Atlas / MCP servers / razee4315 / NetLogo

NetLogoBLOCK

mcp/razee4315/netlogo

The first MCP (Model Context Protocol) server for NetLogo, enabling AI assistants like Claude to create, run, and analyze agent-based models through natural conversation.

Verdict
BLOCK
Grade
F
Trust score
50 /100
Exposed tools
36 21r · 14w · 1d
Transport
stdio
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The first MCP (Model Context Protocol) server for NetLogo — enabling AI assistants to create, run, and analyze agent-based models through natural conversation.

Works with: Claude Code, Claude Desktop, Cursor, Windsurf, VS Code (Copilot), Cline, Continue, Roo Code, Zed, OpenCode, Codex — any tool that supports MCP.

Why NetLogo MCP?

As an AI student taking an Agent-Based Modeling course, I searched for an MCP server to control NetLogo — nothing existed. So I built one.

Instead of manually writing NetLogo code, clicking buttons, and tweaking sliders, you tell your AI assistant what you want in plain English:

"Create a predator-prey model with 100 sheep and 20 wolves. Run it for 500 ticks and show me the population dynamics."

The AI writes the code, runs the simulation, and shows you the results — all through conversation.

Read from source at commit 6c0560bcc76cOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add netlogo-mcp -- None netlogo-mcp==1.0.1
03

Exposed tools (36)

21 read · 14 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
calibratereadCalibrate simulated funnel rates to real-world levels.
close_modeldestructiveUnload the currently loaded model and reset the workspace.
commandwriteExecute a NetLogo command (e.g.
compare_campaign_variantsreadPaired A/B comparison of a campaign
create_campaignwriteCreate and save a campaign (one audience x one or more ad/email
create_modelwriteCreate a new NetLogo model from code and load it.
download_comses_modelreadDownload and safely extract a COMSES model archive.
export_viewreadExport the current NetLogo view as a PNG image.
export_worldreadExport the full world state to a CSV file.
generate_audiencewriteGenerate and save a synthetic audience from a YAML spec.
get_agent_samplereadReturn a sample of agents with selected variables as a markdown table.
get_audiencereadShow a saved audience: spec summary, archetypes, and sample persona
get_campaign_reportwriteGenerate the pre-flight report for a campaign that has been run.
get_comses_modelreadGet detailed metadata for a specific CoMSES model.
get_patch_datawriteGet patch data as a 2D grid (useful for heatmaps / spatial analysis).
get_world_statereadGet the current world state: tick count, agent counts, world dimensions.
interview_personareadAsk a follow-up question to persona(s) — an on-demand focus group.
list_audiencesreadList saved synthetic audiences.
list_campaignsreadList saved campaigns.
list_experimentsreadList BehaviorSpace experiments saved inside a NetLogo model file.
list_modelsreadList all .nlogo model files in the configured models directory.
market_inforeadStatus of the market-simulation module: LLM config, saved audiences,
open_comses_modelreadDownload (or reuse cache), then open a COMSES model ready to use.
open_modelreadOpen an existing .nlogo model file.
preview_experimentwriteShow the run plan for a BehaviorSpace experiment WITHOUT executing it.
read_comses_filesreadReturn text contents of source and documentation files from a
reportreadEvaluate a NetLogo reporter expression and return its value.
run_campaignwriteRun a saved campaign against its audience and log every reaction.
run_experimentwriteRun a BehaviorSpace experiment headlessly and return summarized results.
run_simulationwriteRun the simulation for N ticks and collect reporter data each tick.
save_modelwriteSave NetLogo model code to a .nlogox file in the models directory.
search_comsesreadSearch the CoMSES Net computational model library.
server_inforeadReturn a snapshot of the running NetLogo MCP server
set_parameterwriteSet a NetLogo global variable / slider / switch value.
update_modelwriteUpdate the currently loaded model
watch_simulationwriteRun the simulation SLOWLY so a human can watch it in the GUI window.
04

Trust audit

BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (9 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
desktop-app/node_modules/source-map-js/lib/quick-sort.js:111
let templateFn = new Function(`return ${template}`)();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
desktop-app/node_modules/typescript/lib/lib.es5.d.ts:998
exec(string: string): RegExpExecArray | null;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
overleaf.zip
overleaf.zip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
desktop-app/node_modules/@tauri-apps/api/event.cjs:95
*   console.log(`App is loaded, loggedIn: ${event.payload.loggedIn}, token: ${event.payload.token}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
desktop-app/node_modules/@tauri-apps/api/event.d.ts:97
*   console.log(`App is loaded, loggedIn: ${event.payload.loggedIn}, token: ${event.payload.token}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
desktop-app/node_modules/@tauri-apps/api/event.js:93
*   console.log(`App is loaded, loggedIn: ${event.payload.loggedIn}, token: ${event.payload.token}`);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
desktop-app/node_modules/caniuse-lite/data/features.js:1
module.exports={"aac":require("./features/aac"),"abortcontroller":require("./features/abortcontroller"),"ac3-ec3":require("./features/ac3-ec3"),"accelerometer":require("./features/accelerometer"),"add
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
desktop-app/node_modules/@tauri-apps/api/core.cjs:193
* await invoke('login', { user: 'tauri', password: 'poiwe3h4r5ip3yrhtew9ty' });
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
desktop-app/node_modules/@tauri-apps/api/core.d.ts:117
* await invoke('login', { user: 'tauri', password: 'poiwe3h4r5ip3yrhtew9ty' });
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
desktop-app/node_modules/@tauri-apps/api/core.js:191
* await invoke('login', { user: 'tauri', password: 'poiwe3h4r5ip3yrhtew9ty' });
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
close_model
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
desktop-app/node_modules/.package-lock.json
.package-lock.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
desktop-app/node_modules/gensync/test/.babelrc
.babelrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
desktop-app/node_modules/react-dom/cjs/react-dom-server.node.development.js:4069
componentKeyPath = crypto.createHash("md5");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
desktop-app/node_modules/react-dom/cjs/react-dom-server.node.production.js:3582
componentKeyPath = crypto.createHash("md5");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
desktop-app/node_modules/react-refresh/cjs/react-refresh-babel.development.js:226
.createHash("sha1")
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
desktop-app/node_modules/react-refresh/cjs/react-refresh-babel.production.js:225
.createHash("sha1")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
desktop-app/node_modules/@babel/core/lib/config/files/configuration.js:52
var _configError = require("../../errors/config-error.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
desktop-app/node_modules/@babel/core/lib/config/files/configuration.js:53
var fs = require("../../gensync-utils/fs.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
desktop-app/node_modules/@babel/core/lib/config/files/configuration.js:55
var _rewriteStackTrace = require("../../errors/rewrite-stack-trace.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
desktop-app/node_modules/@babel/core/lib/config/files/configuration.js:56
var _async = require("../../gensync-utils/async.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
desktop-app/node_modules/@babel/core/lib/config/files/module-types.js:8
var _async = require("../../gensync-utils/async.js");
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
desktop-app/node_modules/convert-source-map/index.js:41
return decodeURIComponent(escape(atob(base64)));

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 6c0560bcc76cfull audit observations/trust-audit/mcp-server/razee4315__netlogo.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-096c0560bcc76cBLOCKF50first audit
06

Questions

What is the NetLogo MCP server?

The first MCP (Model Context Protocol) server for NetLogo, enabling AI assistants like Claude to create, run, and analyze agent-based models through natural conversation.

What tools does NetLogo expose?

36 in total: 21 read-only, 14 that write, and 1 that can delete or overwrite (close_model). Every one is listed on this page with its risk.

Is NetLogo safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (50/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does NetLogo need?

It reads SYNTH_LLM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does NetLogo run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as yallist at 3.1.1.

How current is this page?

The grade is for one exact copy of the source (6c0560bcc76c), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement