GlobalpingBLOCK
Remote MCP server that gives LLMs access to run network commands
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Enable AI models to interact with a global network measurement platform through natural language. Give network access to any LLM.
What is Globalping?
Globalping is a free, public API that provides access to a globally distributed network of probes for monitoring, debugging, and benchmarking internet infrastructure. With Globalping, you can run network tests (ping, traceroute, DNS, MTR, HTTP) from thousands of locations worldwide.
What is the Globalping MCP Server?
The Globalping MCP Server implements the Model Context Protocol (MCP), allowing AI models and IDE assistants to interact with Globalping's network measurement capabilities through natural language.
The server supports standard OAuth 2.0 authentication as well as API token authentication for automated workflows.
Key Features
- 🌐 Global Network Access: Run measurements from thousands of probes worldwide
- 🤖 AI-Friendly Interface: Any LLM will easily parse the data and run new measurements as needed
- 📊 Comprehensive Measurements: Support for ping, traceroute, DNS, MTR, and HTTP tests
- 🔍 Smart Context Handling: Detailed parameter descriptions and semantic tool annotations for intelligent agent routing
- 🔄 Comparative Analysis: Compare network latency and routing between different targets and geographic locations
- 🔑 Authentication Support: Use OAuth or an API token with your Globalping account for higher rate limits
Installation
The primary endpoint for all mod
800bd364a751OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add globalping-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"globalping-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (11)
11 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
authStatus | read | |
compareLocations | read | |
dns | read | |
getMeasurement | read | |
help | read | |
http | read | |
limits | read | |
locations | read | |
mtr | read | |
ping | read | |
traceroute | read |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (7 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
exec(cmd: string[], options?: ContainerExecOptions): Promise<ExecProcess>;
exec(query: string): Promise<D1ExecResult>;
"http://127.0.0.1",
"https://127.0.0.1",
const token = "abcdefghijklmnopqrstuvwxyz123456";
const token = "abcdefghijklmnopqrstuvwxyz123456";
const token = "abcdefghijklmnopqrstuvwxyz123456";
sse,streamable-http
} from "../../../src/api/client";
import type { MeasurementOptions } from "../../../src/types";} from "../../../src/auth/token-manager";
"../../../etc/passwd",
import { redactAgentCatEvent } from "../../../src/lib";expect(validateOrigin("http://127.0.0.1")).toBe(true);expect(validateOrigin("https://127.0.0.1")).toBe(true);expect(validateOrigin("http://127.0.0.1:3000")).toBe(true);atob(data: string): string;
declare function atob(data: string): string;
expect(validateOrigin("https://mсp.globalping.io")).toBe(false); // Cyrillic 'с'expect(validateHost("mсp.globalping.io")).toBe(false); // Cyrillic 'с'@cloudflare/workers-oauth-provider, agentcat, agents, globalping, hono, zod, @biomejs/biome, @cloudflare/vitest-pool-workers
* For API-token authentication, generate a current token in the [Globalping dashboard](https://dash.globalping.io) and send it as `Authorization: Bearer YOUR_GLOBALPING_API_TOKEN`.
* For security-sensitive reports, use GitHub's private [Report a vulnerability](https://github.com/jsdelivr/globalping-mcp-server/security/advisories/new) form. Do not include credentials or sensitive
Gates applied: no_behavioural_pass, no_license.
800bd364a751full audit observations/trust-audit/mcp-server/jsdelivr__globalping.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 800bd364a751 | BLOCK | F | 54 | first audit |
Questions
What is the Globalping MCP server?
Remote MCP server that gives LLMs access to run network commands
What tools does Globalping expose?
11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Globalping safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Globalping need?
No credential environment variables were found in its source, so it appears to need none.
How does Globalping run?
It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as globalping-mcp-server at 1.1.0.
How current is this page?
The grade is for one exact copy of the source (800bd364a751), read on 2026-10-07. The repository is watched and re-audited when it changes.