Atlas / MCP servers / tikoci / Rosetta

RosettaBLOCK

mcp/tikoci/rosetta-3

MCP Server with RouterOS docs + commands + products + changelogs, using SQLite-as-RAG, sourced from MikroTik

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
16 16r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
47
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP server that gives AI assistants searchable access to MikroTik RouterOS documentation — 363 pages extracted live from MikroTik's official Docusaurus manual (), 4,587 properties, a 40,000-entry command tree, hardware specs for 156 current products (part of a wider 255-device overlay also covering legacy/EOL gear and accessories), 746 YouTube video transcripts, and direct links to source docs.

If you need MikroTik docs, you likely have a MikroTik. Install rosetta once as a container on your router using RouterOS /app, and any AI assistant on the network can use it. Or run it locally on your workstation. No AI required — rosetta includes a terminal browser for searching the database directly.

SQL-as-RAG

Instead of vector embeddings, rosetta uses SQLite [FTS5](https://www.sqlite.org/fts5.html) full-text search as the retrieval layer — SQL-as-RAG. For structured technical docs, BM25 ranking with porter stemming beats vector similarity: terms like dhcp-snooping and /ip/firewall/filter are exact tokens, not fuzzy embeddings. No API keys, no vector database — just a single SQLite file that searches in milliseconds.

What's Inside

Read from source at commit 3a70d563191cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add rosetta -- npx -y @tikoci/[email protected]
03

Exposed tools (16)

16 read · 0 write · 0 destructive.

ToolRiskDescription
colorreadDisplay color of the note.
pvidreadPort VLAN ID.
routeros_command_diffread
routeros_command_treeread
routeros_command_version_checkread
routeros_current_versionsread
routeros_device_lookupread
routeros_dude_get_pageread
routeros_dude_searchread
routeros_explain_commandread
routeros_get_pageread
routeros_lookup_propertyread
routeros_searchread
routeros_search_changelogsread
routeros_search_testsread
routeros_statsread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (4 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
drafts/forum-post3-why.md:25
- **`/llms.txt`** — an index of all ~558 pages as `[Title](....md): description`
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/pick-next-task
.claude/skills/pick-next-task
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/pr-review-gate
.claude/skills/pr-review-gate
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/promote-idea
.claude/skills/promote-idea
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/re-extract
.claude/skills/re-extract
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/verify-task
.claude/skills/verify-task
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/eval/corpus-compare.ts:94
console.log(`\n0.10.0 (Confluence)  vs  current (Docusaurus) — topic-token hit@5\n`);
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/assess-hardware.ts:126
const raw = readFileSync(csvPath, "utf-8").replace(/^/, "");
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/assess-hardware.ts:325
const text = el.textContent?.replace(//g, "").trim() || "";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/canonicalize.ts:162
if (ch === ' ' || ch === '\t' || ch === '\r' || ch === '`' || ch === '') { i++; continue; }
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coderabbit.yaml
.coderabbit.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint-cli2.yaml
.markdownlint-cli2.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.yaml
.markdownlint.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlintignore
.markdownlintignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/release.test.ts:892
expect(src).not.toContain("MCP retrieval eval (Phase 0)");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/release.test.ts:893
expect(src).not.toContain("MCP retrieval eval (Phase 1, self-supervised, non-blocking)");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/eval/corpus-compare.ts:51
readFileSync(join(import.meta.dir, "../../fixtures/eval/queries.json"), "utf-8"),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/eval/retrieval.ts:153
const FIXTURE_PATH = join(import.meta.dir, "../../fixtures/eval/queries.json");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/eval/retrieval.ts:154
const BASELINE_PATH = join(import.meta.dir, "../../fixtures/eval/baseline.json");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/eval/self-supervised.ts:517
"../../fixtures/eval/self-supervised-baseline.json",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
dude/pages/v3_Web_interface.html:62
<p>After the server is enabled, you can access the router, by entering <b><a rel="nofollow" class="external free" href="https://web.archive.org/web/20240615045957/http://127.0.0.1:8080/">http://127.0.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp-http.test.ts:180
const resp = await fetch(`http://127.0.0.1:${port}/mcp`, {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp-http.test.ts:214
return { port, url: `http://127.0.0.1:${port}/mcp`, proc };
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/canonicalize.fuzz.test.ts:70
const result = canonicalize('/ip/address/print');
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/canonicalize.fuzz.test.ts:78
const result = canonicalize('/ip/address/print');

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 3a70d563191cfull audit observations/trust-audit/mcp-server/tikoci__rosetta-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-083a70d563191cBLOCKD69first audit
06

Questions

What is the Rosetta MCP server?

MCP Server with RouterOS docs + commands + products + changelogs, using SQLite-as-RAG, sourced from MikroTik

What tools does Rosetta expose?

16 in total: 16 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Rosetta safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Rosetta need?

It reads GH_TOKEN, GITHUB_TOKEN and TLS_KEY_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Rosetta run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @tikoci/rosetta at 0.12.0-next.

How current is this page?

The grade is for one exact copy of the source (3a70d563191c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement