Atlas / MCP servers / alikarami / Mikro

MikroBLOCK

mcp/alikarami/mikro

Production-grade MCP server for MikroTik RouterOS with secure AI-native network automation.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
122 62r · 25w · 35d
Transport
sse · stdio · streamable-http
License
MIT
Stars
72
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI-native network automation for MikroTik RouterOS. MikroMCP exposes RouterOS as a typed, auditable Model Context Protocol server so Claude, Cursor, Codex, and other MCP clients can inspect, diagnose, and safely operate MikroTik routers in natural language.

[](https://github.com/AliKarami/MikroMCP/actions/workflows/ci.yml) [](https://github.com/AliKarami/MikroMCP/actions/workflows/release.yml) [](package.json) [](LICENSE) [](package.json) [](https://help.mikrotik.com/docs/display/ROS/REST+API) [](https://modelcontextprotocol.io) [](https://github.com/AliKarami/MikroMCP/wiki/Available-Tools) [](https://glama.ai/mcp/servers/AliKarami/MikroMCP)

MikroMCP exists because raw router CLI access is the wrong abstraction for AI agents. RouterOS is powerful, but asking an LLM to improvise shell commands against production network gear is risky. MikroMCP gives agents a controlled tool surface: strict schemas, idempotent writes, dry-run previews, per-router circuit breakers, retry

Read from source at commit 52a3285b5d24OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mikromcp -- npx -y [email protected]
03

Exposed tools (122)

62 read · 25 write · 35 destructive. Blast radius: 35 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
apply_planwriteExecute write operations in order, stopping on first failure. Each step is snapshotted and journaled individually. Non-admin identities need a confirmationToken (same two-step flow as other destructive tools). Undo individual steps via rollback_change with the returned journal IDs.
bandwidth_testwriteRun a RouterOS bandwidth test from the router to a remote host running a RouterOS btest server. Returns TX and RX throughput in Mbps. Duration capped at 20 seconds. Saturates the link — not auto-retried.
bulk_executewriteFan out a single-router tool to many routers in parallel (up to
bulk_readreadFan out a read-only single-router tool (list_*, get_* and others annotated read-only) to many routers in parallel (up to
check_router_healthreadProbe a device: RouterOS routers via system/resource, SwOS switches via sys.b. Returns health status, firmware version, uptime, and (RouterOS only) CPU load and memory info. Unlike other tools, this never throws — unreachable devices are reported as healthy=false.
create_backupwriteCreate a binary configuration backup on a MikroTik router. The backup is saved as <name>.backup on the router
delete_filedestructiveDelete a file from the router filesystem by name. Idempotent: returns not_found gracefully if the file does not exist.
export_configreadExport the router configuration as a RouterOS script. When no file is specified, returns the script text inline. When a file is specified, saves it as <file>.rsc on the router
fetch_urlwriteSend an HTTP/HTTPS request from the router using /tool/fetch. Response body is returned inline (capped at 64 KB with [TRUNCATED] marker). Use outputFile to save to router filesystem instead. Not read-only: POSTs have side effects and outputFile writes to the router.
get_container_configreadRead global container configuration: registry URL, RAM high-water mark, and veth interface.
get_dns_settingsreadRead DNS resolver configuration: upstream servers, cache size, cache TTL, and whether remote DNS requests are allowed.
get_file_contentreadRead a text file
get_logreadRead and filter the system log from a MikroTik router. Supports filtering by topic, message prefix, and a time window (last N minutes) measured against the router
get_ntp_settingsreadRetrieve NTP client settings from a MikroTik router.
get_ovpn_serverreadGet the OpenVPN server configuration on a MikroTik router. Throws NOT_FOUND if the OpenVPN package is not installed.
get_snmp_settingsreadRetrieve SNMP settings from a MikroTik router.
get_swos_endpointreadFetch and decode a single SwOS
get_swos_statusreadRetrieve status from a MikroTik SwOS switch (SwOS or SwOS Lite): identity, model, firmware, uptime, per-port link state/speed/duplex, PoE mode/state/power, and SFP modules.
get_system_clockreadRead the current date, time, and timezone from a MikroTik router. Focused single-purpose alternative to the clock section in get_system_status.
get_system_statusreadRetrieve system status information from a MikroTik router including resource usage, identity, license, routerboard details, health sensors, and clock.
get_upgrade_statusreadRead the current RouterOS package upgrade status and routerboard firmware versions. Shows installed version, latest available version, update channel, and firmware upgrade availability.
list_address_list_entriesreadList firewall address list entries on a MikroTik router. Supports filtering by list name and address.
list_arp_entriesreadList ARP table entries on a MikroTik router.
list_bgp_peersreadList BGP sessions on a MikroTik router (RouterOS 7+). Returns state, remote AS, prefix counts, and uptime.
list_bridge_portsreadList bridge port entries (interface membership, PVID, STP role and status) on a MikroTik router. Supports filtering by bridge and interface, with pagination.
list_bridgesreadList bridge interfaces and their port members on a MikroTik router.
list_certificatesreadList certificates on a MikroTik router.
list_connectionsreadList active connection tracking entries from the router firewall table. Filters are applied client-side. Useful for diagnosing NAT and firewall behavior.
list_container_envsreadList container environment variable entries, optionally filtered by container name.
list_container_mountsreadList container volume mount definitions with source path, destination path, and mount name.
list_containersreadList RouterOS container instances with status, image, and network information.
list_dhcp_clientsreadList DHCP client configurations on a MikroTik router. Shows which interfaces obtain their IP via DHCP, current status, and assigned address.
list_dhcp_leasesreadList DHCP leases on a MikroTik router with optional filtering by server, status, lease type (dynamic/static), and MAC address. Supports pagination.
list_dhcp_serversreadList DHCP servers on a MikroTik router.
list_dns_entriesreadList static DNS entries on a MikroTik router with optional filtering by name and type.
list_filesreadList files on a MikroTik router filesystem. Supports filtering by name and type.
list_firewall_rulesreadList firewall rules from the filter or nat table on a MikroTik router. Supports filtering by chain and disabled state, with pagination.
list_interface_list_membersreadList interface list memberships (which interface belongs to which list, e.g. WAN/LAN) on a MikroTik router. Supports filtering by list and interface, with pagination.
list_interface_listsreadList all interface lists defined on the router.
list_interfacesreadList network interfaces on a MikroTik router with optional filtering by type and status. Supports pagination and optional traffic counters.
list_ip_addressesreadList IPv4 addresses assigned to interfaces on a MikroTik router, including dynamic ones (DHCP client, PPP). Supports filtering by interface and disabled state, with pagination.
list_ip_poolsreadList IP address pools on a MikroTik router. Supports filtering by name and pagination.
list_ip_servicesreadList IP services on a MikroTik router (api, api-ssl, ssh, telnet, www, www-ssl, winbox, ftp) with their port numbers and enabled/disabled status.
list_ipsec_peersreadList IPSec peers on a MikroTik router.
list_ipsec_policiesreadList IPSec policies on a MikroTik router.
list_log_actionsreadList RouterOS logging action targets (system/logging/action) with optional type filter.
list_log_rulesreadList RouterOS logging rules (system/logging) with optional topic substring and action exact-match filtering.
list_mangle_ruleswriteList firewall mangle rules on a MikroTik router in evaluation order. Supports filtering by chain, action, and disabled state.
list_neighborsreadList discovered neighbors (CDP/LLDP/MNDP) on a MikroTik router.
list_netwatch_entriesreadList Netwatch monitoring entries on a MikroTik router.
list_ospf_neighborsreadList OSPF neighbors on a MikroTik router (RouterOS 7+). Returns neighbor state, interface, DR/BDR, and uptime.
list_ovpn_clientsreadList OpenVPN client interfaces on a MikroTik router. Shows name, remote server, and connection status.
list_packagesreadList installed RouterOS packages with version and enabled status.
list_ppp_profilesreadList PPP profiles including the built-in default and default-encryption profiles.
list_pppoe_clientsreadList PPPoE client interfaces on a MikroTik router. Shows name, parent interface, ISP username, and connection status.
list_queuesreadList simple queues on a MikroTik router.
list_routesreadList static routes on a MikroTik router with optional filtering by active status and dynamic status. Supports pagination.
list_routing_ruleswriteList policy routing rules on a MikroTik router in evaluation order. Supports filtering by table and disabled state.
list_routing_tablesreadList custom routing tables on a MikroTik router.
list_scheduled_jobswriteList RouterOS scheduler entries on a MikroTik router with next-run time, interval, and disabled state.
list_scriptsreadList RouterOS scripts on a MikroTik router. Supports optional name filter.
list_swos_endpointsreadList the SwOS/SwOS Lite
list_user_groupsreadList local user groups on a MikroTik router.
list_usersreadList local users on a MikroTik router. Passwords are never returned.
list_vrrp_instancesreadList VRRP instances on a MikroTik router.
list_wifi_clientsreadList currently connected WiFi clients (stations) with signal strength and transfer rates.
list_wifi_interfacesreadList WiFi/wireless interfaces on a MikroTik router. Uses /interface/wifi on ROS 7.x, /interface/wireless on older versions.
list_wireguard_interfacesreadList WireGuard interfaces and their status on a MikroTik router.
list_wireguard_peerswriteList WireGuard peers with last handshake time and transfer statistics.
manage_address_list_entrydestructiveAdd or remove a firewall address list entry. Idempotent by list name + address. Supports dry-run mode.
manage_bridgedestructiveCreate or remove a bridge interface on a MikroTik router. Idempotent: create returns already_exists if bridge with same name exists.
manage_bridge_portdestructiveAdd or remove an interface from a bridge on a MikroTik router. Idempotent: add returns already_exists if the port assignment already exists.
manage_certificatedestructiveRemove, trust, or untrust a certificate. Idempotent: trust/untrust return early if already in the target state.
manage_containerdestructiveCreate, start, stop, or remove a RouterOS container. create needs a pre-configured veth interface; start/stop are no-ops when already in the target state; remove throws NOT_FOUND when absent. Supports dry-run.
manage_container_configwriteUpdate global container settings. Idempotent: returns no_change if nothing differs.
manage_container_envdestructiveAdd or remove a container environment variable. Idempotent by name+key. add returns already_exists if the entry exists with the same value; throws CONFLICT if the value differs.
manage_container_mountdestructiveAdd or remove a container volume mount. Idempotent by name: add returns already_exists if the mount exists with matching src/dst; throws CONFLICT if name exists with different paths.
manage_dhcp_clientdestructiveAdd, remove, enable, or disable a DHCP client on an interface. Idempotent by interface name: add returns already_exists if a DHCP client is already configured on the same interface.
manage_dhcp_leasedestructiveConvert a dynamic DHCP lease to static (make-static) or remove a lease. Idempotent by MAC address.
manage_dhcp_serverdestructiveAdd, remove, enable, or disable a DHCP server. Idempotent by name: add returns already_exists if a server with the same name, interface, and address pool already exists.
manage_dns_settingswriteUpdate DNS resolver settings (upstream servers, cache size, cache TTL, allow-remote-requests). Idempotent: returns no_change if nothing differs.
manage_interface_listdestructiveAdd or remove an interface list. Idempotent by name. Removing a list that has members is blocked by RouterOS — the error is surfaced as-is.
manage_interface_list_memberdestructiveAdd or remove an interface from an interface list. Idempotent by list+interface composite key. add returns already_exists if the membership exists. remove returns not_found gracefully.
manage_ip_addressdestructiveAdd, update, or remove an IP address on a MikroTik router interface. Performs idempotency checks for add operations and supports dry-run mode for all actions.
manage_ip_pooldestructiveAdd or remove an IP address pool. Idempotent by name: add returns already_exists if a pool with the same name and ranges already exists.
manage_ip_servicewriteEnable or disable a RouterOS IP service (api, api-ssl, ssh, telnet, www, www-ssl, winbox, ftp). Port number changes are intentionally not supported to prevent accidental lockout.
manage_ipsec_peerdestructiveAdd, remove, enable, or disable an IPSec peer. Idempotent by name: add returns already_exists if a peer with the same name and address already exists.
manage_ipsec_policydestructiveAdd, remove, enable, or disable an IPSec policy. Idempotent by composite key (srcAddress + dstAddress + tunnel).
manage_log_actiondestructiveAdd or remove a RouterOS logging action target. Idempotent by name.
manage_log_ruledestructiveAdd, remove, enable, or disable a RouterOS logging rule. Idempotent by topics+logAction (add → already_exists on match; remove → not_found handled gracefully; enable/disable throw NOT_FOUND when absent). Supports dry-run.
manage_netwatch_entrydestructiveAdd, remove, enable, or disable a Netwatch monitoring entry. Idempotent by host+port: add returns already_exists if an entry with the same host and port already exists.
manage_ntp_clientwriteUpdate NTP client settings on a MikroTik router. Idempotent: returns already_set if no changes are needed.
manage_ovpn_clientdestructiveAdd, update, or remove an OpenVPN client interface. Idempotent by name (already_exists on matching name+connectTo; CONFLICT on differing connectTo; no_change when an update differs in nothing). Password is always written when provided since RouterOS does not return it on GET.
manage_ovpn_serverwriteEnable, disable, or configure the OpenVPN server (a per-router singleton). Throws NOT_FOUND if the OpenVPN package is not installed. The set action requires at least one configuration field.
manage_packagewriteEnable or disable a RouterOS package. Changes take effect only after a router reboot — use the reboot tool to apply. Idempotent: no-op if already in the target state.
manage_ppp_profiledestructiveAdd, update, or remove a PPP profile. Idempotent by name. update returns no_change when requested values match. Built-in profiles (default, default-encryption) cannot be removed — RouterOS blocks this and the error is surfaced.
manage_pppoe_clientdestructiveAdd, update, or remove a PPPoE client interface. Idempotent by name (already_exists on matching name+interface+user; CONFLICT on differing config; no_change when an update differs in nothing). Password is always written when provided since RouterOS does not return it on GET.
manage_queuedestructiveAdd, remove, enable, or disable a simple queue. Idempotent by name: add returns already_exists if a queue with the same name and target already exists.
manage_routedestructiveAdd or remove a static route on a MikroTik router. Performs idempotency checks for add operations and supports dry-run mode for all actions.
manage_routing_ruledestructiveAdd, remove, enable, or disable a policy routing rule. Idempotent by srcAddress+dstAddress+interface+table composite key; a repeated add with an explicit, different ruleAction is a CONFLICT. Supports dry-run mode.
manage_routing_tabledestructiveCreate or remove a custom routing table. Idempotent by table name. Supports dry-run mode.
manage_scheduled_jobdestructiveAdd, update, remove, enable, or disable a RouterOS scheduler entry. onEvent is arbitrary RouterOS script run with the router user
manage_scriptdestructiveAdd, update, or remove a RouterOS script. Idempotent by name. add throws CONFLICT if the name already exists; update throws NOT_FOUND if it does not. Supports dry-run.
manage_upgradewriteTrigger a RouterOS package update check or install.
manage_userdestructiveAdd, remove, enable, disable, or set the password for a local RouterOS user. Idempotent by name: add returns already_exists if a user with the same name and group already exists.
manage_user_groupdestructiveAdd, update, or remove a local RouterOS user group. Idempotent by name: add returns already_exists if a group with the same name and policy already exists.
manage_vlandestructiveAdd, remove, enable, or disable a VLAN interface. Idempotent by name: add returns already_exists when a VLAN with matching name, vlan-id, and parent interface exists. Supports dry-run mode.
manage_vrrp_instancedestructiveAdd, remove, enable, or disable a VRRP instance. Idempotent by name: add returns already_exists if an instance with the same name, interface, and VRID already exists.
manage_wifi_interfacewriteEnable, disable, or update SSID settings on a WiFi interface. At least one of disabled or ssid must be provided.
manage_wireguard_interfacedestructiveAdd, remove, enable, or disable a WireGuard interface. Idempotent by name. RouterOS generates the private key on create — it is never passed in. The public key is returned after creation.
manage_wireguard_peerdestructiveAdd or remove a WireGuard peer. Idempotent by public key: add returns already_exists if a peer with the same public key already exists on the interface.
pingwriteSend ICMP echo requests from the router to a target address. Returns per-packet RTT and summary statistics. 100% packet loss is a valid result, not an error.
plan_changeswritePreview a sequence of write operations: each step runs with dryRun=true against live state, returning affected paths and the predicted action per step. Use apply_plan to execute the same steps for real.
rebootwriteTrigger a controlled router reboot with an optional delay. Supports dry-run. Use this tool instead of run_command for reboots — run_command
rollback_changewriteRestore device state to before a write, identified by its journal ID. RouterOS: reads the before-snapshot, diffs against live state, and applies the reverse. SwOS: re-POSTs the exact pre-write
run_commandwriteExecute an arbitrary RouterOS console command via SSH. Guarded by an allow/deny policy (built-in deny list blocks destructive commands; tighten via cmdAllow in routers.yaml or MIKROMCP_CMD_ALLOW). Prefer dedicated tools (reboot, etc.) where available. Output capped at 4000 characters.
run_scriptwriteExecute a named RouterOS script. Fire-and-forget — the script runs asynchronously and its output is written to the router system log. Use get_log after calling this tool to see results.
set_system_clockwriteSet the system date, time, and/or timezone on a MikroTik router. Idempotent: returns already_set if the values already match. Supports dry-run.
test_readreadtest
torchreadCapture a real-time traffic snapshot on a router interface. RouterOS runs the capture for
traceroutereadTrace the network path from the router to a target address. Returns an ordered hop list with RTT per hop. Timeouts and partial results are valid responses. Not auto-retried.
write_swos_blobwriteMutate a SwOS
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (4 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
config/routers.example.yaml:81
#     rejectUnauthorized: false  # Self-signed cert — fingerprint strongly recommended
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/init.ts:286
console.log(chalk.green(`\n  Generated token: ${chalk.bold(rawToken)}`));
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_file, manage_address_list_entry, manage_bridge, manage_bridge_port, manage_certificate, manage_container, manage_container_env, manage_container_mount, manage_dhcp_client, manage_dhcp_lease, ma
Why it matters. 35 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/adapter/swos-client.ts:40
return createHash("md5").update(input).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
test/unit/adapter/swos-client.test.ts:27
const ha1 = createHash("md5").update(`${user}:${REALM}:${password}`).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
test/unit/adapter/swos-client.test.ts:28
const ha2 = createHash("md5").update(`${method}:${fields.uri}`).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
test/unit/adapter/swos-client.test.ts:30
? createHash("md5")
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
test/unit/adapter/swos-client.test.ts:33
: createHash("md5").update(`${ha1}:${fields.nonce}:${ha2}`).digest("hex");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs-site/scripts/sync-wiki.mjs:6
const WIKI_DIR = resolve(__dirname, "../../docs/wiki");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/domain/errors/error-types.ts:5
import type { MikroMCPErrorData } from "../../types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/domain/snapshot/diff-engine.ts:1
import type { RouterOSRestClient } from "../../adapter/rest-client.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/domain/snapshot/diff-engine.ts:2
import type { RouterOSRecord, RouterOSValue, RestorePlan } from "../../types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/domain/snapshot/diff-engine.ts:3
import { isTrue, normalizeWireValue } from "../../adapter/response-parser.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/superpowers/plans/2026-05-27-v1.5.md:2962
**Example prompt:** "Fetch http://10.0.0.1/status from router core-sw and show me the response body"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/wiki/Available-Tools.md:1981
**Example prompt:** "Fetch http://10.0.0.1/status from router core-sw and show me the response body"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/wiki/Getting-Started.md:135
curl -sk https://10.0.0.1/rest/system/resource \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/wiki/RouterOS-API-Setup.md:197
curl -sk https://10.0.0.1/rest/system/resource \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/unit/adapter/rest-client.test.ts:49
expect(requestMock.mock.calls[0][0]).toBe("http://192.0.2.1:80/rest/interface");
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
test/unit/adapter/adapter-factory.test.ts:22
tls: { enabled: true, rejectUnauthorized: false },
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
test/unit/adapter/connection-pool.test.ts:20
tls: { enabled: true, rejectUnauthorized: false },
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
test/unit/adapter/tls-manager.test.ts:12
const opts = buildAgentOptions({ enabled: true, rejectUnauthorized: false });
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
test/unit/adapter/tls-manager.test.ts:19
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
docs-site/package.json
astro, @astrojs/starlight, sharp
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@inquirer/prompts, @modelcontextprotocol/sdk, basic-ftp, bcryptjs, chalk, commander, dotenv, nanoid
Why it matters. 27 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
site/package.json
@astrojs/sitemap, astro
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 52a3285b5d24full audit observations/trust-audit/mcp-server/alikarami__mikro.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0852a3285b5d24BLOCKD69first audit
06

Questions

What is the Mikro MCP server?

Production-grade MCP server for MikroTik RouterOS with secure AI-native network automation.

What tools does Mikro expose?

122 in total: 62 read-only, 25 that write, and 35 that can delete or overwrite (delete_file, manage_address_list_entry, manage_bridge, manage_bridge_port, manage_certificate). Every one is listed on this page with its risk.

Is Mikro safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 35 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mikro need?

It reads MIKROMCP_CONFIRMATION_SECRET, MIKROMCP_ITEST_PASSWORD, ROUTER_CORE01_PASS, ROUTER_ITEST_PASS and ROUTER_R1_PASS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mikro run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mikromcp-site at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (52a3285b5d24), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement