Iota Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Iota Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- mcp-name: io.github.qso-graph/iota-mcp -->
MCP server for Islands on the Air (IOTA) — group lookup, island search, DXCC mapping, nearby groups, and programme statistics through any MCP-compatible AI assistant.
Part of the qso-graph project. No authentication required — all IOTA data is public.
pip install iota-mcp| Tool | Description |
|---|---|
iota_lookup | Look up an IOTA group by reference number (e.g., NA-005) |
iota_search | Search groups and islands by name (e.g., Hawaii, Shetland) |
iota_islands | List all islands and subgroups in an IOTA group |
iota_dxcc | Bidirectional DXCC-to-IOTA mapping |
iota_stats | Programme summary — totals by continent, most/least credited |
iota_nearby | Find IOTA groups nearest to a lat/lon location |
get_version_info | Service version + upstream programme data version (fleet identity attestation) |
No credentials needed — just install and configure your MCP client.
iota-mcp works with any MCP-compatible client. Add the server config and restart — tools appear automatically.
#### Claude Desktop
Add to claude_desktop_config.json (~/Library/Application Support/Claude/ on macOS, %APPDATA%\Claude\ on Windows):
{
"mcpServers": {
"iota": {
"command": "iota-mcp"
}
}
}#### Claude Code
Add to .claude/settings.json:
{
"mcpServers": {
"iota": {
"command": "iota-mcp"
}
}
}#### ChatGPT Desktop
{
"mcpServers": {
"iota": {
"command": "iota-mcp"
}
}
}#### Cursor
Add to .cursor/mcp.json (project-level) or ~/.cursor/mcp.json (global):
{
"mcpServers": {
"iota": {
"command": "iota-mcp"
}
}
}#### VS Code / GitHub Copilot
Add to .vscode/mcp.json in your workspace:
{
"servers": {
"iota": {
"command": "iota-mcp"
}
}
}#### Gemini CLI
Add to ~/.gemini/settings.json (global) or .gemini/settings.json (project):
{
"mcpServers": {
"iota": {
"command": "iota-mcp"
}
}
}Data comes from the official IOTA website JSON downloads:
Data is downloaded once and cached for 24 hours (IOTA refreshes daily at 00:00 UTC).
git clone https://github.com/qso-graph/iota-mcp.git
cd iota-mcp
pip install -e .
# Run with mock data (no network)
IOTA_MCP_MOCK=1 python -m iota_mcp.server
# Run with MCP Inspector
iota-mcp --transport streamable-http --port 8010
# Security tests
pip install pytest
pytest tests/test_security.py -vGPL-3.0-or-later
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.