Network Aiops

Governed network device ops (NAPALM) — 33 MCP tools with audit/undo.

LLM Mart 2 views 20 listing impressions
Transport
Not stated
Package
Registry id
io.github.AIops-tools/network-aiops

No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.

Disclaimer: This is a community-maintained open-source project and is not affiliated with, endorsed by, or sponsored by Cisco, Arista, Juniper, NetBox Labs, or any network vendor. Vendor and product names are trademarks of their respective owners. Source code is publicly auditable at github.com/AIops-tools/Network-AIops under the MIT license.

Governed multi-vendor network device operations for AI agents — 33 MCP tools, every one wrapped with the bundled @governed_tool harness: a local unified audit log under ~/.network-aiops/, token/runaway budget guard, undo-token recording, and descriptive risk-tier labels. Credentials (device passwords + the NetBox token) are kept in an encrypted store (secrets.enc), never plaintext on disk.

Devices are reached over NAPALM; an optional NetBox block adds source-of-truth lookups.

Standalone: the governance harness is bundled in the package (network_aiops.governance) — network-aiops has no external skill-family dependency. Coverage focuses on common device operations and is not yet exhaustive.

Verification status: the test suite is mock-based; not yet validated against live devices — self-testable with cEOS / vMX / containerlab. See docs/VERIFICATION.md.

What works

Read device facts, interfaces (+ counters/IP), BGP/LLDP neighbors (summary and detail), ARP/MAC tables, VLANs, route lookups, hardware environment, optics, NTP, users, SNMP info, VRFs, and an aggregated device_health; run read-only RCA diagnostics that flag down/erroring/flapping interfaces and unhealthy BGP neighbors — each finding citing the measured number that tripped it; back up the running config, dry-run a config diff, and merge/replace/rollback config — across the five core NAPALM platforms below. Optional NetBox lookups (devices + interfaces) confirm intended state before a change.

NAPALM does not implement every getter on every platform; an unsupported getter returns a teaching error ("not supported by the <driver> driver") rather than crashing. Secrets are never returned — get_users redacts password hashes and get_snmp_information redacts community strings.

Supported devices

Platform NAPALM driver Transport
Cisco IOS / IOS-XE ios SSH
Cisco Nexus NX-OS nxos (NX-API) / nxos_ssh (SSH) HTTPS / SSH
Cisco IOS-XR iosxr SSH (XML agent)
Arista EOS eos eAPI (HTTPS)
Juniper Junos junos NETCONF (SSH)

Additional platforms (Nokia SR OS / SR Linux, Huawei VRP, etc.) are reachable via NAPALM community drivers but are not officially tested here. Need one? See Contributing.

Supported actions

From the project's README.

Related servers

vSphere with Tanzu (VKS): Namespace and TanzuKubernetesCluster lifecycle. Requires vSphere 8.x+.

17 views

VMware compliance scanning (CIS, vSphere SCG, GB/T 22239, PCI-DSS) with drift detection.

14 views

MCP server for Geargrafx PC Engine / TurboGrafx-16 emulator

14 views

Read-only discovery for NeuralNg Angular components, APIs, packages, icons and theme recipes.

14 views