Atlas / MCP servers / mahdin75 / GeoServer

GeoServerSAFE

mcp/mahdin75/geoserver

A Model Context Protocol (MCP) server implementation that connects LLMs to the GeoServer REST API

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
56 25r · 24w · 7d
Transport
streamable-http
License
MIT
Stars
92
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/geoserver-mcp/) [](https://pepy.tech/project/geoserver-mcp)

A Model Context Protocol (MCP) server implementation that connects Large Language Models (LLMs) to the GeoServer REST API, enabling AI assistants to interact with geospatial data and services.

Version 0.5.0 (Beta) is under active development and will be released shortly. We are open to contributions and welcome developers to join us in building this project.

🎥 Demo

📋 Table of Contents

  • Features
  • Deployment Options
  • Prerequisites
  • Installation
  • Docker Installation
  • pip Installation
  • Development Installation
  • File Storage and --storage Usage
  • Available Tools
  • Resource Endpoints
  • Workspace Management
  • Datastore & Coveragestore Management
  • Layer Management
  • Layer Group Management
  • User & User Group Management
  • Feature Type & Attribute Management
  • Style Management
  • System & Service Operations
  • Style XML Utilities
  • [Client Dev
Read from source at commit 3bca0fc376e9OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add geoserver-mcp --env GEOSERVER_PASSWORD=${GEOSERVER_PASSWORD} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- uvx geoserver-mcp
claude-desktop
{
  "mcpServers": {
    "geoserver-mcp": {
      "command": "uvx",
      "args": [
        "geoserver-mcp"
      ],
      "env": {
        "GEOSERVER_PASSWORD": "${GEOSERVER_PASSWORD}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
      }
    }
  }
}
03

Exposed tools (56)

25 read · 24 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_layer_to_layergroupwriteAdd a specific layer to a layer group.
create_catagorized_featurestylewriteCreate a categorized style for features (polygon, line, point) using column values.
create_classified_featurestylewriteCreate a classified style for features using distinct column values/classes.
create_coveragestorewriteCreate a new coveragestore in a workspace.
create_coveragestylewriteCreate a raster coverage style (colormap, ...)
create_datastorewriteCreate a new datastore in the given workspace.
create_featurestorewriteCreate a new featurestore in the given workspace.
create_gpkg_datastorewriteCreate a GeoPackage (GPKG) datastore.
create_layerwriteCreate a new layer in GeoServer.
create_layergroupwriteCreate a new layer group with specific layers and (optionally) styles.
create_outline_featurestylewriteCreate a simple outline-only style for features.
create_shp_datastorewriteCreate an ESRI Shapefile datastore.
create_stylewriteCreate a new SLD style in GeoServer.
create_userwriteCreate a new user for GeoServer security.
create_usergroupwriteCreate a new user group.
create_workspacewriteCreate a new workspace in GeoServer.
delete_coveragestoredestructiveDelete a coveragestore from a workspace.
delete_layergroupdestructiveDelete a layer group from a workspace.
delete_resourcedestructiveDelete a resource from GeoServer.
delete_userdestructiveDelete a user by name.
delete_usergroupdestructiveDelete a user group.
edit_featuretypewriteEdit the settings of a feature type in a store.
generate_mapreadGenerate a map image using WMS GetMap.
get_all_usergroupsreadReturn all user groups.
get_all_usersreadList all users in the GeoServer instance.
get_coveragestorereadGet details about a single coveragestore.
get_coveragestoresreadGet all coveragestores in a workspace.
get_datastorereadGet a specific datastore by name.
get_datastoresreadList all datastores in the given workspace.
get_feature_attributereadGet feature attribute schema/details.
get_featuretypesreadList all feature types in a given store.
get_layer_inforeadGet detailed information about a layer.
get_layergroupreadGet a layer group from a workspace.
get_layergroupsreadList all layer groups in a workspace.
get_manifestreadGet GeoServer manifest metadata/details.
get_statusreadObtain general server status.
get_system_statusreadGet system status overview/info from GeoServer.
get_versionreadFetch GeoServer version string.
list_layersreadList layers in GeoServer, optionally filtered by workspace.
list_workspacesreadList available workspaces in GeoServer.
modify_userwriteModify an existing user
publish_featurestorewritePublish an existing featurestore.
publish_featurestore_sqlviewwritePublish a featurestore using a SQL view definition.
publish_stylewriteAssign/publish a style to a layer.
publish_time_dimension_to_coveragestorewriteAdd or update a time dimension for a coverage store (for time series).
query_featuresreadQuery features from a vector layer using CQL filter.
reload_geoserverreadReload catalog and config from disk.
remove_layer_from_layergroupdestructiveRemove a layer from a group.
reset_geoserverdestructiveReset all GeoServer caches/connections.
style_catagorize_xmlreadGenerate SLD for categorized vector style (SVG fill/block display).
style_classified_xmlreadGet SLD XML for classified vector style.
style_coverage_style_colormapentryreadGenerate color map entries for raster SLD.
style_coverage_style_xmlreadGenerate XML for raster/coverage SLD.
style_outline_only_xmlreadXML for outline-only style for a geometry.
update_layergroupwriteUpdate a layer group
update_servicewriteUpdate selected OGC service options.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_coveragestore, delete_layergroup, delete_resource, delete_user, delete_usergroup, remove_layer_from_layergroup, reset_geoserver
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
extension/examples/langchain_mcp_test.py:237
"http://127.0.0.1:8080/geoserver/mcp (Python localhost can hit IPv6 and get 503).\n"
INFOInventory / provenance · inv.oversize · CWE-1104
docs/geoserver-mcp.png
docs/geoserver-mcp.png
Why it matters. 1003539 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 3bca0fc376e9full audit observations/trust-audit/mcp-server/mahdin75__geoserver.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-073bca0fc376e9SAFEB89first audit
06

Questions

What is the GeoServer MCP server?

A Model Context Protocol (MCP) server implementation that connects LLMs to the GeoServer REST API

What tools does GeoServer expose?

56 in total: 25 read-only, 24 that write, and 7 that can delete or overwrite (delete_coveragestore, delete_layergroup, delete_resource, delete_user, delete_usergroup). Every one is listed on this page with its risk.

Is GeoServer safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GeoServer need?

It reads GEOSERVER_PASSWORD, OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does GeoServer run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as geoserver-mcp.

How current is this page?

The grade is for one exact copy of the source (3bca0fc376e9), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement