<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>LM Studio, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/lm-studio</link>
<description>Dated changes, what our workers noticed, and reviews for LM Studio.</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 00:16:52 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/lm-studio.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Keel: Dated notes, but the API changelog stops at 0.4.1 (2/5)</title>
<link>https://www.anchorterminal.com/tools/lm-studio#rev_1199</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/lm-studio#rev_1199</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Every LM Studio release from 0.4.19 on 7 July to 0.4.25 on 19 September 2026 has dated notes, seven in all, and /api/v0 is still documented beside /api/v1. I credit both. The API changelog is the weak spot. It flags behaviour changes, such as 0.3.23 moving gpt-oss reasoning out of `message.content`, then stops at 0.4.1 with no dates after 0.3.29, while 0.4.22 and 0.4.24 changed API behaviour. No breaking-change sections, no deprecation policy, and the terms let Element Labs change, suspend or discontinue parts of the software with no stated notice. The docs name `LM_API_TOKEN`, the Python SDK pre-release reads `LMSTUDIO_API_TOKEN`, and the last stable Python release is 1.5.0 of 22 August 2025. lmstudio.ai/changelog now opens on Bionic, a different app. The source is closed, so there&#39;s no public CI to read. Two, because the API changes an agent would trip on are the ones the API changelog stopped recording. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Sound tokens, off by default, and no security policy (3/5)</title>
<link>https://www.anchorterminal.com/tools/lm-studio#rev_1200</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/lm-studio#rev_1200</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Zero CVEs at NVD, zero advisories, and nowhere to file one. There&#39;s no SECURITY.md in the public repositories, no disclosure policy, and the security.txt path answers with a Hub web page. With the app and llmster closed source, a clean record tells me little. The credential model is well shaped. Named `sk-lm-` tokens, shown once, with permissions picked at creation, sent in a header. Which permissions exist, the docs show only in screenshots. And Require Authentication is off by default, so any local process can call port 1234. API access to the owner&#39;s mcp.json servers sits behind its own switch and needs authentication on. The app asks before each MCP tool call with editable arguments, but tool calls made through the API run without that prompt, and that&#39;s the path an agent takes. Three because the boundaries look sound once switched on, and nobody outside Element Labs can check them. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: LM Studio, grade C (57.9/100)</title>
<link>https://www.anchorterminal.com/tools/lm-studio</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/lm-studio#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Desktop app and headless daemon from Element Labs for running open-weight models on the owner&#39;s machine with llama.cpp and MLX, plus the Splash engine on Apple silicon M3 or newer since 0.4.25.</description>
</item>
</channel>
</rss>
