Nwtools Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Nwtools Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that gives LLMs accurate IPv4 subnet and address tools. LLMs are unreliable at network math — this server provides deterministic, correct results via Python's ipaddress standard library.
PyPI: https://pypi.org/project/nwtools-mcp/
| Tool | Description |
|---|---|
parse_cidr | Network address, broadcast, netmask, wildcard mask, host count |
ip_in_subnet | Check whether an IP falls within a subnet |
subnets_overlap | Detect overlap between two subnets and return the intersection |
cidr_to_range | Convert a CIDR to its first and last IP address |
range_to_cidrs | Convert an IP range to the minimal list of covering CIDRs |
subtract_subnet | Carve a subnet out of a larger block, returning remaining CIDRs |
find_gaps | Find unallocated space within a container block |
check_coverage | Check whether a set of CIDRs fully covers a target block |
summarize_cidrs | Collapse a list of CIDRs into the minimal set of supernets |
classify_ip | Classify an IP as RFC 1918, loopback, link-local, multicast, or public |
ip_convert | Convert an IP between dotted-decimal, hex, binary, and integer |
| Variable | Default | Description |
|---|---|---|
MCP_TRANSPORT | stdio | stdio, streamable-http, or sse |
HOST | 0.0.0.0 | Bind address (HTTP transports only) |
PORT | 8000 | Listen port (HTTP transports only) |
API_KEY | _(none)_ | When set, requires X-API-Key: <value> on all HTTP requests |
LOG_LEVEL | INFO | Python log level for process and request logging |
The stdio transport is used when Claude Desktop spawns the server as a subprocess. No network port is opened.
The simplest way to run the server locally is:
uvx nwtools-mcpThat runs the nwtools-mcp console command from an isolated ephemeral environment. For a persistent install:
uv tool install nwtools-mcp
nwtools-mcpInstall and run directly:
pip install -e .
python main.pyOr use the console script:
nwtools-mcpOr install from PyPI with pip:
pip install nwtools-mcp
nwtools-mcpOr via Docker:
docker run --rm -i nwtools-mcpAdd to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"nwtools": {
"command": "python",
"args": ["/path/to/nwtools-mcp/main.py"]
}
}
}Or run it directly from PyPI with uvx:
{
"mcpServers": {
"nwtools": {
"command": "uvx",
"args": ["nwtools-mcp"]
}
}
}If you prefer a persistent uv-managed install, use:
{
"mcpServers": {
"nwtools": {
"command": "nwtools-mcp"
}
}
}The server supports streamable-http (recommended) and sse transports for remote access. Set MCP_TRANSPORT to switch modes.
# Local test
MCP_TRANSPORT=streamable-http python main.py
# With auth
API_KEY=your-secret MCP_TRANSPORT=streamable-http python main.pyWith Docker:
docker build -t nwtools-mcp .
docker run --rm -p 8000:8000 \
-e MCP_TRANSPORT=streamable-http \
-e API_KEY=your-secret \
nwtools-mcpWhen running in HTTP mode, the container exposes two unauthenticated probe endpoints:
| Endpoint | Description |
|---|---|
/healthz | Basic liveness probe |
/readyz | Readiness probe |
HTTP requests are also logged as structured JSON lines, including method, path, status, duration, client IP, and request ID.
The server does not terminate TLS. In production, place it behind a reverse proxy. Example Caddy config:
nwtools.example.com {
reverse_proxy localhost:8000
}The built-in API_KEY check adds a layer of defense at the application level, but it does not replace TLS — never expose the server without it.
In Claude Desktop (claude_desktop_config.json):
{
"mcpServers": {
"nwtools": {
"url": "https://nwtools.example.com/mcp",
"headers": {
"X-API-Key": "your-secret"
}
}
}
}On claude.ai, add the server under Settings → Integrations using the same URL.
Install with the test extra and run the suite:
pip install -e ".[test]"
pytestTo build distribution artifacts locally:
uv buildOr with the standard Python build frontend:
pip install build
python -m buildThe project is now structured to publish cleanly to PyPI and run via uvx.
Build locally:
uv buildPublish manually:
uv publishAutomated publishing uses publish.yml with PyPI Trusted Publishing.
Release checklist:
version in pyproject.toml and __version__ in src/nwtools_mcp/__init__.py.pytest.uv build.main.v0.2.0.Trusted Publisher settings:
pypi environment in the GitHub repository settings.Repository owner: crims0n Repository name: nwtools-mcp Workflow filename: publish.yml Environment name: pypi
The publish workflow builds the wheel and sdist, smoke-tests both artifacts, and then runs uv publish.
mcpuvicorn~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.