Atlas / MCP servers / yutarop / ROS

ROSCAUTION

mcp/yutarop/ros-2

MCP server for ROS to control robots via topics, services, and actions.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
24 20r · 4w · 0d
Transport
stdio
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

ROS MCP

[](https://archestra.ai/mcp-catalog/yutarop__ros-mcp)

ROS MCP is a MCP server designed for controlling robots in ROS environments using natural language. It supports communication via ROS topics, services, and actions, and works with any ROS message type.

Demo

Test to see if ros topics, services, and actions can be used.

https://github.com/user-attachments/assets/61143c37-fb73-4998-9cbc-844d92ae61d9

Prompt used (Topic)

Open gazebo with TurtleBot3 and publish topic to move it.

Prompt used (Service)

Show me service list and call service to reset the world in Gazebo.

Prompt used (Action)

Show me action list and call action to move the TurtleBot3 forward for 1m.

Components

  • Socket Server (`socket_server.py`): A lightweight server that runs on localhost:8765 to handle GUI-related operations.

It receives instructions from the MCP server to launch tools such as Gazebo or rqt_graph on the local display.

It processes natural language input, maps it to ROS commands, and communicates with the socket server. To enable node communication between the MCP server and the local machine, both must be configured with the same ROS_DOMAIN_ID on the same local network.

Overview of MCP Tools

  • Topic Management: List, monitor, and publish to ROS2 topics
  • Node Control: List and inspect running ROS2 nodes
  • Service Interaction: Call ROS2 services with custom
  • Action Support: Send goals to ROS2 actions
  • GUI Integration: Launch ROS2 GUI tools via WebSocket server
  • Environment Debugging: Check ROS2 setup
Read from source at commit 3931425cd99aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add ros-mcp -- uvx ros-mcp
claude-desktop
{
  "mcpServers": {
    "ros-mcp": {
      "command": "uvx",
      "args": [
        "ros-mcp"
      ]
    }
  }
}
03

Exposed tools (24)

20 read · 4 write · 0 destructive.

ToolRiskDescription
call_ros2_serviceread
check_ros2_topic_hzreadDisplays the publishing frequency (Hz) of a given ROS 2 topic.
check_topic_statusreadChecks whether a specific ROS2 topic is actively publishing messages.
clean_all_ros2_nodesreadKills all currently running ROS 2 and Gazebo related processes to clean the environment.
debug_ros2_environmentreadDebug ROS 2 environment variables and setup.
echo_ros2_topicreadEcho messages from a ROS2 topic for a specified number of messages.
find_ros2_packagereadSearches for available ROS 2 packages that match a given keyword.
get_ros2_node_inforeadShows detailed information about a specific ROS 2 node.
get_topic_inforeadGet detailed information about a specific ROS2 topic.
launch_gazeboreadLaunch Gazebo simulation environment via WebSocket server.
launch_rqt_graphreadLaunch rqt_graph GUI tool via WebSocket server.
launch_rvizreadLaunch RViz2 GUI tool via WebSocket server.
launch_turtlebot3_empty_worldreadLaunch TurtleBot3 in empty world in Gazebo via WebSocket server.
launch_turtlebot3_worldreadLaunch TurtleBot3 world in Gazebo via WebSocket server.
launch_turtlesimreadLaunch turtlesim GUI application via WebSocket server.
list_ros2_actionsreadLists available ROS 2 actions.
list_ros2_nodesreadLists currently running ROS 2 nodes.
list_ros2_servicesreadLists available ROS 2 services.
list_topicsreadDisplays a list of currently accessible ROS2 topics.
publish_ros2_topicwritePublishes a message to a specific ROS 2 topic for a given duration (in seconds).
run_ros2_doctorwriteRuns ros2 doctor to check ROS 2 environment setup and issues.
run_ros2_executablewriteRuns a ROS 2 executable from a specified package.
send_ros2_action_goalwriteSends a goal to a ROS 2 action.
show_ros2_interfacereadShows the interface (definition) for a given ROS 2 message or service type.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
ros-general.py:21
os.environ.copy() ... WebSocket
Why it matters. reads secrets in the same file that sends data out

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 3931425cd99afull audit observations/trust-audit/mcp-server/yutarop__ros-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-083931425cd99aCAUTIONB89first audit
06

Questions

What is the ROS MCP server?

MCP server for ROS to control robots via topics, services, and actions.

What tools does ROS expose?

24 in total: 20 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ROS safe to connect to an agent?

With care. The audit graded it B (89/100) and found 1 thing worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does ROS need?

No credential environment variables were found in its source, so it appears to need none.

How does ROS run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as ros-mcp.

How current is this page?

The grade is for one exact copy of the source (3931425cd99a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement