lms-mcp (shermozle/lms-mcp) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 55 tools. No publisher has claimed this listing.
MCP server that provides LLM tools to interact with Lyrion Music Server (LMS), enabling player control, playback management, playlist operations, and music library search.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
shermozle
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
get_playersGet all available players from the LMS server
get_player_statusGet the current status of a specific player
play_pausePlay or pause a player
set_volumeSet the volume of a player (0-100)
seekSeek to a specific position in the current track
play_trackPlay a specific track by ID
playlist_actionPerform playlist actions (play, pause, stop, next, previous, shuffle, repeat)
search_tracksSearch for tracks
search_artistsSearch for artists
search_albumsSearch for albums
get_playlistsGet all available playlists
get_genresGet all genres available in the music database
search_tracks_by_genreSearch for tracks by genre
get_current_playlistGet the current playlist for a player
add_to_playlistAdd a track to the current playlist
clear_playlistClear the current playlist
sync_playersSynchronize two players (master controls slave)
unsync_playerRemove a player from synchronization (unsync)
get_sync_statusGet synchronization status for a specific player
get_sync_groupsGet all synchronization groups
test_connectionTest connection to the LMS server
play_urlPlay a direct URL or stream on a player (internet radio, podcast, etc.)
add_url_to_playlistAdd a direct URL or stream to the current playlist
get_favoritesGet all favorites (often includes radio stations and online streams)
add_favoriteAdd a URL or stream to favorites
play_favoritePlay a favorite by item ID on a player
get_radiosGet radio directory categories and apps (TuneIn, etc.)
search_radioSearch TuneIn radio stations and podcasts
play_radio_itemPlay a TuneIn radio search result by item ID on a player
get_appsGet installed online music apps (TIDAL, Spotify, Qobuz, YouTube, etc.)
browse_appBrowse an online music app menu (TIDAL, Spotify, etc.)
search_appSearch within an online music app (TIDAL, Spotify, etc.)
play_app_itemPlay an item from an online music app by item ID
set_powerTurn a player on, off, or toggle power
set_sleep_timerSet a sleep timer on a player in seconds
set_bassSet bass level on a player (-100 to 100)
set_trebleSet treble level on a player (-100 to 100)
set_balanceSet left/right balance on a player (-100 to 100)
set_loudnessEnable or disable loudness compensation on a player
set_muteMute or unmute a player
jump_to_playlist_indexJump to a specific track index in the current playlist
delete_playlist_itemDelete a track from the current playlist by index
move_playlist_itemMove a track within the current playlist
save_playlistSave the current player playlist as a named playlist
delete_saved_playlistDelete a saved playlist
rename_saved_playlistRename a saved playlist
get_server_statusGet LMS server status and library statistics
rescan_libraryTrigger a library rescan
set_random_playStart or stop a random play mix
set_shuffleSet shuffle mode on a player
set_repeatSet repeat mode on a player
get_yearsGet years available in the music library
get_decadesGet decades available in the music library
get_new_musicGet recently added albums
get_random_albumsGet a random selection of albums
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Axios is vulnerable to DoS attack through lack of data size check
Axios: Header Injection via Prototype Pollution
LMS_HOSTIP address or hostname of your LMS server (default: localhost)LMS_PORTPort number of your LMS server (default: 9000)LMS_PROTOCOLProtocol to use (http or https, default: http)LMS_TIMEOUTRequest timeout in milliseconds (default: 10000)All four hints declared on every tool
55/55 tools missing one or more hints — get_players (missing: destructiveHint, idempotentHint, openWorldHint); get_player_status (missing: destructiveHint, idempotentHint, openWorldHint); play_pause (missing: destructiveHint, idempotentHint, openWorldHint), +52 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 14 high severity in production deps — axios@1.6.0 (high), axios@1.6.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/shermozle/lms-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check