Atlas / MCP servers / raylanlin / SmartTune

SmartTuneCAUTION

mcp/raylanlin/smarttune

SmartTune CLI — Multi-platform flight log analysis & tuning advisor (ArduPilot + Betaflight + PX4)

Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
16 12r · 4w · 0d
Transport
—
License
MIT
Stars
31
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Offline flight log analysis, built agent-first from day one One command from raw log to tunable PID/FFT/MagFit parameters — no special flights needed

ArduPilot · Betaflight · PX4 Quick Start · For Agents · Commands · Output Formats · Architecture

Pip-install SmartTune, point it at a flight log, and your agent comes back with exact parameter deltas — validated against real firmware parameter tables. No more guessing: stune params --validate checks every recommendation before it reaches the user. Under the hood: ArduPilot step-response analysis replicates WebTools PIDReview.js via Wiener deconvolution. Betaflight blackbox logs are parsed by a 1000+ line pure-Python decoder (no C extensions, no Node.js). All three platforms output to one FlightData dataclass so analyzers work identically across APM/BF/PX4. The 6-layer knowledge base is plain JSON — agents can read rules and propose new ones by editing ~/.smarttune/knowledge/.

Install

pip install git+https://github.com/raylanlin/smarttune-cli.git

# With all platform extras
pip i
Read from source at commit a4ca380ea99bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add smarttune -- uvx smarttune
claude-desktop
{
  "mcpServers": {
    "smarttune": {
      "command": "uvx",
      "args": [
        "smarttune"
      ]
    }
  }
}
03

Exposed tools (16)

12 read · 4 write · 0 destructive.

ToolRiskDescription
smarttune_analyze_fftreadFFT vibration spectrum analysis — identify vibration frequencies and severity.
smarttune_analyze_filterwriteFilter transfer function analysis (Bode plot data).
smarttune_analyze_hardwarereadHardware configuration report — sensor setup, filter config, PID parameters.
smarttune_analyze_logwriteRun comprehensive flight log analysis and return structured recommendations.
smarttune_analyze_magfitreadMagnetometer calibration analysis — evaluate compass calibration quality.
smarttune_analyze_pidreadPID step response analysis — detect step responses and evaluate tuning quality.
smarttune_analyze_sysidwriteARX system identification — estimate transfer function from flight data.
smarttune_generate_plotreadGenerate an analysis chart as a base64 PNG image.
smarttune_get_paramreadGet the FULL definition of one parameter — description, range, default, enum members.
smarttune_list_param_groupsreadList a platform
smarttune_list_paramsreadList parameters for a platform, filtered by group or category.
smarttune_list_platformsreadList all supported flight controller platforms, their log file extensions, and analysis capabilities.
smarttune_log_qualityreadAssess flight log data quality for analysis.
smarttune_search_paramsreadSearch parameters by keyword, ranked by match quality.
smarttune_validate_paramreadValidate that a parameter exists AND the proposed value is legal. Call before recommending anything.
smarttune_validate_paramswriteValidate a WHOLE recommendation set in one call — one tool call instead of N.
04

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (11)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
smarttune/services/analysis.py:392
_hr_mod = importlib.import_module(f"smarttune.platform.{adapter.name}.hardware_report")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
smarttune/services/analysis.py:590
_ft_mod = importlib.import_module(f"smarttune.platform.{adapter.name}.filter_transfer")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
smarttune/services/analysis.py:794
_ft_mod = importlib.import_module(f"smarttune.platform.{adapter.name}.filter_transfer")
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
tools/smoke_mcp.py:371
payload, _ = client.call_tool("smarttune_log_quality", {"log_path": "/etc/passwd"})
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
smarttune/analyzers/magfit.py:64
TYPICAL_FIELD_UT = 50.0  # μT → 换算 1 mGauss = 0.1 μT
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
smarttune/analyzers/sysid_analyzer.py:476
f"  自然频率 ωn = {r.natural_freq_hz:.2f} Hz ({r.natural_freq_hz*2*np.pi:.1f} rad/s)"
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/test_mcp_security.py:95
validate_log_path("/etc/passwd")
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/test_synthetic_regression.py:156
assert abs(wn_est - wn_true) / wn_true < 0.30, f"ωn 估计 {wn_est:.1f} vs 真值 {wn_true}"
INFOInventory / provenance · inv.oversize · CWE-1104
smarttune/knowledge/params/ardupilot.copter-4.5.json
smarttune/knowledge/params/ardupilot.copter-4.5.json
Why it matters. 2305874 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
smarttune/knowledge/params/ardupilot.json
smarttune/knowledge/params/ardupilot.json
Why it matters. 1608620 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
smarttune/knowledge/params/px4.json
smarttune/knowledge/params/px4.json
Why it matters. 1121345 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha a4ca380ea99bfull audit observations/trust-audit/mcp-server/raylanlin__smarttune.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08a4ca380ea99bCAUTIONB82first audit
06

Questions

What is the SmartTune MCP server?

SmartTune CLI — Multi-platform flight log analysis & tuning advisor (ArduPilot + Betaflight + PX4)

What tools does SmartTune expose?

16 in total: 12 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SmartTune safe to connect to an agent?

With care. The audit graded it B (82/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does SmartTune need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (a4ca380ea99b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement