NetOps Helper
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@NetOps HelperShow interface summary for device 'core'."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
netops
Tools that give an AI agent the narrowest possible hands and usable eyes on network devices, and a configuration auditor that is useful without any agent at all. Four components live in this one repository; each is released on its own, under its own tag and its own maturity.
Start here
You want to | Use | What it takes |
Check a FortiGate or ExtremeXOS configuration for known problems | Python 3.13 and a configuration file; no device access for a first try | |
Let an AI agent troubleshoot the network without being able to change it | A read-only account on each device, a Docker host, and an MCP client | |
Let an agent make small changes that roll themselves back unless the result is confirmed | A dedicated write account and a check account per device, a one-time enrollment test on each device and firmware build, and the auditor |
Try the auditor in one minute
No device, no credentials, no database. The auditor reads a sample FortiGate configuration that ships with its tests:
git clone https://github.com/radek-cerny-soukr/netops
cd netops/components/netops-auditor
PYTHONPATH=src:../netops-core/src python3 -m netops_auditor run \
--platform fortios --tenant demo --device fw1 \
--config tests/fixtures/secret_canary.confIt reports nine findings, two of them high: administrative access on a WAN interface and a policy that references an object which does not exist. Each finding names the rule, the object and the line, and never quotes the configuration. The sample carries twenty marked fake secrets; none of them reaches the report, in text, with --json or with --sarif. Twelve of the FortiOS rules are hardening checks mapped to the CIS FortiGate 7.4.x Benchmark; the CIS mapping says what each one checks and which recommendations no rule covers.
On your own device, save the output of show on a FortiGate (or show configuration on an ExtremeXOS switch, with --platform exos) to a file and pass it with --config. To track change over time, add --store audit.db; accept the current findings once with --baseline-accept --accepted-by <name> --note <text>, and later runs report them as open-known and anything that appears as new. Without the repository, pip install netops-auditor (Python 3.13) puts the same command on the path as netops-auditor. The rule catalogue, suppressions with expiry, collection straight from the device and the read-only MCP surface are described in the auditor README.
Audit configuration backups in CI
If your configuration backups live in a Git repository, the auditor runs as a GitHub Action with no device, credential or network access and uploads its findings to code scanning as SARIF:
- id: audit
uses: radek-cerny-soukr/netops/components/netops-auditor@871dbbd7ad3ace53dce3262a71ed0097ea3d63a0 # netops-auditor 0.2.8
with:
platform: fortios
configs: |
backups/**/*.conf
- uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
sarif_file: ${{ steps.audit.outputs.sarif-file }}The workflow needs security-events: write. Inputs, outputs and the SARIF mapping are in the auditor README.
An agent that can look but not touch
netops-helper is an MCP server with a fixed catalogue of named diagnostic queries per platform. The agent chooses a query and its parameters; it never writes a command line, and there is no write tool. The server runs in an isolated container on a runner host that the client reaches over pinned SSH, host-side egress rules are applied before the container starts, and every device is reached with an account the device itself keeps read-only. Setup is nine steps: installation.
An agent that can change a little, and undo it
netops-admin changes one object of a supported table per request. Before writing it arms a rollback on the device itself (a FortiOS automation stitch or an ExtremeXOS Universal Port Manager timer), then compares the result with its prediction through a separate check account, and disarms the rollback only when everything matches. If the check cannot be completed, the timer on the device restores the previous state on its own. Six profiles: FortiOS addresses, address group members and DHCP reservations; ExtremeXOS VLANs, port display strings and port VLAN membership. Two read-only commands help before the first change: netops-admin doctor reports every condition a device still lacks, and netops-admin preview shows the plan of a request and every reason it would be refused, without changing anything. Start here.
Related MCP server: SSH MCP Server
Components
Component | What it does | Released |
Configuration audit; collects the configuration from the device itself or reads a file |
| |
Read-only MCP server for bounded network troubleshooting |
| |
Bounded device changes, mandatory rollback enrollment and predicted/observed audit |
| |
Shared access layer the other components build on: inventory, credential store, host key trust, SSH transport, audit records |
|
Every release carries a source archive, an SBOM, a checksum manifest and a Sigstore signature. All four are also published on PyPI (pip install netops-auditor, pip install netops-admin; pip install netops-helper installs only the helper's client-side proxy, its server runs as a container image). Earlier versions keep their release pages and tags; the table above links the current one. How releases are cut and signed, and what the repository gate enforces, is in the documentation map.
What has been tested on real devices
FortiOS (7.6.x and 8.0.0) and ExtremeXOS (33.7.x) have been exercised end to end against real devices. The helper's Arista EOS, Junos, Cisco IOS, IOS-XE and NX-OS catalogues have been run query by query against the vendors' virtual images (cEOS and vEOS 4.36.1F, vJunos-switch 26.2R1.7, IOL 17.18.2, IOSv 15.9(3)M12, IOSvL2 15.2, Nexus 9300v and 9500v 9.3(12)) and ExtremeXOS also against EXOS-VM 33.6.1.14; no physical device of those three vendors has been measured yet. Cisco IOS-XE and classic IOS need netops-core 0.2.5 and netops-helper 0.3.7, see live lab measurements. Verified platform support states, per platform, firmware, transport, authentication and account privilege, what was measured and what was not.
Security
Read SECURITY.md before deploying anything from here, and the security model of the component you are deploying. Report a vulnerability privately through GitHub Security Advisories; never include live credentials, addresses, configurations, or command output.
MIT licensed.
This server cannot be deployed
Maintenance
Related MCP Connectors
Scoped, audited SSH exec, sessions, and SFTP on your saved servers without exposing credentials
- emisarOAuthdev.emisar
Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.
Securely control computers you explicitly pair through files, terminals, processes, screenshots, desktop UI/input, clipboard, browser automation, diagnostics, and document tools.
Issue, rotate and revoke scoped API-key passes for 25+ providers — the agent never sees a real key
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables secure remote access operations through SSH, SFTP, rsync, VPN, and tunneling with enterprise-grade policy enforcement and audit logging. Provides AI assistants with secure, policy-driven access to remote systems while maintaining comprehensive audit trails and zero-trust security.1Apache 2.0
- AlicenseAqualityCmaintenanceEnables remote server administration via SSH, supporting command execution, SFTP file transfers, and multi-profile management. It features security safeguards like destructive command detection and audit logging to ensure safe interaction with remote Linux/Unix environments.1710 npmMIT
- FlicenseNot gradedqualityDmaintenanceEnables AI assistants to execute SSH commands on network devices using natural language, supporting multiple vendors and authentication methods for automated network management.-
- FlicenseNot gradedqualityCmaintenanceEnables agents to access network device management interfaces via SSH, keeping credentials on the server side. Supports both interactive terminal sessions and command execution on devices like Huawei VRP, MikroTik, and OpenWrt.1-