Atlas / MCP servers / rawveg / Ollama

OllamaCAUTION

mcp/rawveg/ollama

An MCP Server for Ollama

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
14 11r · 2w · 1d
Transport
stdio
License
AGPL-3.0
Stars
174
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Supercharge your AI assistant with local LLM access

[](https://www.gnu.org/licenses/agpl-3.0) [](https://www.typescriptlang.org/) [](https://github.com/anthropics/model-context-protocol) [](https://github.com/rawveg/ollama-mcp)

An MCP (Model Context Protocol) server that exposes the complete Ollama SDK as MCP tools, enabling seamless integration between your local LLM models and MCP-compatible applications like Claude Desktop and Cline.

Features • Installation • Available Tools • Configuration • Retry Behavior • Development

✨ Features

  • ☁️ Ollama Cloud Support - Full integration with Ollama's cloud platform
  • 🔧 14 Comprehensive Tools - Full access to Ollama's SDK functionality
  • 🔄 Hot-Swap Architecture - Automatic tool discovery with zero-config
  • 🎯 Type-Safe - Built with TypeScript and Zod validation
  • 📊 High Test Coverage - 96%+ coverage with comprehensive test suite
  • 🚀 Zero Dependencies - Minimal footprint, maximum performance
  • 🔌 Drop-in Integration - Works with Claude Desktop, Cline, and other MCP clients
  • 🌐 Web Search & Fetch - Real-time web search and content extraction via Ollama Cloud
  • 🔀 Hybrid Mode - Use local and cloud models seamlessly in one server

💡 Level Up Your Ollama Experience with Claude Code and Desktop

The Complete Package: Tools + Knowledge

This MCP server gives Claude the tools to interact with Ollama - but you'll get even more value by also installing the Ollama Skill from the Skillsforge Marketplace:

  • 🚗
Read from source at commit 78471f5c7f0eOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ollama-mcp --env OLLAMA_API_KEY=${OLLAMA_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "ollama-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OLLAMA_API_KEY": "${OLLAMA_API_KEY}"
      }
    }
  }
}
03

Exposed tools (14)

11 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
get_weatherreadGet weather
ollama_chatreadChat with a model using conversation messages. Supports system messages, multi-turn conversations, tool calling, and generation options.
ollama_copyreadCopy a model. Creates a duplicate of an existing model with a new name.
ollama_createwriteCreate a new model with structured parameters. Allows customization of model behavior, system prompts, and templates.
ollama_deletedestructiveDelete a model from local storage. Removes the model and frees up disk space.
ollama_embedreadGenerate embeddings for text input. Returns numerical vector representations.
ollama_generatereadGenerate completion from a prompt. Simpler than chat, useful for single-turn completions.
ollama_listreadList all available Ollama models installed locally. Returns model names, sizes, and modification dates.
ollama_psreadList running models. Shows which models are currently loaded in memory.
ollama_pullreadPull a model from the Ollama registry. Downloads the model to make it available locally.
ollama_pushwritePush a model to the Ollama registry. Uploads a local model to make it available remotely.
ollama_showreadShow detailed information about a specific model including modelfile, parameters, and architecture details.
ollama_web_fetchreadFetch a web page by URL using Ollama\
ollama_web_searchreadPerform a web search using Ollama\
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/server.ts:23
host: process.env.OLLAMA_HOST || 'http://127.0.0.1:11434',
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
ollama_delete
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/server.test.ts:45
const { createServer } = await import('../../src/server.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/schemas/chat-input.test.ts:2
import { ChatInputSchema } from '../../src/schemas.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/chat.test.ts:3
import { chatWithModel, toolDefinition } from '../../src/tools/chat.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/chat.test.ts:4
import { ResponseFormat } from '../../src/types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/copy.test.ts:3
import { copyModel, toolDefinition } from '../../src/tools/copy.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:127
| `OLLAMA_HOST` | `http://127.0.0.1:11434` | Ollama server endpoint (use `https://ollama.com` for cloud) |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:184
"OLLAMA_HOST": "http://127.0.0.1:11434",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, json2md, markdown-table, ollama, zod, @types/node, @vitest/coverage-v8, typescript
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:23
- 🔧 **14 Comprehensive Tools** - Full access to Ollama's SDK functionality

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 78471f5c7f0efull audit observations/trust-audit/mcp-server/rawveg__ollama.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0678471f5c7f0eCAUTIONB89first audit
06

Questions

What is the Ollama MCP server?

An MCP Server for Ollama

What tools does Ollama expose?

14 in total: 11 read-only, 2 that write, and 1 that can delete or overwrite (ollama_delete). Every one is listed on this page with its risk.

Is Ollama safe to connect to an agent?

With care. The audit graded it B (89/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Ollama need?

It reads OLLAMA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Ollama run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as ollama-mcp at 2.1.0.

How current is this page?

The grade is for one exact copy of the source (78471f5c7f0e), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement