Atlas / MCP servers / xorrkaz / CML

CMLCAUTION

mcp/xorrkaz/cml

A Model Context Protocol (MCP) Server for Cisco Modeling Labs (CML)

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
36 19r · 10w · 7d
Transport
stdio
License
BSD-2-Clause
Stars
72
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mcptoplist.com/server/io.github.xorrkaz%2Fcml-mcp)

[](https://deepwiki.com/xorrkaz/cml-mcp)

mcp-name: io.github.xorrkaz/cml-mcp

Overview

cml-mcp brings the power of AI assistants to your network lab! This tool allows you to interact with Cisco Modeling Labs (CML) using natural language through AI applications like Claude Desktop, Claude Code, and Cursor.

Instead of clicking through menus or writing scripts, simply tell the AI what you want to do in plain English—like "Create a new lab with two routers and configure OSPF" or "Show me the running config on Router1"—and watch it happen automatically.

This is accomplished through the Model Context Protocol (MCP), a standard way for AI applications to interact with external tools and services. Think of it as giving your AI assistant a direct connection to your CML server.

Features

  • Create Lab Topologies: Tools to create new labs and define network topologies from scratch or using full topology definitions.
  • Query Status: Tools to retrieve detailed status information for labs, nodes, links, annotations, and the CML server itself.
  • Control Labs and Nodes: Tools to start, stop, and wipe labs or individual nodes as needed.
  • Manage CML Users and Groups: Tools to list, create, and delete local users and groups (requires admin privileges).
  • Visual Annotations: Add visual elements (text, rectangles, ellipses, lines) to lab topologies for documentation and organization.
  • Link Management: Connect nodes, configure link conditioning (bandwidth, latency, jitter, loss), and control link states.
  • Packet Capture: Start, stop, and retrie
Read from source at commit fada3631c737OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add cml-mcp --env CML_PASSWORD=${CML_PASSWORD} --env PYATS_PASSWORD=${PYATS_PASSWORD} --env PYATS_AUTH_PASS=${PYATS_AUTH_PASS} -- uvx cml-mcp==0.32.1
03

Exposed tools (36)

19 read · 10 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_interface_to_nodewrite
check_packet_capture_statusread
configure_cml_noderead
create_full_lab_topologywrite
delete_annotation_from_labdestructive
delete_cml_groupdestructive
delete_cml_labdestructive
delete_cml_nodedestructive
delete_cml_userdestructive
download_lab_topologyread
get_all_links_for_labread
get_annotations_for_cml_labread
get_captured_packet_overviewread
get_cml_groupsread
get_cml_informationread
get_cml_labsread
get_cml_licensing_detailsread
get_cml_node_definitionsread
get_cml_statisticsread
get_cml_statusread
get_cml_usersread
get_console_logread
get_interfaces_for_noderead
get_node_definition_detailread
get_nodes_for_cml_labread
get_packet_capture_dataread
send_cli_commandwrite
start_cml_labwrite
start_cml_linkwrite
start_cml_nodewrite
stop_cml_labwrite
stop_cml_linkwrite
stop_cml_nodewrite
stop_packet_capturewrite
wipe_cml_labdestructive
wipe_cml_nodedestructive
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (17)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/cml_mcp/settings.py:85
" cannot be exfiltrated to a client-chosen server. This lets any client that can reach the port act as"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_annotation_from_lab, delete_cml_group, delete_cml_lab, delete_cml_node, delete_cml_user, wipe_cml_lab, wipe_cml_node
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.envrc
.envrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.flake8
.flake8
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_border_style.py:179
module = importlib.import_module(f"cml_mcp.tools.{module_name}")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
INSTALLATION.md:110
- Replace `<URL_OF_CML_SERVER>` with your actual CML server URL (e.g., `https://cml.mylab.com` or `https://10.10.20.50`)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
INSTALLATION.md:354
The server will start and listen for plain HTTP connections at `http://0.0.0.0:9000`. For production or shared deployments, place a TLS-terminating reverse proxy (nginx, Caddy, etc.) in front of it be
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:63
- `CML_URL`: Your CML server address (e.g., `https://cml.example.com` or `https://10.10.20.50`)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/README.md:95
export CML_URL=https://192.168.1.100
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/cml_mcp/tools/middleware.py:299
decoded = base64.b64decode(parts[1]).decode("utf-8")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/cml_mcp/tools/middleware.py:321
pyats_decoded = base64.b64decode(pyats_parts[1]).decode("utf-8")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/cml_mcp/tools/middleware.py:345
pyats_enable_decoded = base64.b64decode(pyats_enable_parts[1]).decode("utf-8")
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
INSTALLATION.md:543
**Important:** ACLs only work in HTTP transport mode. If you're using stdio mode (direct connection), everyone has full access.
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
INSTALLATION.md:612
admin: {}  # Admin has full access
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
INSTALLATION.md:35
- **Cisco Modeling Labs (CML) 2.9 or later** - You'll need access to a running CML server with valid credentials
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:27
- **Run Commands on Devices:** Using [PyATS](https://developer.cisco.com/pyats/), MCP clients can execute commands on virtual devices within CML labs.
Why it matters. remote text is to be obeyed as instructions
INFOInventory / provenance · inv.oversize · CWE-1104
img/cml_mcp.gif
img/cml_mcp.gif
Why it matters. 27314042 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fada3631c737full audit observations/trust-audit/mcp-server/xorrkaz__cml.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fada3631c737CAUTIONB87first audit
06

Questions

What is the CML MCP server?

A Model Context Protocol (MCP) Server for Cisco Modeling Labs (CML)

What tools does CML expose?

36 in total: 19 read-only, 10 that write, and 7 that can delete or overwrite (delete_annotation_from_lab, delete_cml_group, delete_cml_lab, delete_cml_node, delete_cml_user). Every one is listed on this page with its risk.

Is CML safe to connect to an agent?

With care. The audit graded it B (87/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does CML need?

It reads CML_PASSWORD, PYATS_AUTH_PASS and PYATS_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does CML run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as cml-mcp.

How current is this page?

The grade is for one exact copy of the source (fada3631c737), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement