Endpoint Aiops
Governed managed-endpoint ops — login-storm & drift analysis, 13 MCP tools with audit/budget/undo.
- Transport
- Not stated
- Package
- —
- Registry id
- io.github.AIops-tools/endpoint-aiops
No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.
Disclaimer: Community-maintained open-source project. Not affiliated with, endorsed by, or sponsored by any endpoint-management vendor. Product and trademark names belong to their owners. MIT licensed.
Governed AI-ops for managed-endpoint fleets — thin clients, VDI endpoints,
and other centrally-managed devices — with a built-in governance harness:
unified audit log, token/runaway budget guard, undo-token recording, and
descriptive risk tiers. Vendor-neutral: it talks to an
endpoint-management server's REST API (Bearer auth) through a configurable
dialect — see Dialects. Self-contained: no
dependencies beyond httpx and the MCP SDK. The test suite is mock-based; the
endpoint-management REST paths have not yet been exercised against a live
management server — see docs/VERIFICATION.md.
What it does
Two signature analyses, plus the guarded reads and writes around them:
- Login-storm analysis — during a "everyone logs in at 9am" incident, detect the storm (bursts of concurrent logins in a sliding window) and rank the endpoints/users dragging login and boot times. Every flag is reported with its number, not a black-box verdict.
- Patch / config drift — find endpoints that have drifted from the fleet (outdated patch level, stray agent version, divergent OS build or config profile). With no declared baseline it derives one by fleet majority, so it works before a gold image exists.
What works
- CLI (
endpoint-aiops ...):init,overview,endpoint list/get/assign-profile/reboot,session list/storm,drift report/patch,secret set/list/rm/migrate/rotate-password,doctor,mcp. - MCP server (
endpoint-aiops mcporendpoint-aiops-mcp): 13 tools (10 read, 3 write), every one wrapped with the bundled@governed_toolharness. - Encrypted credentials: the management-server API key lives in an encrypted store
~/.endpoint-aiops/secrets.enc(Fernet + scrypt) — never plaintext on disk. Unlock with a master password fromENDPOINT_AIOPS_MASTER_PASSWORD(MCP/CI) or an interactive prompt (CLI). - Reversibility:
endpoint_assign_profile(highrisk) captures the prior profile and records an inverse "reassign the prior profile" undo descriptor.endpoint_reboot(mediumrisk) captures the prior online state for the audit record but declares no undo (a reboot has no safe inverse). - Safety: state-changing CLI ops (
endpoint assign-profile,endpoint reboot) require double confirmation and support--dry-run.
Capability matrix (13 MCP tools)
| Category | Tools | Count | R/W |
|---|---|---|---|
| Overview | overview |
1 | read |
| Inventory | endpoint_list, endpoint_get, endpoint_health_score |
3 | read |
| Sessions | session_list, login_storm_analysis |
2 | read |
| Drift | drift_report, patch_status, patch_compliance |
3 | read |
| Remediation | endpoint_assign_profile |
1 | write (high) |
endpoint_reboot |
1 | write (medium) | |
| Undo | undo_list |
1 | read |
undo_apply |
1 | write (medium) |
The analysis tools (login_storm_analysis, drift_report, patch_status,
patch_compliance, endpoint_health_score) accept injected records for
pure/offline analysis; endpoint_health_score and patch_compliance are
injected-only, the others also pull live from a configured target.
What this tool does, and does not, decide
It delivers managed-endpoint operations — reads and writes — accurately and efficiently, and records every one of them. It does not decide whether a write is allowed to happen. That is the agent's judgement, or the permission of the account you connect it with: give it a management-console account or API token scoped to a read-only role and the writes fail at the server — the place that actually owns the permission.
From the project's README.