Atlas / MCP servers / bsahane / Ansible Server

Ansible ServerSAFE

mcp/bsahane/ansible-server

MCP Ansible Server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
38 27r · 11w · 0d
Transport
stdio
License
—
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP Ansible Server

Advanced Ansible Model Context Protocol (MCP) server in Python exposing Ansible utilities for inventories, playbooks, roles, and project workflows.

Quick start

git clone https://github.com/bsahane/mcp-ansible.git
cd mcp-ansible

# Create and activate Python virtual environment
python3 -m venv .venv
source .venv/bin/activate

# Install dependencies via requirements.txt
python -m pip install -U pip
pip install -r requirements.txt

# (Optional) install the project package locally
pip install -e .

# Run the MCP server
python src/ansible_mcp/server.py

Requirements

  • Python 3.10+
  • macOS/Linux

Setup

cd /Users/bsahane/Developer/cursor/mcp-ansible
python3 -m venv .venv
source .venv/bin/activate
python -m pip install -U pip
pip install "mcp[cli]>=1.2.0" "PyYAML>=6.0.1" "ansible-core>=2.16.0"
pip install -e .

Run the server

python src/ansible_mcp/server.py

Cursor config (/Users/bsahane/.cursor/mcp.json)

{
"mcpServers": {
"ansible-mcp": {
"command": "python",
"args": [
"/Users/bsahane/Developer/cursor/mcp-ansible/src/ansible_mcp/server.py"
],
"env": {
"MCP_ANSIBLE_PROJECT_ROOT": "/Users/bsahane/GitLab/projectAIOPS/mcp-ansible-server",
"MCP_ANSIBLE_INVENTORY": "/Users/bsahane/GitLab/projectAIOPS/mcp-ansible-server/inventory/hosts.ini",
"MCP_ANSIBLE_PROJECT_NAME": "projectAIOPS"
}
}
}
}

Claude for Desktop config

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
"mcpServers": {
"ansible-mcp": {
"command": "python",
"args": [
"/Users/bsahane/Developer/cursor/mcp-ansible/src/ansible_mcp/server.py"
],
"env": {
"MCP_ANSIBLE_PROJECT_ROOT": "/Users/bsahane/GitLab/projectAIOPS/mcp-ansible-server",
"MCP_ANSIBLE_INVENTORY": "/Users/bsahane/GitLab/projectAIOPS/mcp-ansible-server/inventory/hosts.ini",
"MCP_ANSIBLE_PROJECT_NAME": "projectAIOP
Read from source at commit da5b4660b654OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-ansible --env MCP_VAULT_PASSWORD=${MCP_VAULT_PASSWORD} --env VAULT_PASSWORD_FILE=${VAULT_PASSWORD_FILE} -- uvx mcp-ansible
claude-desktop
{
  "mcpServers": {
    "mcp-ansible": {
      "command": "uvx",
      "args": [
        "mcp-ansible"
      ],
      "env": {
        "MCP_VAULT_PASSWORD": "${MCP_VAULT_PASSWORD}",
        "VAULT_PASSWORD_FILE": "${VAULT_PASSWORD_FILE}"
      }
    }
  }
}
03

Exposed tools (38)

27 read · 11 write · 0 destructive.

ToolRiskDescription
ansible-auto-healreadIntelligent automated problem resolution with safety checks.
ansible-capture-baselinereadCapture comprehensive system state baseline for later comparison.
ansible-compare-statesreadCompare current system state against a previously captured baseline.
ansible-diagnose-hostreadComprehensive health assessment of target hosts.
ansible-fetch-logsreadFetch and analyze log files from remote hosts.
ansible-gather-factsreadGather facts using the setup module and return parsed per-host facts.
ansible-health-monitorreadContinuous health monitoring with trend analysis.
ansible-log-hunterreadAdvanced log hunting and correlation across multiple sources.
ansible-network-matrixreadComprehensive network connectivity matrix between hosts.
ansible-performance-baselinereadEstablish performance baselines and detect regressions.
ansible-pingreadPing hosts using the Ansible ad-hoc ping module.
ansible-playbookwriteRun an Ansible playbook.
ansible-remote-commandwriteExecute arbitrary shell commands on remote hosts with enhanced output parsing.
ansible-rolewriteExecute an Ansible role by generating a temporary playbook.
ansible-security-auditreadComprehensive security audit and vulnerability assessment.
ansible-service-managerreadManage services with status checking and log correlation.
ansible-taskwriteRun an ad-hoc Ansible task using the ansible CLI.
ansible-test-idempotencewriteRun a playbook twice and ensure no changes on the second run. Returns recap and pass/fail.
ansible_inventoryreadList Ansible inventory hosts and groups using the ansible-inventory CLI.
create-playbookwriteCreate an Ansible playbook from YAML string or object.
create-role-structurewriteGenerate the standard Ansible role directory structure.
galaxy-installwriteInstall roles and collections from requirements files under the project root.
galaxy-lockwriteCreate a simple lock file for installed roles/collections under the project root.
inventory-diffreadDiff two inventories: hosts, groups, and optionally hostvars keys.
inventory-find-hostreadFind a host, its groups, and merged variables across the resolved inventories.
inventory-graphreadReturn ansible-inventory --graph output using discovered config.
inventory-parsereadParse inventory via ansible-inventory, merging group_vars/host_vars.
list-projectsreadList all registered Ansible projects and the default selection.
project-bootstrapwriteBootstrap a project: install galaxy deps and report Ansible environment details.
project-playbooksreadDiscover playbooks (YAML lists) under the project root.
project-run-playbookwriteRun a playbook within a registered project, applying its inventory and environment.
register-projectreadRegister an existing Ansible project with this MCP server.
validate-playbookreadValidate playbook syntax using ansible-playbook --syntax-check.
validate-yamlreadValidate YAML files; return parse errors with line/column if any.
vault-decryptreadfiles = [file_paths] if isinstance(file_paths, str) else list(file_paths)
vault-encryptreadfiles = [file_paths] if isinstance(file_paths, str) else list(file_paths)
vault-rekeyreadfiles = [file_paths] if isinstance(file_paths, str) else list(file_paths)
vault-viewreadreturn _run_vault_cmd([
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/ansible_mcp/server.py:1094
random_suffix = hashlib.md5(str(time.time()).encode()).hexdigest()[:8]

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha da5b4660b654full audit observations/trust-audit/mcp-server/bsahane__ansible-server.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08da5b4660b654SAFEB89first audit
06

Questions

What is the Ansible Server MCP server?

MCP Ansible Server

What tools does Ansible Server expose?

38 in total: 27 read-only, 11 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Ansible Server safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Ansible Server need?

It reads MCP_VAULT_PASSWORD and VAULT_PASSWORD_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Ansible Server run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-ansible.

How current is this page?

The grade is for one exact copy of the source (da5b4660b654), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement