Atlas / MCP servers / kallistox / UniFi Applications

UniFi ApplicationsSAFE

mcp/kallistox/unifi-applications

UniFi MCP server that makes the official UniFi API documentation (Network, Protect, Site Manager, InnerSpace) queryable by AI agents — endpoint search, schema drill-down, code examples in 5 languages. Read-only, no controller credentials.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
10 10r · 0w · 0d
Transport
stdio
License
MIT
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/mcp-unifi-applications/) [](https://pypi.org/project/mcp-unifi-applications/) [](https://glama.ai/mcp/servers/KallistoX/mcp-unifi-applications)

A Model Context Protocol (MCP) server that makes the official UniFi API documentation queryable by AI agents — endpoint search, schema drill-down, and code examples in five languages, for Claude Desktop, Claude Code (VS Code / JetBrains), or any MCP-compatible client.

Covers every application Ubiquiti publishes API docs for: Network, Protect, Site Manager, InnerSpace, Mobility and Carrier Fabric.

It is read-only and credential-free: it serves documentation, it does not talk to your controller. Includes a Playwright-based scraper that turns the JS-rendered docs SPA into structured JSON, and a Python MCP server that serves it.

Example

"Without any context, just by using the unifi-applications MCP Server: can you tell me how to create a network with Go with the network API from UniFi, and what options do I have regarding the managed IPv4 DHCP gateway configuration?"

Claude works that out through the server, with none of the documentation in its con

Read from source at commit 48cab0b6983aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add mcp-unifi-applications -- None mcp-unifi-applications==0.4.0
03

Exposed tools (10)

10 read · 0 write · 0 destructive.

ToolRiskDescription
find_fieldreadLocate a field by name across every endpoint, including inside discriminator
get_docs_inforeadReport what documentation this server is serving.
get_endpointreadGet everything documented about one endpoint: method, path, description,
get_endpoint_groupreadSee every operation on one resource at once, grouped by API path.
get_examplereadGet a runnable request for one endpoint, in one language, as published by
get_field_schemareadDrill into a specific field
get_guidereadRead a prose guide page: filtering syntax, error handling, getting started,
get_response_samplereadGet the sample response body published for one endpoint.
list_endpointsreadBrowse the endpoint catalogue: one line per endpoint with method, path, slug
search_endpointsreadFind endpoints by name, path fragment, method or description.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:16
It is **read-only and credential-free**: it serves documentation, it does not talk to your controller. Includes a Playwright-based scraper that turns the JS-rendered docs SPA into structured JSON, and
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
ROADMAP.md:113
long-running jobs. This one is a stateless, read-only, credential-free server that reads
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/superpowers/plans/2026-07-17-update-round.md:827
The `unifi-applications` server registered in `homelab-infra/.mcp.json` runs this repo's venv directly — tell the user: **Reload Window** (or restart Claude Code session) to pick up the new server cod
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 48cab0b6983afull audit observations/trust-audit/mcp-server/kallistox__unifi-applications.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0848cab0b6983aSAFEB89first audit
06

Questions

What is the UniFi Applications MCP server?

UniFi MCP server that makes the official UniFi API documentation (Network, Protect, Site Manager, InnerSpace) queryable by AI agents — endpoint search, schema drill-down, code examples in 5 languages. Read-only, no controller credentials.

What tools does UniFi Applications expose?

10 in total: 10 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is UniFi Applications safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does UniFi Applications need?

No credential environment variables were found in its source, so it appears to need none.

How does UniFi Applications run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-unifi-applications.

How current is this page?

The grade is for one exact copy of the source (48cab0b6983a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement