Atlas / MCP servers / jameshgordy / Snipe-IT

Snipe-ITCAUTION

mcp/jameshgordy/snipe-it-1

MCP server for Snipe-IT asset management. Enables AI assistants to manage assets, consumables, accessories, licenses, users, and system configuration via 39 comprehensive tools.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
8 8r · 0w · 0d
Transport
streamable-http
License
—
Stars
32
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A comprehensive Model Context Protocol (MCP) server for managing Snipe-IT inventory systems. This server enables AI assistants to perform full CRUD operations across your entire Snipe-IT instance with 40 tools covering all major API endpoints.

Features

Asset Management

  • Full CRUD Operations: Create, read, update, delete, and search assets with enhanced filtering
  • Barcode/Serial Lookup: Direct bytag/byserial API endpoints for reliable barcode scanning
  • Asset Operations: Checkout, checkin, audit, and restore assets
  • Checkout Requests: Submit and cancel checkout requests for requestable assets
  • File Attachments: Upload, download, list, and delete asset files
  • Label Generation: Generate printable PDF labels
  • Maintenance Tracking: Create and manage maintenance records
  • License Associations: View licenses assigned to assets

Inventory Tracking

  • Consumables: Complete management of consumable items
  • Components: Manage components with checkout/checkin to assets
  • Accessories: Track accessories with checkout/checkin to users, assets, or locations

Users & Organization

  • Users: Full user management including restore and current user endpoint
  • User Assets: View all items checked out to a user (assets, accessories, licenses, consumables, EULAs)
  • Two-Factor Auth: Reset user 2FA (admin function)
  • Companies: Multi-tenant company management
  • Departments: Organizational department management
  • Groups: Permission group management

System Configuration

  • Categories: Manage categories for all item types
  • Manufacturers: Track manufacturer information
  • Models: Define asset models with depreciation, custom fields, and file attachments
  • Status Labels: Configure asset statuses with asset listing
  • Locations: Manage physical locations with hierarchy, asset/user queries
  • **Supplie
Read from source at commit 64cdcce0204dOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add snipeit-mcp --env SNIPEIT_OAUTH_CLIENT_ID=${SNIPEIT_OAUTH_CLIENT_ID} --env SNIPEIT_OAUTH_CLIENT_SECRET=${SNIPEIT_OAUTH_CLIENT_SECRET} --env SNIPEIT_TOKEN=${SNIPEIT_TOKEN} -- uvx snipeit-mcp
claude-desktop
{
  "mcpServers": {
    "snipeit-mcp": {
      "command": "uvx",
      "args": [
        "snipeit-mcp"
      ],
      "env": {
        "SNIPEIT_OAUTH_CLIENT_ID": "${SNIPEIT_OAUTH_CLIENT_ID}",
        "SNIPEIT_OAUTH_CLIENT_SECRET": "${SNIPEIT_OAUTH_CLIENT_SECRET}",
        "SNIPEIT_TOKEN": "${SNIPEIT_TOKEN}"
      }
    }
  }
}
03

Exposed tools (8)

8 read · 0 write · 0 destructive.

ToolRiskDescription
asset_labelsreadGenerate printable labels for assets.
asset_licensesreadGet all licenses checked out to an asset.
audit_trackingreadTrack asset audit status for compliance.
ldap_operationsreadManage LDAP synchronization.
status_summaryreadGet asset counts grouped by status label.
system_inforeadGet Snipe-IT system information.
user_assetsreadGet items checked out to a user.
user_two_factorreadManage user two-factor authentication.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (12 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/setup-snipeit-mcp.sh:216
probe_url="http://127.0.0.1:${MCP_PORT}/.well-known/oauth-authorization-server"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/update-snipeit-mcp.sh:61
probe_url="http://127.0.0.1:${probe_port}/.well-known/oauth-authorization-server"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_identity_http.py:131
url = f"http://127.0.0.1:{port}/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_identity_http.py:147
url = f"http://127.0.0.1:{port}/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_identity_http.py:164
response = await http.get(f"http://127.0.0.1:{port}/healthz")

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 64cdcce0204dfull audit observations/trust-audit/mcp-server/jameshgordy__snipe-it-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0964cdcce0204dCAUTIONB89first audit
06

Questions

What is the Snipe-IT MCP server?

MCP server for Snipe-IT asset management. Enables AI assistants to manage assets, consumables, accessories, licenses, users, and system configuration via 39 comprehensive tools.

What tools does Snipe-IT expose?

8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Snipe-IT safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Snipe-IT need?

It reads SNIPEIT_OAUTH_CLIENT_ID, SNIPEIT_OAUTH_CLIENT_SECRET and SNIPEIT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Snipe-IT run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as snipeit-mcp.

How current is this page?

The grade is for one exact copy of the source (64cdcce0204d), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement