Atlas / MCP servers / robotmcp / ros-mcp-server

ros-mcp-serverSAFE

mcp/robotmcp/ros-mcp-server

Connect AI models like Claude & GPT with robots using MCP and ROS.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio · streamable-http
License
Apache-2.0
Stars
1,469
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

ROS-MCP-Server connects large language models (such as Claude, GPT, and Gemini) to robots, enabling bidirectional communication with no changes to existing robot source code.

Why ROS-MCP?

  • No robot source code changes → just add the rosbridge node to your existing ROS setup.
  • True two-way communication → LLMs can both control robots and observe everything happening on the Robot.
  • Full context → publish & subscribe to topics, call services & actions, set parameters, read sensor data, and monitor robot state in real time.
  • Deep ROS understanding → guides the LLM to discover available topics, services, actions, and their types (including custom ones) — enabling it to use them with the right syntax without manual configuration.
  • Works with any MCP client → built on the open MCP standard, supporting Claude Code, Codex CLI, Gemini CLI, Claude Desktop, ChatGPT, Cursor, and more.
  • Works across ROS versions → compatible across ROS 2 (Jazzy, Humble, and others) and ROS 1 distros.

🎥 Examples in Action

Read from source at commit ff82718ec099OBSERVED · 2026-09-22
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add ros-mcp -- None ros-mcp==3.1.0
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (21)

LOWInventory / provenance · inv.binary · CWE-1104
examples/3_limo_mobile_robot/isaac_sim/usd/limo_example.usd
limo_example.usd
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/install/from-source.md:46
Then point your AI client to `http://127.0.0.1:9000/mcp`. See the [HTTP transport](http-transport.md) page for client configuration details.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/install/http-transport.md:22
The server will start listening at `http://127.0.0.1:9000/mcp`.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/install/http-transport.md:42
"url": "http://127.0.0.1:9000/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
examples/6_chatgpt/README.md:353
- Ensure the server is accessible at `http://127.0.0.1:9000/mcp`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
examples/6_chatgpt/README.md:362
- Check if your domain is active: Visit ngrok dashboard at `http://127.0.0.1:4040/status`
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
ros_mcp/utils/websocket.py:141
image_bytes = base64.b64decode(data_b64)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
ros_mcp/utils/websocket.py:155
image_bytes = base64.b64decode(data_b64)
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
examples/3_limo_mobile_robot/isaac_sim/README.md:118
Open PowerShell and configure the environment variables to enable ROS2 bridge:
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
examples/6_chatgpt/README.md:155
Add to `~/.zshrc` for persistence.
Why it matters. instructs the agent to persist itself in the user's environment
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/install/clients/chatgpt.md:14
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/install/clients/claude-code.md:10
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/install/clients/claude-desktop.md:13
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/install/clients/codex-cli.md:10
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/install/clients/cursor.md:10
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOInventory / provenance · inv.oversize · CWE-1104
docs/images/MCP Demos Slide - 7to12s.gif
docs/images/MCP Demos Slide - 7to12s.gif
Why it matters. 6953500 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
examples/3_limo_mobile_robot/images/limo.png
examples/3_limo_mobile_robot/images/limo.png
Why it matters. 2032689 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
examples/3_limo_mobile_robot/images/limo_isaac_sim.png
examples/3_limo_mobile_robot/images/limo_isaac_sim.png
Why it matters. 1324096 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
examples/3_limo_mobile_robot/images/limo_isaac_sim_simple_movement.gif
examples/3_limo_mobile_robot/images/limo_isaac_sim_simple_movement.gif
Why it matters. 17122573 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
examples/3_limo_mobile_robot/images/limo_real_simple_movement.gif
examples/3_limo_mobile_robot/images/limo_real_simple_movement.gif
Why it matters. 49154186 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha ff82718ec099full audit observations/trust-audit/mcp-server/robotmcp__ros-mcp-server.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-22ff82718ec099SAFEB89first audit
05

Questions

What is the ros-mcp-server MCP server?

Connect AI models like Claude & GPT with robots using MCP and ROS.

Is ros-mcp-server safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does ros-mcp-server need?

No credential environment variables were found in its source, so it appears to need none.

How does ros-mcp-server run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as ros-mcp.

How current is this page?

The grade is for one exact copy of the source (ff82718ec099), read on 2026-09-22. The repository is watched and re-audited when it changes.

Advertisement