SO-ARM100 Robot ControlCAUTION
A simple MCP server for the SO-ARM100 control
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://youtu.be/EmpQQd7jRqs)
A companion repository to my video about MCP server for the robot:
- MCP Server for LLM-based AI agents (Claude Desktop, Cursor, Windsurf, etc.) to control the robot
- Direct keyboard control for manual operation
- CLI AI Agent can use it directly to control the robot with Claude, Gemini or GPT model
If you want to know more about MCP refer to the official MCP documentation
This repository suppose to work with the SO-ARM100 / 101 robots. Refer to lerobot SO-101 setup guide for the detailed instructions on how to setup the robot.
Update! Now it partially supports LeKiwi (only arm, the mobile base control through MCP is TBD). I also added a simple agent that uses MCP server to control the robot. It supports Claude, Gemini and GPT models. In my experience Claude is the best and GPT is not so good, Gemini is in between.
After I released the video and this repository, LeRobot released a significant update of the library that breaks the compatibility with the original code.
If you want to use the original code and exactly follow the video, please use this release.
Quick Start
1. Install Dependencies
For simplicity I use simple pip instead of uv that is often recommended in MCP tutorials - it works just fine.
python -m venv .venv source .venv/bin/activate # or .venv\Scripts\activate on Windows pip install -r requirements.txt
It may be required to install lerobot separately, just use the official instructions from the lerobot repository
2. Connect Your Robot
- Connect SO-ARM100 via USB
- Update
config.pywith your serial port for so-arm (e.g., `
d0bc8721f299OBSERVED · 2026-10-07Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_initial_instructions | read | return robot_config.robot_description |
get_robot_state | read | robot = get_robot() |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
__import__(module_name)
__import__(package)
"url": "http://127.0.0.1:3001/sse"
"url": "http://127.0.0.1:3001/mcp"
self.assertEqual(agent.mcp_url, "http://127.0.0.1:3001/sse")
self.assertEqual(agent.mcp_url, "http://127.0.0.1:3002/sse")
img_bytes = base64.b64decode(image_data)
anthropic, google-genai, openai, mcp, pylint, numpy, pynput, git+https://github.com/huggingface/lerobot.git
WARNING: using MCP server itself is free, but it requires MCP client that will send requests to some LLM. Generally it is not free - and controlling the robot with MCP can become expensive, as it send
Gates applied: no_behavioural_pass.
d0bc8721f299full audit observations/trust-audit/mcp-server/ilialarchenko__so-arm100-robot-control.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d0bc8721f299 | CAUTION | B | 85 | first audit |
Questions
What is the SO-ARM100 Robot Control MCP server?
A simple MCP server for the SO-ARM100 control
What tools does SO-ARM100 Robot Control expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SO-ARM100 Robot Control safe to connect to an agent?
With care. The audit graded it B (85/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does SO-ARM100 Robot Control need?
It reads ANTHROPIC_API_KEY, GEMINI_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (d0bc8721f299), read on 2026-10-07. The repository is watched and re-audited when it changes.