# javaperf

MCP server for Java application profiling via JDK utilities (jcmd, jfr, jps)

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 1.4.2
- **Author:** theSharque
- **License:** MIT
- **npm:** javaperf
- **Source:** https://github.com/theSharque/mcp-jperf
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-04T19:34:43.657Z
- **Version scanned:** 1.4.2
- **CVEs:** none found by OSV at scan time

## Tools

26 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `list_java_processes` — Lists all running Java processes on the machine. Returns an array of objects with pid, mainClass, and args. Use this tool first to discover the target process P
- `start_profiling` — Starts JFR on the target PID. Rotates recordings (old_profile.jfr ← new_profile.jfr). Default preset is profile. Optional preset or settingsFile (.jfc, cwd-rela
- `stop_profiling` — Stops an active JFR recording and saves it to recordings/new_profile.jfr. Use recordings/new_profile.jfr for current data, recordings/old_profile.jfr for previo
- `check_deadlock` — Checks for Java-level deadlocks in the specified process. Parses jcmd Thread.print output and returns structured JSON: which threads are involved, what locks th
- `list_jfr_recordings` — Lists active and recent JFR recordings for a Java process (jcmd JFR.check). Returns recording id, duration, state (running/stopped), and filename. Use before st
- `analyze_threads` — Thread dump (jstack -l). Default: plain text. Set structured=true for JSON lock-wait chains (live snapshot). Historical contention: profile_jfr_locks. Deadlock 
- `heap_histogram` — Static class histogram (jcmd GC.class_histogram). For live growth over time use heap_live_histogram_diff instead.
- `heap_live_histogram_diff` — Two GC.class_histogram snapshots spaced by intervalSeconds; returns classes whose instance count grew most. Use first in memory-leak workflow; then profile_memo
- `heap_dump` — Creates .hprof for Eclipse MAT / VisualVM. After heap_live_histogram_diff picks a growing class, use MAT Path to GC Roots (exclude weak/soft). Saved to recordin
- `heap_info` — Brief heap usage summary: capacities, used, committed regions. Quick snapshot without full dump.
- `vm_info` — JVM information: uptime, version, and flags. Useful for environment verification.
- `trace_method` — Builds a call tree for a specific method from a .jfr file. Filters ExecutionSample events to find stack traces containing the given class and method, then aggre
- `parse_jfr_summary` — Parses a .jfr file and returns a structured summary: top methods by CPU samples, GC statistics, thread allocation stats, and anomaly hints (e.g. high GC count).
- `profile_memory` — JFR memory profile: top allocators by bytes/count, allocation stacks, OldObjectSample by class (allocation site, not GC roots). Pair with heap_live_histogram_di
- `gc_efficiency` — GC efficiency from .jfr: pause time vs freed bytes per collector/cause. Use after stop_profiling; complements profile_memory and heap_info. Not a general JFR su
- `profile_time` — CPU time (bottleneck) profile from a .jfr file. Uses bottom-up aggregation: each method is counted in every sample where it appears in the stack, including time
- `profile_frequency` — Call frequency profile from a .jfr file. Counts methods that appear at the leaf (top) of the stack in ExecutionSample events — i.e. methods that were actively e
- `profile_jfr_network` — Summarize JDK socket I/O from a .jfr (jdk.SocketRead, jdk.SocketWrite): event counts, total bytes read/written where available, top endpoints (host:port / addre
- `profile_jfr_file_io` — Summarize file read/write events (jdk.FileRead, jdk.FileWrite): counts, bytes, top paths, stack hotspots. Events must exist in recording; configure via start_pr
- `profile_jfr_locks` — Lock contention from JFR: synchronized monitors (JavaMonitorBlocked) and j.u.c parking (ThreadPark). Live wait chains: analyze_threads structured=true. Deadlock
- `profile_jfr_native` — CPU-style cumulative hotspots from jdk.NativeMethodSample stacks. Recording must enable NativeMethodSample (often requires custom .jfc).
- `native_memory_summary` — jcmd VM.native_memory summary=true. Requires JVM started with -XX:NativeMemoryTracking=summary or detail; otherwise explains how to enable.
- `gc_class_stats` — jcmd GC.class_stats (class loader / metaspace style stats where supported—often JDK 21+). On older JDK returns error hint; use heap_info or heap_histogram inste
- `gc_finalizer_info` — jcmd GC.finalizer_info — finalizer queue diagnostics for the live process.
- `compiler_codecache` — jcmd Compiler.codecache — code heap usage and related JVM output.
- `compiler_queue` — jcmd Compiler.queue — methods queued for JIT compilation.

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"javaperf\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"javaperf\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 13, ceiling 31 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/javaperf
- Install plan: https://forgeregistry.com/api/v1/packages/javaperf/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/javaperf
- HTML page: https://forgeregistry.com/registry/javaperf
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
