Atlas / MCP servers / ibm / IBM i Server

IBM i ServerBLOCK

mcp/ibm/ibm-i-server

MCP server for IBM i systems

Verdict
BLOCK
Grade
F
Trust score
39 /100
Exposed tools
7 7r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
85
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.typescriptlang.org/) [](https://github.com/modelcontextprotocol/typescript-sdk) [](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/docs/specification/2025-06-18/changelog.mdx) [](https://opensource.org/licenses/Apache-2.0) [](https://github.com/IBM/ibmi-mcp-server.git) [](https://deepwiki.com/IBM/ibmi-mcp-server)

MCP server and CLI for IBM i

Overview

The IBM i MCP Server enables AI agents to interact with IBM i systems through the Model Context Protocol (MCP). It provides secure, SQL-based access to Db2 for i databases, allowing AI applications like Claude, VSCode Copilot, Bob, and custom agents to query system information, monitor performance, and execute database operations.

This repo also ships the `ibmi` CLI (`@ibm/ibmi-cli`) — a terminal-first sibling that shares the same YAML-driven SQL tool engine, so the same tool definitions work in both the MCP server and the CLI.

How it works: AI clients connect via MCP → Server executes YAML-defined SQL tools → Results stream back to the AI agent through Mapepire.
[!TIP] 📚 [Official Documentation](https://ibm-d95bab6e.mintlify.app/) | ⚠️ Docs are under active development The Docs are continuously evolving. Please check back f
Read from source at commit 4cf8304d9a2cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ibmi-mcp-server --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env IBMI_MCP_ACCESS_TOKEN=${IBMI_MCP_ACCESS_TOKEN} --env MCP_AUTH_TOKEN=${MCP_AUTH_TOKEN} --env MY_TEST_PASS=${MY_TEST_PASS} -- npx -y @ibm/[email protected]
claude-desktop
{
  "mcpServers": {
    "ibmi-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@ibm/[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "IBMI_MCP_ACCESS_TOKEN": "${IBMI_MCP_ACCESS_TOKEN}",
        "MCP_AUTH_TOKEN": "${MCP_AUTH_TOKEN}",
        "MY_TEST_PASS": "${MY_TEST_PASS}"
      }
    }
  }
}
03

Exposed tools (7)

7 read · 0 write · 0 destructive.

ToolRiskDescription
1_test_toolreadA test tool
describe_sql_objectreadGenerate the SQL DDL statement for an IBM i database object. Use this to see the full CREATE definition of a table, view, index, procedure, function, or other object.
get_related_objectsreadGet all objects that depend on a database file — views, indexes, triggers, foreign keys, logical files, and more. Use for impact analysis before schema changes or to understand a table
get_table_columnsreadGet column metadata for a table including names, data types, lengths, nullability, defaults, and descriptions. Use this to understand table structure before writing SQL queries.
list_schemasreadList available schemas/libraries on the IBM i system. Use this as the first step in schema discovery to find which schemas contain relevant tables.
list_tables_in_schemareadList tables, views, and physical files in a specific schema with metadata including row counts. Use after list_schemas to find tables before querying column details.
test_toolreadA test tool
04

Trust audit

BLOCKgrade F · trust 39/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (16 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/cli/src/config/loader.ts:72
const parsed = yaml.load(raw);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/server/scripts/convert-rules-to-yaml.ts:68
const data = yaml.load(raw) as unknown;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/validate-config.ts:325
const config = yaml.load(yamlContent);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
deployment/mcpgateway/docker-compose.yml:279
#     - NODE_TLS_REJECT_UNAUTHORIZED=0  # <- Node.js will accept your self-signed cert
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
get-access-token.js:223
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
get-access-token.js:342
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
app/infra/config_models.py:145
url: str = "postgresql://postgres:mysecretpassword@localhost:5432/agno"
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
get-access-token.js:138
console.log(`   Password: ${credentialSource.password}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
get-access-token.js:184
console.log(`   Password: ${"*".repeat(TEST_CONFIG.password.length)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
get-access-token.js:381
console.log(`export IBMI_MCP_ACCESS_TOKEN="${token}"`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
get-access-token.js:388
console.log(`   Token: ${token.substring(0, 20)}...`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
get-access-token.js:394
console.log(`   Length: ${token.length} bytes`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
agents/frameworks/agno/src/ibmi_agents/agents/ibmi_agents.py:30
DEFAULT_MCP_URL = "http://127.0.0.1:3010/mcp"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
agents/frameworks/google_adk/.env.example:13
# Optional: MCP server URL (default: http://127.0.0.1:3010/mcp)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
agents/frameworks/google_adk/.env.example:14
IBMI_MCP_SERVER_URL=http://127.0.0.1:3010/mcp
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
app/agent-ui/src/components/ui/icon/custom-icons.tsx:701
xlinkHref="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAMgAAADICAIAAAAiOjnJAAAMPWlDQ1BJQ0MgUHJvZmlsZQAASImVVwdYU8kWnltSSWgBBKSE3gSRGkBKCC2A9CLYCEmAUGIMBBU7uqjg2kUEbOiqiGIHxI7YWRR7XyyoKOtiwa68SQFd95X
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
agents/frameworks/agno/README.md:99
ANTHROPIC_API_KEY=sk-ant-your-anthropic-api-key
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/agents/security.mdx:281
api_key="sk-hardcoded-key-bad"  # Never do this
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ncurc.json
.ncurc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.versionrc.json
.versionrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/server/scripts/fetch-openapi-spec.ts:113
return yaml.load(data) as object;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/server/scripts/fetch-openapi-spec.ts:122
const parsedYaml = yaml.load(data) as object;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/agent-ui/src/components/chat/Sidebar/Sessions/SessionItem.tsx:3
import { Button } from '../../../ui/button'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
deployment/mcpgateway/docker-compose.yml:415
- ../../.env     # Load environment variables from root .env file

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 4cf8304d9a2cfull audit observations/trust-audit/mcp-server/ibm__ibm-i-server.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-074cf8304d9a2cBLOCKF39first audit
06

Questions

What is the IBM i Server MCP server?

MCP server for IBM i systems

What tools does IBM i Server expose?

7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is IBM i Server safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (39/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does IBM i Server need?

It reads ANTHROPIC_API_KEY, IBMI_MCP_ACCESS_TOKEN, MCP_AUTH_TOKEN, MY_TEST_PASS, NEXT_PUBLIC_OS_SECURITY_KEY, OPENAI_API_KEY, TEST_PASS and WATSONX_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does IBM i Server run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @ibm/ibmi-mcp-server at 0.6.1.

How current is this page?

The grade is for one exact copy of the source (4cf8304d9a2c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement