Kip Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Kip Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that lets an AI assistant (such as Claude, Codex, or Gemini) look at your boat's Signal K data and help you design and install KIP dashboards — the gauges and panels you see on your chartplotter or tablet.
You stay in control: the assistant shows you a picture of each dashboard first, and it only saves anything to your boat after you say yes.
— speed, wind, depth, batteries, engine, and so on.
sailing, motoring, power, anchoring, navigation, and weather.
saved.
you a file you can import yourself.
A short session with an AI assistant, after pointing it at your boat:
You: Look at my boat's data and suggest some KIP dashboards.
→ analyze_signalk_data 142 paths · speed, wind, depth, battery, engine
→ recommend_dashboard_set 6 dashboards the data supports
Assistant: Your boat reports navigation, wind, depth, electrical and engine data,
so I can build these. Here's the "Sailing" one — a preview, nothing saved yet:
┌─────────────┬─────────────┬───────────────────────────┐
│ SOG 6.2 kn │ AWS 14 kn │ │
├─────────────┼─────────────┤ wind steering │
│ DPT 8.4 m │ AWA 42° │ │
└─────────────┴─────────────┴───────────────────────────┘
You: Looks good — install the sailing and anchor ones.
→ apply_kip_config (dry run) 2 dashboards → KipConfig (global)
Assistant: This will add "Sailing" and "Anchor" to KIP. Go ahead?
You: Yes.
→ apply_kip_config written ✓ — open KIP to see them.The assistant always shows a preview first and asks before writing anything to your boat.
You need a Signal K server running on your boat (or on your network), with KIP installed.
http://your-boat:3000. Notethe host name (or IP) and port.
run it on demand with npx (which comes with Node.js 24 or newer):
npx -y kip-mcp-serverThe next step wires this command into your assistant. (Prefer to build from source? See Develop below.)
and follow the short setup there. You tell the assistant your boat's host and port.
dashboards."* Review the previews it shows you.
If your Signal K server is older, it gives you a KipConfig.json file to import from KIP's Settings instead.
The server reads a few settings from its environment:
| Setting | What it is | Default |
|---|---|---|
SIGNALK_HOST | Your Signal K host name or IP | localhost |
SIGNALK_PORT | Your Signal K port | 3000 |
SIGNALK_TLS | Set to true if your server uses https | false |
SIGNALK_TOKEN | A Signal K login token, needed to write dashboards | (none) |
SIGNALK_USER | A Signal K username — used with SIGNALK_PASSWORD instead of a token | (none) |
SIGNALK_PASSWORD | The matching Signal K password | (none) |
KIP_URL | Override where KIP is served, if it's not the default | (derived) |
Reading your data needs no login. Writing dashboards to the server needs either a token or a username and password; you can always use the file-export option instead, which needs nothing extra. For how to get a token (or why a username/password is simpler), see Signal K authentication.
By default the server talks over stdio — the assistant runs it as a local subprocess. There is also an optional HTTP mode (kip-mcp-http) for hosting the server so a remote assistant (such as Claude.ai) can reach it over the network. It is opt-in and meant for a single operator behind a reverse proxy that adds TLS.
# Behind a TLS-terminating reverse proxy that forwards to 127.0.0.1:3017
MCP_BEARER_TOKEN=a-long-random-secret \
MCP_PUBLIC_URL=https://boat.example.com/mcp \
npx kip-mcp-http| Setting | What it is | Default |
|---|---|---|
HTTP_HOST | Address to bind | 127.0.0.1 (loopback) |
HTTP_PORT | Port to listen on | 3017 |
HTTP_PATH | URL path for the MCP endpoint | /mcp |
MCP_BEARER_TOKEN | One or more (comma-separated) bearer tokens that callers must present | (none) |
MCP_PUBLIC_URL | The public URL clients reach, used for the Host allowlist and metadata | (derived) |
MCP_ALLOWED_ORIGINS | Comma-separated browser origins to accept (off by default) | (none) |
MCP_ALLOWED_HOSTS | Override the Host allowlist | (derived) |
MCP_ALLOW_INSECURE | Set to true to start anyway in an unsafe setup | (unset) |
Every request must present a valid Authorization: Bearer <token> and pass a Host/Origin allowlist before it reaches the MCP layer. The server refuses to start if it would bind to a non-loopback address or run without a bearer token, unless you set MCP_ALLOW_INSECURE=true. It uses one Signal K login for all sessions, so treat it as a single-tenant deployment; the same SIGNALK_* settings above apply.
The server gives the assistant a set of tools, grouped by job:
icons and units KIP understands.
a preview.
consistency, labels) with severity-tagged findings; the review_dashboard prompt drives it, backed by a deterministic check_dashboard_ux lint.
the boat (asking first).
the built-in --doctor check.
A few terms, in plain words:
the network.
navigation.speedOverGround (speed overground).
is a dry run by default.
This project uses Node.js 24 (LTS). Common commands:
npm install # install dependencies
npm run typecheck # check types
npm run lint # check code style
npm test # run the tests
npm run build # compile to dist/
npm run smoke # start the built server and check it answers
npm run ci # run the full set of checksFor a full guide to running and testing the server locally during development — pointing an AI client or the MCP Inspector at a local build, running the HTTP transport, and testing against Signal K (or offline) — see docs/development.md.
Commits follow Conventional Commits; releases and version numbers are produced automatically from those commit messages.
MIT — see LICENSE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.