OllamaCAUTION
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
🚀 A powerful bridge between Ollama and the Model Context Protocol (MCP), enabling seamless integration of Ollama's local LLM capabilities into your MCP-powered applications.
🌟 Features
Complete Ollama Integration
- Full API Coverage: Access all essential Ollama functionality through a clean MCP interface
- OpenAI-Compatible Chat: Drop-in replacement for OpenAI's chat completion API
- Local LLM Power: Run AI models locally with full control and privacy
Core Capabilities
- 🔄 Model Management
- Pull models from registries
- Push models to registries
- List available models
- Create custom models from Modelfiles
- Copy and remove models
- 🤖 Model Execution
- Run models with customizable prompts
- Chat completion API with system/user/assistant roles
- Configurable parameters (temperature, timeout)
- Raw mode support for direct responses
- 🛠 Server Control
- Start and manage Ollama server
- View detailed model information
- Error handling and timeout management
🚀 Getting Started
Prerequisites
- Ollama installed on your system
- Node.js and npm/pnpm
Installation
- Install dependencies:
pnpm install
- Build the server:
pnpm run build
Configuration
Add the server to your MCP configuration:
For Claude Desktop:
MacOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%/Claude/claude_desktop_config.json
{
"mcpServers": {
"ollama": {
"command": "node",
"args": ["/path/to/ollama-server/build/index.js"],
"env": {
"OLLAMA_HOST": "http://127.0.0.1:11434" // Optional: customize Ollama API endpoint
}
}
}
}🛠 Usage Examples
Pull and Run a Model
// Pull a model
await mcp.use_mcp_tool({
server_name: "ollama",
tool_name: "pull",
arguments: {
name: "llama2"
}
});
// Run the model
await mcp.use_mcp_tool({
a68540b923ceOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ollama-mcp -- npx -y [email protected]
{
"mcpServers": {
"ollama-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (10)
5 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
chat_completion | read | OpenAI-compatible chat completion API |
cp | read | Copy a model |
create | write | Create a model from a Modelfile |
list | read | List models |
pull | read | Pull a model from a registry |
push | write | Push a model to a registry |
rm | destructive | Remove a model |
run | write | Run a model |
serve | write | Start Ollama server |
show | read | Show information for a model |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
const OLLAMA_HOST = process.env.OLLAMA_HOST || 'http://127.0.0.1:11434';
rm
"OLLAMA_HOST": "http://127.0.0.1:11434" // Optional: customize Ollama API endpoint
- `OLLAMA_HOST`: Configure custom Ollama API endpoint (default: http://127.0.0.1:11434)
axios, @types/node, typescript
Gates applied: no_behavioural_pass, no_license.
a68540b923cefull audit observations/trust-audit/mcp-server/nighttrek__ollama-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a68540b923ce | CAUTION | B | 86 | first audit |
Questions
What tools does Ollama expose?
10 in total: 5 read-only, 4 that write, and 1 that can delete or overwrite (rm). Every one is listed on this page with its risk.
Is Ollama safe to connect to an agent?
With care. The audit graded it B (86/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Ollama need?
No credential environment variables were found in its source, so it appears to need none.
How does Ollama run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as ollama-mcp at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (a68540b923ce), read on 2026-10-07. The repository is watched and re-audited when it changes.