Technitium Safe MCP
# Technitium Safe MCP
A focused, read-only MCP server for bounded reachability checks and explicit DNS lookups against allowlisted Technitium DNS servers. **Alpha:** tests are synthetic; compatibility with a live Technitium deployment is not certified.
## Install and run
Requires Python 3.11+, `uv`, and `dig`.
```sh
uv sync --extra test
export TECHNITIUM_SAFE_SERVERS=primary=dns-primary.example.invalid
uv run technitium-safe-mcp
```
The process speaks MCP over stdio and does not load `.env`. Server aliases/hosts and probe ports are allowlisted configuration.
## Safety
No Technitium API or mutation is exposed. Server count, port count/range, DNS names/types, subprocess duration, and output bytes are bounded. DNS names cannot begin with option syntax, and `dig` receives a fixed argument vector without a shell. Audit data is bounded but includes queried names; protect it accordingly. See [security design](docs/SECURITY-DESIGN.md).
## Verify
```sh
uv run --extra test pytest
uv run python -m compileall -q src tests
uv build
```
MIT © 2026 Ben Gauger.
TDQS
Scored across 2 tools
The two tools, server_health and dns_lookup, have clearly distinct purposes: one checks server status, the other performs DNS resolution. There is no overlap or ambiguity between them.
Both tool names follow a consistent lowercase_with_underscores pattern, using noun compounds ('server_health', 'dns_lookup'). The style is uniform and predictable, though a verb_noun pattern is not used, consistency is maintained.
With only 2 tools, the server is at the borderline of being too thin. While the tools are functional, they represent a minimal surface that may not justify a standalone MCP server for meaningful use.
For a DNS-related server, the tool surface is severely incomplete. Only health checking and basic DNS lookup are provided, with no support for managing zones, records, DNSSEC, or other essential DNS operations. This leaves major gaps for any typical DNS administration workflow.