Atlas / MCP servers / cisco-open / Network Sketcher

Network SketcherBLOCK

mcp/cisco-open/network-sketcher

Network Sketcher is an AI-ready network design tool with Local MCP, Online, and Offline editions for creating network designs and exporting PowerPoint diagrams and Excel-based configuration data.

Verdict
BLOCK
Grade
F
Trust score
36 /100
Exposed tools
12 7r · 5w · 0d
Transport
—
License
Apache-2.0
Stars
400
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Network Sketcher is an AI-native network design and diagramming tool. It generates L1/L2/L3 topology diagrams, device tables, and AI-ready context files from structured network data and natural-language workflows.

For MCP users, Network Sketcher Local MCP lets LLM clients such as Cursor and Claude Code design Cisco-style networks directly through Model Context Protocol tool calls. It runs locally over stdio, keeps master files on your machine, and produces SVG / PowerPoint diagrams plus HTML device tables.

If Network Sketcher helps your workflow, please consider starring the repository.

Common use cases:

  • Build a 5-site WAN or campus LAN design from an AI conversation
  • Generate L1 physical, L2 VLAN/broadcast-domain, and L3 IP topology diagrams
  • Export a combined L1/L2/L3 HTML viewer and an interactive device table
  • Create an AI Context file so another LLM can review or extend the network design
  • Import from live inventory: Use Network Sketcher Cisco Extension converters to turn ACI, Catalyst Center, Catalyst SD-WAN, Meraki, Nexus Dashboard, CML, Cyber Vision, SNA, NetBox exports, or config files (IOS / IOS-XE / NX-OS / IOS-XR / ASA) into CLI commands for any Network Sketcher edition

Quick Start: Local MCP in 3 Steps

The quickes

Read from source at commit c97b6fd4d07fOBSERVED · 2026-10-02
02

Exposed tools (12)

7 read · 5 write · 0 destructive.

ToolRiskDescription
build_default_outputsreadGenerate the default deliverable bundle for a .nsm master.
create_empty_masterwriteCreate a new empty Network Sketcher master file (.nsm) in the working dir.
export_device_table_htmlreadExport an interactive HTML Device Table preview from a .nsm master.
export_diagramreadExport an L1, L2, or L3 network diagram for the given .nsm master.
export_master_xlsxreadConvert a .nsm master back to .xlsx for Excel/Offline edition use.
get_ai_contextreadGenerate the full AI Context file for a master and return its contents.
get_network_statewriteRun the standard set of `show` commands and return aggregated results.
get_workspace_inforeadReturn the active workspace and the list of .nsm master files in it.
import_masterwriteConvert an existing .xlsx master into a .nsm in the working directory.
run_commandswriteExecute one or more Network Sketcher CLI commands against a .nsm master.
set_workspacewriteSet the active workspace directory for this session.
suggest_workspacereadSuggest OS-appropriate workspace directory candidates.
03

Trust audit

BLOCKgrade F · trust 36/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
none-observed
Shell
declared (10 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (15)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
network-sketcher_offline/network_sketcher.py:186
exec(self.entry_name_main1_1 + '.delete(0, tkinter.END)')
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
network-sketcher_offline/network_sketcher.py:187
exec(self.entry_name_main1_1 + '.insert(tk.END, event.data)')
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
network-sketcher_offline/network_sketcher.py:204
exec(self.entry_name_main1_1 + '.delete(0, tkinter.END)')
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
network-sketcher_offline/network_sketcher.py:205
exec(self.entry_name_main1_1 + '.insert(tk.END, self.full_filepath)')
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
network-sketcher_offline/network_sketcher.py:279
exec(self.entry_name_external_systems1_1 + '.delete(0, tkinter.END)')
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHObfuscation / stealth · obf.rtl_override · CWE-506, CWE-94
network-sketcher_offline/ns_ddx_figure.py:133
self.root_folder = [0.28, 1.42, 9.45, 5.75]  # Defalut setting.  left , top , width , hight(Inches)  / EMU is 914400
HIGHObfuscation / stealth · obf.rtl_override · CWE-506, CWE-94
network-sketcher_offline/ns_ddx_figure.py:205
self.sub_folder = [self.root_folder[0],self.root_folder[1],self.root_folder[2],self.root_folder[3]]  # left , top , width , hight(Inches)  / EMU is 914400
HIGHObfuscation / stealth · obf.rtl_override · CWE-506, CWE-94
network-sketcher_online/ns_engine/nsm_ddx_figure.py:134
self.root_folder = [0.28, 1.42, 9.45, 5.75]  # Defalut setting.  left , top , width , hight(Inches)  / EMU is 914400
HIGHObfuscation / stealth · obf.rtl_override · CWE-506, CWE-94
network-sketcher_online/ns_engine/nsm_ddx_figure.py:206
self.sub_folder = [self.root_folder[0],self.root_folder[1],self.root_folder[2],self.root_folder[3]]  # left , top , width , hight(Inches)  / EMU is 914400
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
network-sketcher_offline/Sample_data/No_data_Master_file_with_AI_Context/[AI_Context]no_data.txt:1098
**[IMPORTANT] Default Attribute Rules for Device Type**<br>
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
network-sketcher_offline/ns_extensions_cmd_list.txt:1057
**[IMPORTANT] Default Attribute Rules for Device Type**<br>
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
network-sketcher_online/ns_engine/nsm_extensions_cmd_list.txt:1074
**[IMPORTANT] Default Attribute Rules for Device Type**
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:161
The AI agent Cursor autonomously creates a network using Network Sketcher's Local MCP functionality. It also simultaneously references best practices from other MCPs.
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:366
**Network Sketcher generates network configuration diagrams in PowerPoint and manages configuration information in Excel. Additionally, exporting a AI context can be used to generate config files usin
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.binary · CWE-1104
network-sketcher_offline/Sample_data/No_data_Master_file_with_AI_Context/[MASTER]no_data.xlsx
[MASTER]no_data.xlsx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha c97b6fd4d07ffull audit observations/trust-audit/mcp-server/cisco-open__network-sketcher.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-02c97b6fd4d07fBLOCKF36first audit
05

Questions

What is the Network Sketcher MCP server?

Network Sketcher is an AI-ready network design tool with Local MCP, Online, and Offline editions for creating network designs and exporting PowerPoint diagrams and Excel-based configuration data.

What tools does Network Sketcher expose?

12 in total: 7 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Network Sketcher safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (36/100) and found 14 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Network Sketcher need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (c97b6fd4d07f), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement