Atlas / MCP servers / ilialarchenko / SO-ARM100 Robot Control

SO-ARM100 Robot ControlCAUTION

mcp/ilialarchenko/so-arm100-robot-control

A simple MCP server for the SO-ARM100 control

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
2 2r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
85
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://youtu.be/EmpQQd7jRqs)

A companion repository to my video about MCP server for the robot:

  • MCP Server for LLM-based AI agents (Claude Desktop, Cursor, Windsurf, etc.) to control the robot
  • Direct keyboard control for manual operation
  • CLI AI Agent can use it directly to control the robot with Claude, Gemini or GPT model

If you want to know more about MCP refer to the official MCP documentation

This repository suppose to work with the SO-ARM100 / 101 robots. Refer to lerobot SO-101 setup guide for the detailed instructions on how to setup the robot.

Update! Now it partially supports LeKiwi (only arm, the mobile base control through MCP is TBD). I also added a simple agent that uses MCP server to control the robot. It supports Claude, Gemini and GPT models. In my experience Claude is the best and GPT is not so good, Gemini is in between.

After I released the video and this repository, LeRobot released a significant update of the library that breaks the compatibility with the original code.

If you want to use the original code and exactly follow the video, please use this release.

Quick Start

1. Install Dependencies

For simplicity I use simple pip instead of uv that is often recommended in MCP tutorials - it works just fine.

python -m venv .venv
source .venv/bin/activate  # or .venv\Scripts\activate on Windows
pip install -r requirements.txt

It may be required to install lerobot separately, just use the official instructions from the lerobot repository

2. Connect Your Robot

  • Connect SO-ARM100 via USB
  • Update config.py with your serial port for so-arm (e.g., `
Read from source at commit d0bc8721f299OBSERVED · 2026-10-07
02

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
get_initial_instructionsreadreturn robot_config.robot_description
get_robot_statereadrobot = get_robot()
03

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
run_tests.py:67
__import__(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
run_tests.py:144
__import__(package)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:108
"url": "http://127.0.0.1:3001/sse"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:128
"url": "http://127.0.0.1:3001/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_agent.py:51
self.assertEqual(agent.mcp_url, "http://127.0.0.1:3001/sse")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_agent.py:77
self.assertEqual(agent.mcp_url, "http://127.0.0.1:3002/sse")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
agent_utils.py:92
img_bytes = base64.b64decode(image_data)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
anthropic, google-genai, openai, mcp, pylint, numpy, pynput, git+https://github.com/huggingface/lerobot.git
Why it matters. 12 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:68
WARNING: using MCP server itself is free, but it requires MCP client that will send requests to some LLM. Generally it is not free - and controlling the robot with MCP can become expensive, as it send
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d0bc8721f299full audit observations/trust-audit/mcp-server/ilialarchenko__so-arm100-robot-control.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d0bc8721f299CAUTIONB85first audit
05

Questions

What is the SO-ARM100 Robot Control MCP server?

A simple MCP server for the SO-ARM100 control

What tools does SO-ARM100 Robot Control expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SO-ARM100 Robot Control safe to connect to an agent?

With care. The audit graded it B (85/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does SO-ARM100 Robot Control need?

It reads ANTHROPIC_API_KEY, GEMINI_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (d0bc8721f299), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement