Atlas / MCP servers / bjeans / Homelab Manager

Homelab ManagerSAFE

mcp/bjeans/homelab-manager

Model Context Protocol (MCP) servers for managing homelab infrastructure through Claude Desktop. Monitor Docker/Podman containers, Ollama AI models, Pi-hole DNS, Unifi networks, and Ansible inventory. Includes security checks, templates, and automated pre-push validation. Production-ready for homela

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
6 5r · 1w · 0d
Transport
sse · stdio
License
MIT
Stars
43
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/bjeans/homelab-mcp/releases) [](https://github.com/bjeans/homelab-mcp/actions/workflows/security-check.yml) [](https://github.com/bjeans/homelab-mcp/actions/workflows/docker-publish.yml) [](https://hub.docker.com/r/bjeans/homelab-mcp) [](https://hub.docker.com/r/bjeans/homelab-mcp) [](https://github.com/bjeans/homelab-mcp/blob/main/LICENSE)

Model Context Protocol (MCP) servers for managing homelab infrastructure through Claude Desktop.

A collection of Model Context Protocol (MCP) servers for managing and monitoring your homelab infrastructure through Claude Desktop.

🔒 Security Notice

⚠️ IMPORTANT: Please read SECURITY.md before deploying this project.

This project interacts with critical infrastructure (Docker APIs, DNS, network devices). Improper configuration can expose your homelab to security risks.

Key Security Requirements:

  • NEVER expose Docker/Podman APIs to the internet - Use firewall rules to restrict access
  • Keep `.env` file secure - Contains API keys and should never be committed
  • Use unique API keys - Generate separate keys for each service
  • Review network security - Ensure proper VLAN segmentation and firewall rules

See SECURITY.md for comprehensive security

Read from source at commit 7e0e620888caOBSERVED · 2026-10-08
02

Exposed tools (6)

5 read · 1 write · 0 destructive.

ToolRiskDescription
get_claude_configreadGet the Claude Desktop MCP server configuration. Shows all registered MCP servers.
list_mcp_directoryreadList all files and directories in the MCP development directory.
list_mcp_serversreadList all MCP servers registered in Claude Desktop config with their details.
read_mcp_filereadRead the contents of a specific MCP file. Provide either absolute path or relative to MCP directory.
search_mcp_filesreadSearch for files in MCP directory by name. Optionally filter by extensions.
write_mcp_filewriteWrite content to an MCP file. Creates parent directories if needed. Path can be absolute or relative to MCP directory.
03

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
pihole_mcp.py:116
logger.info(f"Loaded from env: {display_name} -> {host}:{port} (api_key: {'***' if api_key else 'NOT SET'})")
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.docker.example
.env.docker.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONTRIBUTING.md:300
minio_endpoint: "http://192.0.2.10:9000"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
DOCKER.md:331
docker exec homelab-mcp-docker curl http://192.168.1.100:2375/containers/json
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:826
- **Centralized Access**: Single endpoint (e.g., `http://192.0.2.10:4000`) for all models
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
helpers/requirements-dev.txt
flake8, pylint, black, isort, mypy, bandit, safety, pip-audit
Why it matters. 14 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, fastmcp, ansible-core, aiohttp, requests, urllib3, PyYAML, orjson
Why it matters. 9 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:192
- ✅ Full access to source code
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:1631
2. Ensure the API key has admin/full access rights
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:89
# Load environment variables
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:93
# Only load .env if NOT in unified mode (to avoid duplicate loading)
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CONTRIBUTING.md:211
# Load environment variables
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CONTRIBUTING.md:539
- `DOCKERHUB_TOKEN` - Docker Hub access token (not password!)
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CONTRIBUTING.md:542
- Use Docker Hub access tokens, never passwords
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
assets/Homelab-mcp-logo-transparent.png
assets/Homelab-mcp-logo-transparent.png
Why it matters. 1054916 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7e0e620888cafull audit observations/trust-audit/mcp-server/bjeans__homelab-manager.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087e0e620888caSAFEB88first audit
05

Questions

What is the Homelab Manager MCP server?

Model Context Protocol (MCP) servers for managing homelab infrastructure through Claude Desktop. Monitor Docker/Podman containers, Ollama AI models, Pi-hole DNS, Unifi networks, and Ansible inventory. Includes security checks, templates, and automated pre-push validation. Production-ready for homela

What tools does Homelab Manager expose?

6 in total: 5 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Homelab Manager safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Homelab Manager need?

It reads NUT_PASSWORD and UNIFI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Homelab Manager run?

It speaks sse and stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (7e0e620888ca), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement