No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by juliodelimas · MCP Server · ★ 64
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is jmeter-mcp-server safe to install? View the security audit →
jmeter-mcp-server Give an LLM real, deterministic control over Apache JMeter — build test plans, run real load tests, and read back real results, without ever hand-writing XML or opening the GUI. ...turns into a running JMeter test and a real report, through typed tool calls an MCP client (Claude Code, Claude Desktop, etc.) makes directly. Why not just ask an LLM to write the itself? It can — a is just XML, and any capable model has seen plenty of JMeter test plans. The problem is how it fails: JMeter's format is a with dozens of fragile, easy-to-misremember details — exact / pairs, property names that don't match their GUI label ( is a str
| Stars | 64 |
| Forks | 11 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 69.3428231895983/100 |
| Last Updated | 2026-09-03 |
| Created | 2026-08-26 |
| Platforms | mcp, node |
| Est. Tokens | ~19k |
These tools work well together with jmeter-mcp-server for enhanced workflows:
Explore other popular mcp server tools:
jmeter-mcp-server is Stdio MCP server to build, run and read reports for JMeter test plans. It is categorized as a MCP Server with 64 GitHub stars.
jmeter-mcp-server is primarily written in TypeScript.
You can find installation instructions and usage details in the jmeter-mcp-server GitHub repository at github.com/juliodelimas/jmeter-mcp-server. The project has 64 stars and 11 forks, indicating an active community.
jmeter-mcp-server is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: