Atlas / MCP servers / ibm / AssetOpsBench

AssetOpsBenchBLOCK

mcp/ibm/assetopsbench

AssetOpsBench - Industry 4.0: A unified benchmark and framework for building, orchestrating, and evaluating domain-specific AI agents for Industry 4.0 asset operations and maintenance, with 460+ scenarios, 5 specialist agents (IoT, FMSR, TSFM, Work Order,...), and multi-agent orchestration blueprint

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
69 58r · 11w · 0d
Transport
stdio
License
Apache-2.0
Stars
2,312
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI Agents for Industrial Asset Operations & Maintenance

A unified, open framework for building, orchestrating, and evaluating domain-specific AI agents in Industry 4.0.

[](https://github.com/IBM/AssetOpsBench/stargazers) [](https://github.com/IBM/AssetOpsBench/network/members) [](LICENSE) [](#publications) [](#ai-competitions) [](#ai-competitions)

[](#) [](#) [](#publications) [](#publications) [](#publications) [](#publications) [](#publications) [](#publications)

📄 **Paper** · 🤗 **Dataset** · 🎮 **Playground** · 📢 **IBM Blog** · 🎥 [Video](https://www.youtube.com/watch?v=kXmB

Read from source at commit 76c35330ddcbOBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add assetopsbench-mcp --env COUCHDB_PASSWORD=${COUCHDB_PASSWORD} --env LITELLM_API_KEY=${LITELLM_API_KEY} --env WATSONX_APIKEY=${WATSONX_APIKEY} -- uvx assetopsbench-mcp
claude-desktop
{
  "mcpServers": {
    "assetopsbench-mcp": {
      "command": "uvx",
      "args": [
        "assetopsbench-mcp"
      ],
      "env": {
        "COUCHDB_PASSWORD": "${COUCHDB_PASSWORD}",
        "LITELLM_API_KEY": "${LITELLM_API_KEY}",
        "WATSONX_APIKEY": "${WATSONX_APIKEY}"
      }
    }
  }
}
03

Exposed tools (69)

58 read · 11 write · 0 destructive.

ToolRiskDescription
add_failure_modeswriteWRITE failure modes for an asset class to the database.
assess_vibration_severityreadClassify vibration severity per ISO 10816.
asset_detailreadReturn registry details for one asset.
asset_idsreadList asset identifiers registered at one site.
assetsreadList assets at one site with compact registry metadata.
calculate_bearing_frequenciesreadCompute bearing characteristic frequencies (BPFO, BPFI, BSF, FTF) from geometry.
compute_envelope_spectrumreadCompute the envelope spectrum for bearing fault detection.
compute_fft_spectrumreadCompute FFT amplitude spectrum of a stored vibration signal.
count_featuresreadCount the feature catalog cards by kind.
count_modelsreadCount the models in the catalog.
current_date_timereadProvides the current date time as a JSON object.
current_time_englishreadReturns the current time in English text.
data_qualityreadAssess data quality for a time-series dataset and produce a cleaned file pointer.
deprecate_featurereadMark a feature catalog card as deprecated.
deprecate_modelreadRetire a model card by setting `status=deprecated`.
describe_candidateswriteReturn a shortlist of candidate models for a task, in catalog order.
describe_featuresreadDescribe specific feature cards by name.
describe_modelsreadReturn a compact record for each of the given model ids.
diagnose_vibrationreadFull automated vibration diagnosis pipeline.
extract_featuresreadCompute scalar feature values from a series with the named extractors.
find_assets_by_sensorsreadFind site assets by installed or measured sensor names.
find_modelsreadFilter the model catalog for a task and return a ranked shortlist.
generate_failure_modesreadGENERATE a new or extended failure-mode list for an asset class.
get_asset_catalogreadReturn cataloged asset classes and categories.
get_failure_mode_catalogreadReturn cataloged failure modes by asset category.
get_failure_modesreadREAD the known failure modes for an asset class.
get_featurereadReturn one feature catalog card by feature id.
get_feature_lineagereadReturn the parent and descendant chain for a feature catalog card.
get_model_lineagereadReturn a model card
get_resultreadFetch one persisted result by task type and result id.
get_runwriteFetch one run record by id.
get_sensor_catalogreadReturn cataloged sensor types.
get_vibration_datareadFetch vibration sensor time-series from CouchDB and load into the analysis store.
hf_statsreadLook up HuggingFace popularity for a model card or repo.
historyreadReturn one chronological page of telemetry observations for an asset.
installed_sensorsreadList sensor names assigned to an asset in the registry.
json_readerreadReads a JSON file, parses its content, and returns the parsed data.
latest_readingreadReturn the newest telemetry observation for an asset.
list_domainsreadList the distinct domains present in the model catalog, with counts.
list_featuresreadList feature catalog cards from the configured database.
list_known_bearingsreadList all bearings in the built-in database with their geometric parameters.
list_modelsreadList model cards in the catalog, optionally filtered by task / domain.
list_resultsreadList persisted results for a task type, optionally narrowed by asset or scenario.
list_runswriteList run records and plans, optionally filtered by asset.
list_tasksreadList the standardized TSFM tasks available in the benchmark.
list_vibration_sensorsreadList available sensor fields for an asset.
measured_sensorsreadList measurement fields observed in an asset
model_templatereadReturn the template for authoring a new model card.
new_feature_versionwriteCreate a successor version for a transform feature.
new_model_versionwriteCreate a successor version of a model card.
profile_seriesreadProfile a time-series dataset behind a file pointer.
recipe_templatereadReturn the template for authoring a recipe for run_recipe / run_tabular_recipe.
register_featurereadRegister an executable transform feature card.
register_finetunedreadRegister a fine-tuned model as a card pointing at its checkpoint.
register_modelreadRegister a model card in the catalog.
resolve_modelreadPreflight a model card: check that it can actually be loaded.
run_planwriteExecute a plan: a DAG of recipes chained by file pointers.
run_recipewriteRun a forecasting or anomaly-detection recipe on a target series from a file pointer.
run_tabular_recipewriteRun a series-to-tabular recipe: regression, classification, or clustering.
search_featuresreadSearch feature catalog cards by id, name, description, or tags.
search_modelsreadSubstring (case-insensitive) search over the model catalog.
select_featuresreadRank candidate extractors on one series and return the shortlist worth keeping.
sensor_coveragereadSummarize non-null observation coverage for every measured sensor.
sensor_statsreadCompute numeric statistics for one or all measured sensors.
sitesreadList sorted site identifiers available in the asset registry.
stream_extentreadInspect the size and timestamp span of an asset
update_featurewritePatch fields on an existing feature catalog card.
update_modelwritePatch fields on an existing model card.
wo__list_workordersreadTest MCP tool
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (8 observation(s))
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (17)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/servers/tsfm/engine/feature_runner.py:27
exec(code, ns)  # noqa: S102 - intentional; sandbox in production
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/servers/tsfm/reasoning/param_space.py:25
Est = getattr(importlib.import_module(module), cls)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/servers/tsfm/substrate/resolver.py:32
return getattr(importlib.import_module(module), name)
LOWInventory / provenance · inv.hidden_file · CWE-1104
.all-contributorsrc
.all-contributorsrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.public
.env.public
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaksignore
.gitleaksignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/servers/vibration/data_store.py:121
h = hashlib.md5(signal.tobytes()[:1024]).hexdigest()[:8]
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
INSTRUCTIONS.md:153
| `fmsr`      | 4     | read, write, LLM-use     | CouchDB + LLM credentials for generation |
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/running_benchmark.md:53
`run.sh` does not read `.env`; these three must be exported or passed. `.env`
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTRUCTIONS.md:27
curl -LsSf https://astral.sh/uv/install.sh | sh   # macOS / Linux
INFOInventory / provenance · inv.oversize · CWE-1104
docs/tutorial/AssetOpsBench_Neurips_Slide-2.pdf
docs/tutorial/AssetOpsBench_Neurips_Slide-2.pdf
Why it matters. 2272159 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/tutorial/AssetOpsBench_Technical_Material.pdf
docs/tutorial/AssetOpsBench_Technical_Material.pdf
Why it matters. 2067010 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/tutorial/Neurips_Social_Slide.pdf
docs/tutorial/Neurips_Social_Slide.pdf
Why it matters. 2683414 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
src/couchdb/scenarios_data/shared/iot/chiller_6.json
src/couchdb/scenarios_data/shared/iot/chiller_6.json
Why it matters. 1776999 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
src/couchdb/scenarios_data/shared/iot/hydraulic_pump_1.json
src/couchdb/scenarios_data/shared/iot/hydraulic_pump_1.json
Why it matters. 1880617 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 76c35330ddcbfull audit observations/trust-audit/mcp-server/ibm__assetopsbench.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2876c35330ddcbBLOCKD69first audit
06

Questions

What is the AssetOpsBench MCP server?

AssetOpsBench - Industry 4.0: A unified benchmark and framework for building, orchestrating, and evaluating domain-specific AI agents for Industry 4.0 asset operations and maintenance, with 460+ scenarios, 5 specialist agents (IoT, FMSR, TSFM, Work Order,...), and multi-agent orchestration blueprint

What tools does AssetOpsBench expose?

69 in total: 58 read-only, 11 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is AssetOpsBench safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does AssetOpsBench need?

It reads COUCHDB_PASSWORD, LITELLM_API_KEY and WATSONX_APIKEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does AssetOpsBench run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as assetopsbench-mcp.

How current is this page?

The grade is for one exact copy of the source (76c35330ddcb), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement