MLX inference server for Apple Silicon — Text, Image, Video & Audio generation with 20+ agentic tools, voice, vision, Mamba, and 5-layer caching
vMLX exposes 6 tools with critical definition gaps. Tool definitions are inferred from filenames and minimal context rather than explicit server registration code. No input schemas are visible in the provided source material. Descriptions are present but generic (10-40 chars), lacking the LLM-optimized detail required for agent planning. Parameter types are not documented. No output schema documentation. Error handling guidance is absent. The codebase shows Electron/FastAPI infrastructure but the actual MCP tool registration logic is not provided, making schema validation impossible.
List directory contents.
Read a UTF-8 text file and return its content.
Read an image file.
Read a video file.
Execute a shell command in the working directory.
Write UTF-8 text content to a path.
No input schemas visible in source code. Tool definitions appear inferred from filenames rather than explicit registration with JSON Schema.
Descriptions are too generic and under 20 characters (e.g., 'Read a UTF-8 text file' is 22 chars but lacks WHEN/WHY guidance).
No parameter type documentation. Schema shows parameter names ('command', 'path', 'content', 'recursive') but no type definitions (string, boolean, integer), constraints (min/max, enums), or validation rules visible.
Destructive tool (run_command) has no confirmation, dry-run, or rate-limiting mechanism. No error handling or recovery guidance documented.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 42 | 2026-07-28+ | v2 |
No output schema documented. Agents cannot plan downstream tool calls or extract expected fields (e.g., what does read_file return, just content, or also metadata like size/encoding/last_modified?).
list_directory accepts a 'recursive' boolean but no limit or pagination parameters. Large directory traversals could return thousands of entries, exhausting context windows without guidance on result limits.
Parameter descriptions lack format constraints. 'path' parameter in read_file has no guidance on absolute vs. relative paths, symlink handling, or which roots are accessible. 'command' in run_command has no shell or environment documentation.
No error classification or recovery guidance. If run_command fails, write_file encounters permission denied, or read_file hits a 404, agents have no actionable error message or retry strategy.
File operations lack security boundaries. No documentation of accessible paths, sandbox roots, or permission models. run_command with unbounded shell access is a major security risk without explicit safeguards.