ROSSAFE
Connect AI models like Claude & GPT with robots using MCP and ROS.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
ROS-MCP-Server connects large language models (such as Claude, GPT, and Gemini) to robots, enabling bidirectional communication with no changes to existing robot source code.
Why ROS-MCP?
- No robot source code changes → just add the
rosbridgenode to your existing ROS setup. - True two-way communication → LLMs can both control robots and observe everything happening on the Robot.
- Full context → publish & subscribe to topics, call services & actions, set parameters, read sensor data, and monitor robot state in real time.
- Deep ROS understanding → guides the LLM to discover available topics, services, actions, and their types (including custom ones) — enabling it to use them with the right syntax without manual configuration.
- Works with any MCP client → built on the open MCP standard, supporting Claude Code, Codex CLI, Gemini CLI, Claude Desktop, ChatGPT, Cursor, and more.
- Works across ROS versions → compatible across ROS 2 (Jazzy, Humble, and others) and ROS 1 distros.
🎥 Examples in Action
96438cba9b12OBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ros-mcp -- None ros-mcp==3.1.2
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (21)
limo_example.usd
Then point your AI client to `http://127.0.0.1:9000/mcp`. See the [HTTP transport](http-transport.md) page for client configuration details.
The server will start listening at `http://127.0.0.1:9000/mcp`.
"url": "http://127.0.0.1:9000/mcp"
- Ensure the server is accessible at `http://127.0.0.1:9000/mcp`
- Check if your domain is active: Visit ngrok dashboard at `http://127.0.0.1:4040/status`
image_bytes = base64.b64decode(data_b64)
image_bytes = base64.b64decode(data_b64)
Open PowerShell and configure the environment variables to enable ROS2 bridge:
Add to `~/.zshrc` for persistence.
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
docs/images/MCP Demos Slide - 7to12s.gif
examples/3_limo_mobile_robot/images/limo.png
examples/3_limo_mobile_robot/images/limo_isaac_sim.png
examples/3_limo_mobile_robot/images/limo_isaac_sim_simple_movement.gif
examples/3_limo_mobile_robot/images/limo_real_simple_movement.gif
Gates applied: no_behavioural_pass.
96438cba9b12full audit observations/trust-audit/mcp-server/robotmcp__ros-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | 96438cba9b12 | SAFE | B | 89 | first audit |
Questions
What is the ROS MCP server?
Connect AI models like Claude & GPT with robots using MCP and ROS.
Is ROS safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does ROS need?
No credential environment variables were found in its source, so it appears to need none.
How does ROS run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as ros-mcp.
How current is this page?
The grade is for one exact copy of the source (96438cba9b12), read on 2026-09-24. The repository is watched and re-audited when it changes.