76
/ 100
1 month ago
github_topic

wmux

Windows tmux alternative for AI agents — split terminals for Claude Code, Codex, Gemini CLI with MCP browser automation. No WSL required.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Tool descriptions don’t match what handlers do
1 tool describes read intent but its handler mutates — company_a2a_ack (line 148: execFileSync(ps, [)
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 4 credentials: APPLE_APP_SPECIFIC_PASSWORD, WMUX_AUTH_TOKEN, WMUX_MINISERVER_TOKEN, WMUX_WSID_PROBE_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 medium4 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

mediumvite@5.4.21GHSA-4w7w-66w2-5vf9

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

lowelectron@41.0.3GHSA-8x5q-pvf5-64mp

Electron: Use-after-free in offscreen shared texture release() callback

lowelectron@41.0.3GHSA-f37v-82c4-4x64

Electron: Crash in clipboard.readImage() on malformed clipboard image data

lowelectron@41.0.3GHSA-f3pv-wv63-48x8

Electron: Named window.open targets not scoped to the opener's browsing context

lowpostcss@8.5.8GHSA-qx2v-qp2m-jg93

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretAPPLE_APP_SPECIFIC_PASSWORD
configAPPLE_ID
configAPPLE_TEAM_ID
configCDPRandomized port — no fixed debug port
configCDP_URL
configCYCLES
configComSpec
configPath
configProgramFiles
configSHELL
configSystemRoot
configTAG
configWMUX_APP_ROOT
🔐 secretWMUX_AUTH_TOKEN
configWMUX_BRIDGE_DEBUG
configWMUX_DATA_SUFFIX
configWMUX_IDLE_GRACE_MS
configWMUX_IDLE_SHUTDOWN_MS
configWMUX_MINISERVER_OWNERS
configWMUX_MINISERVER_PIPE
configWMUX_MINISERVER_RESOLVE_ONCE
🔐 secretWMUX_MINISERVER_TOKEN
configWMUX_MINISERVER_WORKSPACES
configWMUX_SOCKET_PATH
configWMUX_SURFACE_ID
configWMUX_WATCHDOG_TICK_MS
configWMUX_WORKSPACE_ID
configWMUX_WSID_PROBE_DOUBLE
configWMUX_WSID_PROBE_PIPE
🔐 secretWMUX_WSID_PROBE_TOKEN
configWS_NAME
configXDG_CONFIG_HOME
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 9 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/openwong2kim-wmux-r0kgtr)](https://m8ven.ai/mcp/openwong2kim-wmux-r0kgtr)
commit: 27a79a3c89b004e6aba9ff1d21fdfabc921ef033
code hash: c9967b231e80b3b739a39e4ce1b77c6a5e0985a31782a8851fb8e88c2c4e1df4
verified: 6/14/2026, 11:01:00 AM
view raw JSON →