Skip to main content
Glama

netops

Tools that give an AI agent the narrowest possible hands and usable eyes on network devices, and a configuration auditor that is useful without any agent at all. Four components live in this one repository; each is released on its own, under its own tag and its own maturity.

Start here

You want to

Use

What it takes

Check a FortiGate or ExtremeXOS configuration for known problems

netops-auditor

Python 3.13 and a configuration file; no device access for a first try

Let an AI agent troubleshoot the network without being able to change it

netops-helper

A read-only account on each device, a Docker host, and an MCP client

Let an agent make small changes that roll themselves back unless the result is confirmed

netops-admin

A dedicated write account and a check account per device, a one-time enrollment test on each device and firmware build, and the auditor

Try the auditor in one minute

No device, no credentials, no database. The auditor reads a sample FortiGate configuration that ships with its tests:

git clone https://github.com/radek-cerny-soukr/netops
cd netops/components/netops-auditor
PYTHONPATH=src:../netops-core/src python3 -m netops_auditor run \
  --platform fortios --tenant demo --device fw1 \
  --config tests/fixtures/secret_canary.conf

It reports nine findings, two of them high: administrative access on a WAN interface and a policy that references an object which does not exist. Each finding names the rule, the object and the line, and never quotes the configuration. The sample carries twenty marked fake secrets; none of them reaches the report, in text, with --json or with --sarif. Twelve of the FortiOS rules are hardening checks mapped to the CIS FortiGate 7.4.x Benchmark; the CIS mapping says what each one checks and which recommendations no rule covers.

On your own device, save the output of show on a FortiGate (or show configuration on an ExtremeXOS switch, with --platform exos) to a file and pass it with --config. To track change over time, add --store audit.db; accept the current findings once with --baseline-accept --accepted-by <name> --note <text>, and later runs report them as open-known and anything that appears as new. Without the repository, pip install netops-auditor (Python 3.13) puts the same command on the path as netops-auditor. The rule catalogue, suppressions with expiry, collection straight from the device and the read-only MCP surface are described in the auditor README.

Audit configuration backups in CI

If your configuration backups live in a Git repository, the auditor runs as a GitHub Action with no device, credential or network access and uploads its findings to code scanning as SARIF:

- id: audit
  uses: radek-cerny-soukr/netops/components/netops-auditor@871dbbd7ad3ace53dce3262a71ed0097ea3d63a0 # netops-auditor 0.2.8
  with:
    platform: fortios
    configs: |
      backups/**/*.conf
- uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
  with:
    sarif_file: ${{ steps.audit.outputs.sarif-file }}

The workflow needs security-events: write. Inputs, outputs and the SARIF mapping are in the auditor README.

An agent that can look but not touch

netops-helper is an MCP server with a fixed catalogue of named diagnostic queries per platform. The agent chooses a query and its parameters; it never writes a command line, and there is no write tool. The server runs in an isolated container on a runner host that the client reaches over pinned SSH, host-side egress rules are applied before the container starts, and every device is reached with an account the device itself keeps read-only. Setup is nine steps: installation.

An agent that can change a little, and undo it

netops-admin changes one object of a supported table per request. Before writing it arms a rollback on the device itself (a FortiOS automation stitch or an ExtremeXOS Universal Port Manager timer), then compares the result with its prediction through a separate check account, and disarms the rollback only when everything matches. If the check cannot be completed, the timer on the device restores the previous state on its own. Six profiles: FortiOS addresses, address group members and DHCP reservations; ExtremeXOS VLANs, port display strings and port VLAN membership. Two read-only commands help before the first change: netops-admin doctor reports every condition a device still lacks, and netops-admin preview shows the plan of a request and every reason it would be refused, without changing anything. Start here.

Related MCP server: SSH MCP Server

Components

Component

What it does

Released

netops-auditor

Configuration audit; collects the configuration from the device itself or reads a file

netops-auditor/v0.2.8 (2026-09-26)

netops-helper

Read-only MCP server for bounded network troubleshooting

netops-helper/v0.3.7 (2026-09-26)

netops-admin

Bounded device changes, mandatory rollback enrollment and predicted/observed audit

netops-admin/v0.2.3 (2026-09-26)

netops-core

Shared access layer the other components build on: inventory, credential store, host key trust, SSH transport, audit records

netops-core/v0.2.5 (2026-09-26)

Every release carries a source archive, an SBOM, a checksum manifest and a Sigstore signature. All four are also published on PyPI (pip install netops-auditor, pip install netops-admin; pip install netops-helper installs only the helper's client-side proxy, its server runs as a container image). Earlier versions keep their release pages and tags; the table above links the current one. How releases are cut and signed, and what the repository gate enforces, is in the documentation map.

What has been tested on real devices

FortiOS (7.6.x and 8.0.0) and ExtremeXOS (33.7.x) have been exercised end to end against real devices. The helper's Arista EOS, Junos, Cisco IOS, IOS-XE and NX-OS catalogues have been run query by query against the vendors' virtual images (cEOS and vEOS 4.36.1F, vJunos-switch 26.2R1.7, IOL 17.18.2, IOSv 15.9(3)M12, IOSvL2 15.2, Nexus 9300v and 9500v 9.3(12)) and ExtremeXOS also against EXOS-VM 33.6.1.14; no physical device of those three vendors has been measured yet. Cisco IOS-XE and classic IOS need netops-core 0.2.5 and netops-helper 0.3.7, see live lab measurements. Verified platform support states, per platform, firmware, transport, authentication and account privilege, what was measured and what was not.

Security

Read SECURITY.md before deploying anything from here, and the security model of the component you are deploying. Report a vulnerability privately through GitHub Security Advisories; never include live credentials, addresses, configurations, or command output.

MIT licensed.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables secure remote access operations through SSH, SFTP, rsync, VPN, and tunneling with enterprise-grade policy enforcement and audit logging. Provides AI assistants with secure, policy-driven access to remote systems while maintaining comprehensive audit trails and zero-trust security.
    1
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    Enables remote server administration via SSH, supporting command execution, SFTP file transfers, and multi-profile management. It features security safeguards like destructive command detection and audit logging to ensure safe interaction with remote Linux/Unix environments.
    17
    10 npm
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to execute SSH commands on network devices using natural language, supporting multiple vendors and authentication methods for automated network management.
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables agents to access network device management interfaces via SSH, keeping credentials on the server side. Supports both interactive terminal sessions and command execution on devices like Huawei VRP, MikroTik, and OpenWrt.
    1
    -