MCP server for interacting with Cisco ACI APIC controllers, including authentication, fetching classes, and managing APIC resources. Supports authentication, fetching tenants, application profiles, EPGs, fabric nodes, bridge domains, contracts, VRFs, and more. Includes tools for analyzing tenant configurations, checking denied logs, and verifying APIC vulnerabilities using the PSIRT API.
This server has 6 tools with clear, verb-based names (authenticate_apic, fetch_apic_class, get_tenants, get_application_profiles, get_epgs, get_fabric_nodes). Most tools have reasonable descriptions and input parameters with types and descriptions. However, there are significant gaps: (1) Output schemas are not documented, responses are described as 'Dict[str, Any]' with no structure specification, forcing LLMs to infer result shape; (2) Error handling is present but generic, most tools return a dictionary with 'status' and 'message' fields, but these lack guidance for LLM recovery actions; (3) Tool descriptions are adequate (60 - 150 chars) but lack context on WHEN to use each tool vs. others (e.g., when to call fetch_apic_class vs. get_tenants); (4) Parameters like 'query_params' (in fetch_apic_class) accept free-form objects with no validation or enumeration, LLMs can pass invalid APIC query syntax; (5) No pagination or result limiting is documented, despite tools returning potentially large lists (get_tenants, get_epgs could return hundreds of objects); (6) Credentials are passed as function parameters in authenticate_apic, but the function ignores them and reads from .env instead, this is confusing API design that could lead to agent misuse. The per-tool average is 52.
Authenticate to a Cisco ACI APIC controller and establish a session using .env variables.
Fetch objects of a specific APIC class.
Get application profiles from the APIC controller.
Get Endpoint Groups (EPGs) from the APIC controller.
Get fabric nodes (switches, controllers) from the APIC controller with OOB and INB management IPs.
Get all tenants from the APIC controller.
Output schemas are not documented for any tool. All tools return 'Dict[str, Any]' with no structure specification. LLMs cannot determine what fields to extract or how to chain results to downstream calls.
No pagination or result limiting. Tools like get_tenants and get_epgs can return hundreds of objects with no limit, bloating context. No next_cursor, page, or offset parameters.
authenticate_apic accepts username and password parameters but ignores them, reading from .env instead. This breaks the API contract and confuses agents about how to provide credentials.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | - | v1 |
query_params in fetch_apic_class and filter string construction in get_application_profiles/get_epgs are vulnerable to injection attacks. Tenant names or filter values containing special characters (quotes, commas) will break APIC API queries. Parameters should be validated and properly escaped.
Error messages lack recovery guidance. Tools return generic {'status': 'error', 'message': '...'} but do not tell the LLM what to do next (e.g., 'Try authenticate_apic() first' when not authenticated).
Descriptions do not explain WHEN to use each tool vs. others. fetch_apic_class is low-level; get_tenants/get_epgs are convenience wrappers. LLMs need guidance on tool selection.
query_params parameter in fetch_apic_class accepts free-form Dict[str, str] with no validation or enumeration of valid APIC query keys (rsp-subtree, query-target-filter, rsp-prop-include, etc.). LLMs can pass invalid syntax.