Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
NET_MCP_CONFIGNoPath to config file
BGPROUTES_API_KEYNobgproutes.io API key
CLOUDFLARE_API_TOKENNoCloudflare Radar API token (required for BGP security tools like hijacks and leaks)
NET_MCP_DNS_RESOLVERNoDefault DNS resolver IP1.1.1.1
NET_MCP_MRT_CACHE_DIRNoMRT file download/cache directory/tmp/net-mcp/mrt
NET_MCP_MRT_MAX_CACHE_GBNoMax cache size before evicting old files10
NET_MCP_DEFAULT_COLLECTORNoDefault RIPE RIS collector IDrrc00

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
logging
{}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}

Tools

Functions exposed to the LLM to take actions

NameDescription
dns_lookupA

Query DNS records for a domain with DNSSEC validation status.

Returns the requested records along with whether DNSSEC is enabled and whether validation passes. Use this to check DNS configuration and DNSSEC health for any domain.

If the resolver returns SERVFAIL (which a validating resolver does when DNSSEC validation fails), this re-queries with the CD (Checking Disabled) bit to distinguish a genuine DNSSEC failure from an unrelated server error.

dns_traceA

Trace DNS resolution from root to authoritative nameservers.

Walks the actual delegation chain (zone cuts) from the root down, showing each zone's nameservers and DNSSEC signing status. Labels that are not their own zone (e.g. 'www' as a record inside a parent zone) are skipped so they are not mistaken for a broken delegation.

This traces the delegation/chain-of-trust structure, which is independent of any particular record type.

A DNSSEC break is reported when a zone is signed (publishes DNSKEY) but its parent publishes no DS record for it — an "island of security" that breaks the chain of trust.

rpki_validateA

Validate a BGP route origin against RPKI ROAs.

Checks whether a given prefix + origin ASN pair is VALID, INVALID, or NOT_FOUND in RPKI. Returns matching ROAs and details about any max-length issues.

Queries RIPEstat first for full ROA details. If RIPEstat returns NOT_FOUND, Cloudflare Radar is consulted to confirm the status. If RIPEstat is unavailable entirely, falls back to Cloudflare Radar (status only, no ROA details).

rpki_roa_lookupA

Look up RPKI ROAs for a prefix or ASN.

Returns Route Origin Authorizations matching the query, including max-length, trust anchor, and ASN. Useful for understanding what routes an AS is authorized to originate or what ROAs cover a prefix.

For an ASN query only the first 50 announced prefixes are scanned (large ASes announce thousands); note says when that cap applied. Data source: RIPEstat. error is set if RIPEstat could not be reached.

rpki_aspa_lookupA

Look up RPKI ASPA (AS Provider Authorization) objects.

ASPA defines which upstream providers an AS authorizes for its route announcements. This is a newer RPKI extension that helps prevent route leaks by validating AS path relationships.

Use 'customer' role to see who an AS has authorized as providers. Use 'provider' role to see which ASes have authorized a given AS as their provider.

At most 200 objects are returned (an unfiltered snapshot is the whole dataset); total reports the real count. Requires a Cloudflare Radar API token (CLOUDFLARE_API_TOKEN); error explains if it is missing.

rpki_aspa_changesB

Track changes to RPKI ASPA objects over time.

Shows when ASPA objects were added, removed, or modified. Useful for monitoring provider authorization changes and detecting potential routing policy shifts.

Requires Cloudflare Radar API token (CLOUDFLARE_API_TOKEN).

bgp_route_lookupA

Look up current BGP routes for a prefix from global routing tables.

Returns BGP route entries including origin AS, AS path, communities, and peer information. Optionally filter by a specific RIPE RIS collector to get a regional perspective (e.g. RRC06 for Tokyo, RRC15 for Sao Paulo).

Source order: RIPEstat looking glass, then Cloudflare Radar (if a token is configured), then bgproutes.io (if a key is configured), then the bgp.tools full table only if RIPEstat itself failed. At most 20 routes are returned; total reports how many were observed. Use ris_collectors first to pick a collector ID for a regional view.

ris_collectorsA

List RIPE RIS route collectors with location, peer counts, and status.

Use this to understand where BGP data is collected from. Each collector is at a specific IXP or operates as a multihop peer. Collectors with more full-feed peers provide better global visibility.

Common use cases:

  • Need Asian perspective? Use RRC06 (Tokyo) or RRC23 (Singapore)

  • Need US perspective? Use RRC11 (NYC), RRC14 (Palo Alto), RRC16 (Miami)

  • Need South American view? Use RRC15 (Sao Paulo) or RRC24 (Montevideo)

  • Need African view? Use RRC19 (Johannesburg)

  • Need best global visibility? Use RRC00 or RRC25 (multihop, most peers)

mrt_searchA

Find available MRT data files for a given time range and collector.

Use this to discover what historical BGP data is available before calling bgp_historical_lookup. Returns URLs, sizes, and timestamps for each MRT file.

RIB dumps (bview) are snapshots of the full routing table, taken every 8 hours at 00:00, 08:00, 16:00 UTC. Use these to see what the routing table looked like at a specific time.

Update files contain BGP announcements and withdrawals, archived every 5 minutes. Use these to see route changes during an incident.

bgp_historical_lookupA

Look up historical BGP routes for a prefix from MRT archive data.

Downloads and parses MRT files from RIPE RIS to show what BGP routes existed for a prefix at a specific point in time (rib) or what route changes occurred during a time window (update).

For RIB lookups: shows all routes for the prefix at that snapshot. For update lookups: shows announcements and withdrawals during the window.

Note: RIB files are ~400MB and take 30-60s to download and parse. Update files are ~3MB and parse in seconds. Prefer 'update' for narrow time windows and 'rib' for full routing state.

bgp_prefix_originA

Find which AS(es) originate a given prefix.

Returns the distinct origin ASN(s) with AS names. Cloudflare Radar (pfx2as) is queried first because it also reports per-origin RPKI status; if it is not configured or returns nothing, RIPEstat routing-status is used (no rpki_status). error is set only when every source failed, so an empty origins with no error means the prefix is genuinely not announced.

bgp_asn_infoA

Get information about an Autonomous System.

Returns the AS name, announced prefixes (v4 and v6), upstream providers, and total prefix count. Use this to understand an AS's footprint on the Internet.

bgp_hijacksA

Search for BGP origin hijack events.

Detects when an AS announces prefixes it is not authorized to originate (based on RPKI, IRR, and historical data). Each event includes a confidence score, the hijacker and victim ASNs, affected prefixes, and duration.

Requires Cloudflare Radar API token (CLOUDFLARE_API_TOKEN).

bgp_leaksA

Search for BGP route leak events.

Detects when an AS improperly propagates routes it received from one peer to another peer (violating expected routing policy). Each event includes the leaking AS, affected origin/prefix counts, and detection timestamps.

Requires Cloudflare Radar API token (CLOUDFLARE_API_TOKEN).

irr_route_lookupA

Look up IRR route objects for a prefix or origin ASN.

Queries Internet Routing Registries to find what route objects exist. Compare with RPKI (rpki_validate) and actual BGP (bgp_prefix_origin) to identify inconsistencies between what's registered, what's authorized, and what's actually announced.

The query must be an ASN ('AS13335' or bare '13335', normalised to 'AS13335') or an IP prefix/address (normalised to CIDR form); anything else is rejected. Each returned object reports both registry (the server it was fetched from) and source (the registry that authoritatively holds it), which differ for objects mirrored by RADB. Results are capped at 200 objects; total is the uncapped count. If a registry cannot be reached, error is set and the objects from the remaining registries are still returned.

irr_autnumA

Look up an aut-num object in IRR databases.

Returns the AS name, description, import/export policies (capped at 20 lines each), and organisation handle. Useful for understanding an AS's registered routing policy. The ASN may be given as 'AS13335' or a bare '13335'.

One object is returned per queried registry: the first aut-num object in that registry's response whose aut-num matches the requested ASN. registry is the server queried and source is the object's own source: attribute (they differ for mirrored objects). If a registry cannot be reached, error is set and results from the remaining registries are still returned.

irr_as_set_expandA

Expand an AS-SET into its member ASNs.

Recursively resolves an AS-SET: reads its members/mp-members attributes, follows any nested AS-SET members, and collects every member ASN. Useful for understanding the customer cone of a transit provider or what ASNs are in a peering group. Uses RADB by default because it mirrors objects from many registries.

The name must look like an RPSL set ('AS-...', 'RS-...', or a hierarchical 'AS13335:AS-...' name); bare ASNs are rejected. Recursion is bounded (6 levels deep, 20000 ASNs) to keep very large transit cones from running unbounded. If any lookup during expansion fails, error is set and the members collected so far are returned.

peeringdb_networkA

Look up a network in PeeringDB by ASN.

Returns peering policy, network type, IRR as-set, website, and every IXP where the network peers (with LAN addresses, port speeds, and route-server participation). Useful for understanding a network's peering footprint and how to reach it.

Data source: PeeringDB (two requests: the net record, then its netixlan entries). A null network with no error means the ASN has no PeeringDB entry; if error is set the lookup failed upstream and the record may be missing or partial (e.g. exchanges empty).

peeringdb_ixA

Search for Internet Exchange Points (IXPs) in PeeringDB.

Returns exchange name, location, website, and the number of connected networks (total_members) for every match. With include_members, the member list (ASN, LAN addresses, port speed, route-server flag) is fetched for ONE exchange only: the exact name match if there is one, otherwise the first result. That entry has members_included=true. To get members of a specific exchange, query by its numeric IX id.

Data source: PeeringDB. A name search that returns nothing falls back to a city search. total_members comes from PeeringDB's net_count and costs no extra requests. If error is set the search or the member fetch failed upstream and the payload may be empty or partial.

peeringdb_facilityA

Search for data center facilities in PeeringDB.

Returns facility name, location, website, how many networks are present (networks_count), and how many IXPs are reachable there (exchanges_count). Useful for understanding colocation options and where networks can physically interconnect.

Data source: PeeringDB, one request (two if the name search is empty and falls back to a city search). Counts come from PeeringDB's own net_count / ix_count fields, so no per-facility lookups are made. If error is set the search failed upstream and facilities is empty.

subnet_infoA

Get detailed information about an IP prefix or address.

Returns network/broadcast addresses, netmask, host count, and classification (private, global, multicast, etc.). Works with both IPv4 and IPv6.

subnet_splitA

Split an IP prefix into smaller subnets.

For example, split 10.0.0.0/24 into /26s to get 4 subnets. Works with both IPv4 and IPv6.

ip_containsA

Check if an IP address or prefix is within a network.

Answers questions like 'is 10.5.5.1 in 10.0.0.0/8?' or 'is 192.168.1.0/24 inside 192.168.0.0/16?'.

prefix_overlapA

Check if two IP prefixes overlap.

Returns the relationship: disjoint, one contains the other, or equal. Useful for detecting conflicts in IP allocation or routing policy.

supernet_aggregateA

Try to aggregate a list of IP prefixes into a supernet.

Given contiguous subnets, returns the smallest covering supernet. Useful for summarizing route announcements.

bogon_checkA

Check if an IP address or prefix is a bogon (reserved/non-routable).

Tests against all IANA reserved ranges including RFC 1918 (private), RFC 6598 (CGNAT), RFC 5737 (documentation), multicast, loopback, link-local, and other special-use prefixes.

A bogon appearing in the global routing table usually indicates a misconfiguration or a hijack attempt.

local_pingA

Ping a host from the local machine.

Sends ICMP echo requests and reports round-trip time, packet loss, and latency statistics. Does not require admin privileges. Invalid hosts are reported in the result's error field rather than raised.

local_tracerouteA

Trace the network path to a host from the local machine.

Shows each hop along the route with latency. Uses UDP probes by default (no admin required). On macOS/Linux uses traceroute, on Windows uses tracert. If the trace exceeds its time budget the partial output collected so far is returned with returncode 124.

local_mtrA

Run mtr (My Traceroute) combining ping and traceroute.

Shows per-hop packet loss and latency statistics. Requires mtr to be installed. May require admin/sudo for raw ICMP sockets on some systems — if permission is denied, the error will say so.

local_digA

Run dig on the local machine for DNS lookups.

Unlike dns_lookup (which uses dnspython), this runs the actual dig binary and returns raw output including query time, server used, and all sections. Useful for seeing exactly what a real resolver returns. Falls back to nslookup when dig is not installed. Does not require admin privileges.

record_type must be a bare mnemonic (1-10 letters/digits); dig options such as '+trace' or '-x' are rejected and reported in the result's error field.

local_interfacesA

Show network interfaces and their IP addresses on the local machine.

Returns interface names, IP addresses, subnet masks, and status. Uses ifconfig on macOS, ip addr on Linux, ipconfig on Windows. Does not require admin privileges.

local_routesA

Show the local routing table.

Displays all routes including default gateway, connected networks, and static routes. Uses netstat -rn on macOS, ip route on Linux, route print on Windows. Does not require admin privileges.

local_connectionsA

Show active network connections and listening ports.

Displays TCP/UDP sockets with local/remote addresses and state. Uses ss on Linux (netstat as a fallback) and netstat on macOS and Windows. ss filters by state natively; netstat on macOS, Windows and older Linux has no state filter, so for 'listen' and 'established' this tool filters the output lines itself after the command runs and says so in the note field. Does not require admin privileges (PIDs may require admin).

local_arpA

Show the ARP table (IP-to-MAC address mappings).

Displays cached ARP entries for the local network. Useful for seeing what hosts are on the same L2 segment. Does not require admin privileges.

local_whoisA

Run a whois lookup from the local machine.

Queries the appropriate whois server for domain registration, IP allocation, or ASN information. Does not require admin privileges.

local_curlA

Make an HTTP request from the local machine using curl.

Useful for testing connectivity, checking HTTP headers, TLS certificates, and response codes from the local network perspective. Output is capped at 10,000 characters (the note field says when it was truncated). Does not require admin privileges.

curl runs with -q (ignores ~/.curlrc) and -g (no URL globbing, so brackets and braces in the URL are literal and cannot fan out into many requests). Only http:// and https:// URLs are accepted.

Disabled by default. When enabled via allow_active_tools this tool deliberately does NOT block private, loopback, link-local or cloud metadata addresses (for example 127.0.0.1, 10.0.0.0/8 or 169.254.169.254): reaching internal endpoints from this host is part of its purpose as a local diagnostic, and operators who enable it accept that trade-off.

local_nmapA

Run an nmap TCP connect scan on a target.

Uses TCP connect scan (-sT, no admin needed) with host discovery skipped (-Pn) and reports only open ports. SYN scans and OS detection require root and are not used. Nmap must be installed separately.

Targets are limited to one host or a CIDR block of at most 256 addresses (/24 for IPv4, /120 for IPv6): with -Pn nmap probes every address in the block, so a larger prefix would exhaust the 120 s time budget without finishing. nmap's octet-range (10.0.0-255.1), wildcard and comma-list target syntax is rejected for the same reason; scan several small blocks instead. Rejected inputs are reported in the result's error field.

Disabled by default (it can scan arbitrary internal hosts from this machine). Enable via allow_active_tools in config.

local_netstat_statsA

Show network protocol statistics (TCP, UDP, ICMP counters).

Displays packet counts, error rates, retransmissions, and other protocol-level statistics. Useful for diagnosing network health issues. Does not require admin privileges.

local_public_ipA

Get the public IP address of the local machine.

Queries external services (ifconfig.me, ipify, icanhazip) in turn until one answers, identifying itself with the net-mcp User-Agent. Useful for verifying NAT, VPN, or proxy configuration. Does not require admin privileges.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.8/5.0

Scored across 39 tools

Disambiguation4/5

Most tools have a clear, distinct target and data source, and descriptions explicitly call out differences (e.g., dns_lookup vs local_dig). A few pairs overlap in concept (bgp_prefix_origin vs bgp_route_lookup, local_mtr vs local_ping/local_traceroute), but the descriptions are enough to disambiguate.

Naming Consistency4/5

Names are all lowercase snake_case and consistently use a domain-prefix pattern (rpki_*, bgp_*, irr_*, peeringdb_*, local_*). The tails mix verbs and plain nouns (lookup, validate, info, hijacks, public_ip), so it is not a uniform verb_noun scheme, but it is predictable.

Tool Count2/5

39 tools is beyond the 25+ threshold and presents a heavy selection surface, even though the tools are organized into distinct clusters. The broad network scope justifies more than a typical server, but the count strains agent decision-making.

Completeness4/5

The server covers core workflows across IP planning, DNS, BGP, RPKI, IRR, PeeringDB, and local diagnostics with no serious dead ends. Minor gaps exist (e.g., no RDAP abstraction or multi-vantage-point probing), but the covered domains feel substantially complete.

Maintenance

ActivityMaintained
ResponsivenessNo issues