CMLCAUTION
A Model Context Protocol (MCP) Server for Cisco Modeling Labs (CML)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mcptoplist.com/server/io.github.xorrkaz%2Fcml-mcp)
[](https://deepwiki.com/xorrkaz/cml-mcp)
mcp-name: io.github.xorrkaz/cml-mcp
Overview
cml-mcp brings the power of AI assistants to your network lab! This tool allows you to interact with Cisco Modeling Labs (CML) using natural language through AI applications like Claude Desktop, Claude Code, and Cursor.
Instead of clicking through menus or writing scripts, simply tell the AI what you want to do in plain English—like "Create a new lab with two routers and configure OSPF" or "Show me the running config on Router1"—and watch it happen automatically.
This is accomplished through the Model Context Protocol (MCP), a standard way for AI applications to interact with external tools and services. Think of it as giving your AI assistant a direct connection to your CML server.
Features
- Create Lab Topologies: Tools to create new labs and define network topologies from scratch or using full topology definitions.
- Query Status: Tools to retrieve detailed status information for labs, nodes, links, annotations, and the CML server itself.
- Control Labs and Nodes: Tools to start, stop, and wipe labs or individual nodes as needed.
- Manage CML Users and Groups: Tools to list, create, and delete local users and groups (requires admin privileges).
- Visual Annotations: Add visual elements (text, rectangles, ellipses, lines) to lab topologies for documentation and organization.
- Link Management: Connect nodes, configure link conditioning (bandwidth, latency, jitter, loss), and control link states.
- Packet Capture: Start, stop, and retrie
fada3631c737OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cml-mcp --env CML_PASSWORD=${CML_PASSWORD} --env PYATS_PASSWORD=${PYATS_PASSWORD} --env PYATS_AUTH_PASS=${PYATS_AUTH_PASS} -- uvx cml-mcp==0.32.1Exposed tools (36)
19 read · 10 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_interface_to_node | write | |
check_packet_capture_status | read | |
configure_cml_node | read | |
create_full_lab_topology | write | |
delete_annotation_from_lab | destructive | |
delete_cml_group | destructive | |
delete_cml_lab | destructive | |
delete_cml_node | destructive | |
delete_cml_user | destructive | |
download_lab_topology | read | |
get_all_links_for_lab | read | |
get_annotations_for_cml_lab | read | |
get_captured_packet_overview | read | |
get_cml_groups | read | |
get_cml_information | read | |
get_cml_labs | read | |
get_cml_licensing_details | read | |
get_cml_node_definitions | read | |
get_cml_statistics | read | |
get_cml_status | read | |
get_cml_users | read | |
get_console_log | read | |
get_interfaces_for_node | read | |
get_node_definition_detail | read | |
get_nodes_for_cml_lab | read | |
get_packet_capture_data | read | |
send_cli_command | write | |
start_cml_lab | write | |
start_cml_link | write | |
start_cml_node | write | |
stop_cml_lab | write | |
stop_cml_link | write | |
stop_cml_node | write | |
stop_packet_capture | write | |
wipe_cml_lab | destructive | |
wipe_cml_node | destructive |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (17)
" cannot be exfiltrated to a client-chosen server. This lets any client that can reach the port act as"
delete_annotation_from_lab, delete_cml_group, delete_cml_lab, delete_cml_node, delete_cml_user, wipe_cml_lab, wipe_cml_node
.envrc
.flake8
module = importlib.import_module(f"cml_mcp.tools.{module_name}")- Replace `<URL_OF_CML_SERVER>` with your actual CML server URL (e.g., `https://cml.mylab.com` or `https://10.10.20.50`)
The server will start and listen for plain HTTP connections at `http://0.0.0.0:9000`. For production or shared deployments, place a TLS-terminating reverse proxy (nginx, Caddy, etc.) in front of it be
- `CML_URL`: Your CML server address (e.g., `https://cml.example.com` or `https://10.10.20.50`)
export CML_URL=https://192.168.1.100
decoded = base64.b64decode(parts[1]).decode("utf-8")pyats_decoded = base64.b64decode(pyats_parts[1]).decode("utf-8")pyats_enable_decoded = base64.b64decode(pyats_enable_parts[1]).decode("utf-8")**Important:** ACLs only work in HTTP transport mode. If you're using stdio mode (direct connection), everyone has full access.
admin: {} # Admin has full access- **Cisco Modeling Labs (CML) 2.9 or later** - You'll need access to a running CML server with valid credentials
- **Run Commands on Devices:** Using [PyATS](https://developer.cisco.com/pyats/), MCP clients can execute commands on virtual devices within CML labs.
img/cml_mcp.gif
Gates applied: no_behavioural_pass.
fada3631c737full audit observations/trust-audit/mcp-server/xorrkaz__cml.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | fada3631c737 | CAUTION | B | 87 | first audit |
Questions
What is the CML MCP server?
A Model Context Protocol (MCP) Server for Cisco Modeling Labs (CML)
What tools does CML expose?
36 in total: 19 read-only, 10 that write, and 7 that can delete or overwrite (delete_annotation_from_lab, delete_cml_group, delete_cml_lab, delete_cml_node, delete_cml_user). Every one is listed on this page with its risk.
Is CML safe to connect to an agent?
With care. The audit graded it B (87/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does CML need?
It reads CML_PASSWORD, PYATS_AUTH_PASS and PYATS_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does CML run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as cml-mcp.
How current is this page?
The grade is for one exact copy of the source (fada3631c737), read on 2026-10-07. The repository is watched and re-audited when it changes.