MCP server for managing MikroTik RouterOS devices via API. Provides tools for querying system info, interfaces, DHCP leases, firewall rules, NAT, address lists, queues, routes, WireGuard, DNS, and executing read-only commands.
Server has 16 well-named tools with consistent verb_noun patterns (get_*, add_*, remove_). All tools have descriptions (10 - 200 chars, within baseline 34 - 392 range). Input schemas are present and properly typed for all tools. However, output schemas are completely undocumented, LLMs cannot predict response structure for planning. Parameter descriptions are minimal (e.g., 'IP address to remove' lacks format/validation hints). Two-step confirmation pattern for write operations (add_to_address_list, remove_from_address_list) is excellent for safety, but error handling and recovery guidance are absent. No tool annotations (readOnlyHint/destructiveHint) despite clear risk stratification. Missing: output schema documentation, parameter constraints (enums, ranges), error recovery guidance, and per-parameter validation rules.
Add an IP address to an address-list on the MikroTik. Two-step call: the first call (without confirm_token) changes nothing and returns a preview + confirm_token; call again with that confirm_token to apply.
JSON snapshot of key config sections (interfaces, firewall filter/NAT, address-lists, DHCP leases, routes, WireGuard, static DNS) — for diffing 'before/after' around manual changes. This is not a native RouterOS backup file, just a readable JSON snapshot.
Run a RouterOS command for reading/diagnostics. Read-only commands only. Example: /ip/firewall/filter/print or /ping address=8.8.8.8 count=3
Contents of an address-list. Can specify a particular list.
List of DHCP leases — who's connected to the network. Can be filtered by server.
Output schemas completely undocumented. LLMs cannot predict response structure, field names, or types for any tool. This forces agents to guess at downstream field mappings and breaks tool chaining.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Tools are clearly stratified by risk (READ_ONLY vs WRITE), but LLMs cannot see this classification. Agents may incorrectly treat write operations as safe to retry.
Parameter descriptions lack validation rules and constraints. E.g., 'address' in add_to_address_list says 'IP address or subnet' but does not specify format (CIDR notation required?), validation rules, or examples. 'timeout' accepts '1h, 1d' but no enum or pattern constraint.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 73 | 2026-07-28+ | v2 |
List of static DNS entries (/ip/dns/static) on the MikroTik
Firewall filter rules. Can be filtered by chain (input/forward/output).
Instant snapshot of current interface throughput (bits/s, packets/s) — for diagnosing 'why is the internet slow right now'
List of network interfaces with their status and comments
Recent MikroTik log entries
NAT rules (dstnat and srcnat)
Simple Queues — bandwidth limits for devices and interfaces
Routing table
WireGuard: interfaces (listen-port, public-key) and peers (endpoint, allowed-address, last handshake, rx/tx)
Remove an IP address from an address-list on the MikroTik. Two-step call: the first call (without confirm_token) changes nothing and returns a preview + confirm_token; call again with that confirm_token to apply.
System info: model, RouterOS version, uptime, CPU, RAM
No error handling or recovery guidance. Tools lack descriptions of failure modes, retryability, or what the LLM should do if a call fails. E.g., execute_command has no guidance on what happens if the command is invalid or times out.
execute_command whitelist is incomplete in visible code. Only ~15 commands shown; full list not visible. If whitelist is incomplete or missing critical commands, agents cannot perform necessary diagnostics.