ROS 2BLOCK
ROS2 MCP: the MCP server that lets AI agents see, understand and operate ROS 2 robots. MPL-2.0.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://discord.gg/9aSw6HbUaw) [](https://hub.docker.com/mcp/server/ros2/overview) [](LICENSE) [](https://wisevision.tech) [](https://wisevision.tech/docs/)
ROS2 MCP is an open-source (MPL-2.0) Model Context Protocol (MCP) server for ROS 2 Humble and Jazzy, written in Python. It lets AI tools such as Claude, Cursor and Codex list, subscribe to, publish on and call ROS 2 topics, services and actions over stdio (or SSE). It is listed in Docker's official MCP catalog as `mcp/ros2`.
Every tool is free and open source, including multi-topic subscribe/publish, map-to-image and point-cloud bird's-eye view.
🌐 Website: wisevision.tech · 📚 Documentation: wisevision.tech/docs
🔒 Security: read-only mode
An agent connected to a real robot can move it. Start the server in read-only mode to let the agent observe but not act:
ROS2_MCP_READONLY=1 uv run mcp_ros_2_server # env var uv run mcp_ros_2_server --read-only # or CLI flag docker run -i --rm -e ROS2_MCP_READONLY=1 mcp/ros2
In read-only mode the tools that change robot state are not registered at all: they do not appear in list_tools, and calling one returns an Unknown tool error. The hidden tools are: ros2_topic_publish, ros2_publish_multiple_topics, ros2_service_call, ros2_send_action_goal, `ros2_ca
e4ee2af4cdafOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ros2:latest -- docker run -i --rm docker.io/mcp/ros2:latest:None
Trust audit
BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
preact ~ react
- ROS 2 installed on your system (humble or later). [Get ROS 2](https://docs.ros.org/en/humble/Installation.html)
- Docker installed and running. [Get Docker](https://docs.docker.com/get-docker/)
- Visual Studio Code installed. [Get Visual Studio Code](https://code.visualstudio.com/Download)
- ROS 2 installed on your system (humble or later). [Get ROS 2](https://docs.ros.org/en/humble/Installation.html)
- Docker installed and running. [Get Docker](https://docs.docker.com/get-docker/)
module = importlib.import_module(f"{pkg}.msg")module = importlib.import_module(f"{pkg}.msg")module = importlib.import_module(f"{pkg}.srv")module = importlib.import_module(f"{pkg}.action")module = importlib.import_module(f"{pkg}.srv")"-----BEGIN OPENSSH PRIVATE KEY-----",
"-----BEGIN RSA PRIVATE KEY-----",
.licenserc.json
.pre-commit-config.yaml
"src/content/docs/../../../.github/workflows/x.yml",
["import Evil from '../../../../src/components/Evil.astro';"],
"[x](https://1.2.3.4/)",
return list(bytes.fromhex(hex_clean))
const bin = atob(b64);
decoded_bytes = base64.b64decode(msg_1["data"])
decoded_bytes = base64.b64decode(msg_2["data"])
raw = base64.b64decode(image_content.data)
preact, three, @types/node, @types/three, esbuild, typescript
Gates applied: no_behavioural_pass.
e4ee2af4cdaffull audit observations/trust-audit/mcp-server/wise-vision__ros-2-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | e4ee2af4cdaf | BLOCK | F | 44 | first audit |
Questions
What is the ROS 2 MCP server?
ROS2 MCP: the MCP server that lets AI agents see, understand and operate ROS 2 robots. MPL-2.0.
Is ROS 2 safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (44/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does ROS 2 need?
No credential environment variables were found in its source, so it appears to need none.
How does ROS 2 run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as ros2-viewer-app.
How current is this page?
The grade is for one exact copy of the source (e4ee2af4cdaf), read on 2026-10-07. The repository is watched and re-audited when it changes.