Atlas / MCP servers / enuno / UniFi

UniFiBLOCK

mcp/enuno/unifi-1

An MCP server that leverages official UniFi API

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
280
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/enuno/unifi-mcp-server/actions/workflows/ci.yml) [](https://github.com/enuno/unifi-mcp-server/actions/workflows/security.yml) [](https://codecov.io/github/enuno/unifi-mcp-server) [](https://pypi.org/project/unifi-mcp-server/) [](https://www.python.org/downloads/) [](LICENSE) [](https://deepwiki.com/enuno/unifi-mcp-server)

A Model Context Protocol (MCP) server that exposes the UniFi Network Controller API today and is evolving into a production-grade multi-domain platform for Protect, Access, and enterprise-scale orchestration.

See SPEC.md for the architecture target and DEVELOPMENT_PLAN.md for the phase roadmap.

Operator quick start

Objective

Give operators a fast, safe reading order for understanding what the server does today, what it is becoming, and which docs govern rollout decisions.

Prerequisites

  • You know which UniFi API mode the deployment uses: local, cloud-ea, or cloud-v1.
  • You know whether the runtime is stdio, HTTP, SSE, or streamable HTTP.
  • You have read the phase target in SPEC.md and the current work item in DEVELOPMENT_PLAN.md.

Procedure

  1. Confirm the current stable release and current phase focus.
  2. Read SPEC.md for architecture intent and DEVELOPMENT_PLAN.md for sequencing.
  3. Use API.md and docs/UNIFI_API.md for implementation surface details.
Read from source at commit d542d730ae99OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add unifi-mcp-server --env UNIFI_PASSWORD=${UNIFI_PASSWORD} -- npx -y [email protected]
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
debug_api_requestreadDebug tool to query arbitrary UniFi API endpoints.
health_checkreadHealth check endpoint to verify server is running.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.agents/skills/fastmcp/SKILL.md:676
- Use `--env-file` to load from `.env` file
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.claude/skills/fastmcp/SKILL.md:676
- Use `--env-file` to load from `.env` file
Why it matters. asks the agent to read credentials
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/commands/unifi-mcp-inspect.md:118
✓ UniFi Host: https://192.168.2.1
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
AGENTS.md:293
api_key="abc123def456ghi789...",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.aiignore
.aiignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.docker.example
.env.docker.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.json
.markdownlint.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/unit/test_tool_registry.py:126
modules.append(importlib.import_module(f"src.tools.{info.name}"))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/scraper/auth/debug-login-page.js:41
const screenshotPath = path.join(__dirname, '../../screenshots/login-page.png');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/scraper/auth/debug-login-page.js:101
const htmlPath = path.join(__dirname, '../../screenshots/login-page.html');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/scraper/auth/unifi-login.js:13
const COOKIES_FILE = path.join(__dirname, '../../session-cookies.json');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/scraper/utils/screenshot-debugger.js:12
const SCREENSHOT_DIR = path.join(__dirname, '../../screenshots');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/update/update-docs.js:413
const docsDir = path.join(__dirname, '../../docs');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/agents/unifi-documentation.md:229
- `UNIFI_HOST`: "<https://192.168.2.1>"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/api/test_client.py:46
settings.base_url = "https://192.168.2.1"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/api/test_client.py:493
== "https://192.168.2.1/proxy/network/v2/api/site/default/firewall/zone"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/api/test_protect_client.py:36
settings.base_url = "https://192.168.2.1:443"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.agents/skills/mcp-builder/scripts/requirements.txt
anthropic, mcp
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.claude/skills/mcp-builder/scripts/requirements.txt
anthropic, mcp
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
posthog-node
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
scripts/package.json
puppeteer, dotenv, prompts, chalk, ora
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:35
- **Network transports now require authentication (breaking)**: the `http`, `sse`, and `streamable_http` transports expose every registered tool — including destructive ones — over a TCP listener, but
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:65
- **Every rejected sessionless request to `/mcp` leaked ~44 KiB, permanently (issue #173)**: the `mcp` SDK's `StreamableHTTPSessionManager` creates and registers a new session (transport plus server t
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha d542d730ae99full audit observations/trust-audit/mcp-server/enuno__unifi-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06d542d730ae99BLOCKD69first audit
06

Questions

What is the UniFi MCP server?

An MCP server that leverages official UniFi API

What tools does UniFi expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is UniFi safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does UniFi need?

It reads ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, AUTH_2FA_TIMEOUT, AUTH_PASSKEY_TIMEOUT, AUTH_PASSWORD_TIMEOUT, UNIFI_API_KEY, UNIFI_CLOUD_API_KEY, UNIFI_CLOUD_EA_API_KEY, UNIFI_CLOUD_V1_API_KEY, UNIFI_HOME_API_KEY, UNIFI_LAB_API_KEY and UNIFI_LOCAL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does UniFi run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as unifi-api-scraper at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (d542d730ae99), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement