOOLS_SOURCE
configVMLX_R20_RELEASE_ATTESTATION
configVMLX_R20_PRIVATE_EVIDENCE_ROOT
// quality suggestions

Shell command execution

97 child_process/subprocess calls in production code — runs shell commands (panel/src/main/ipc/coding-tools.ts:179, panel/src/main/ipc/coding-tools.ts:277, panel/src/main/ipc/coding-tools.ts:573)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets not logged

13 secret values sent to console.log

Redact or omit secret values from log output.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 2 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/jjang-ai-vmlx-li8asy)](https://m8ven.ai/mcp/jjang-ai-vmlx-li8asy)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 15ab55c09109fdfb16f9a57a5f74443f84282c6b
code hash: bfa8d24884a3a4558762066b7ed7d70953a39eceb53bde04ab4d007f0ccdc276
verified: 8/20/2026, 3:09:59 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client