unifi-network — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited unifi-network (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You have access to a UniFi Network MCP server that lets you query and manage a UniFi Network Controller. It provides 177 tools covering devices, clients, firewall, VPN, routing, WLANs, Traffic Flows, statistics, and more.
The server uses lazy loading by default — only meta-tools are registered initially. Use them to find and call any tool:
| Meta-Tool | Purpose |
|---|---|
unifi_tool_index | Discover tools by name/description; use category, search, or include_schemas to filter |
unifi_execute | Call any tool by name (essential in lazy mode) |
unifi_batch | Run multiple tools in parallel |
unifi_batch_status | Check async batch job status |
Workflow: Call unifi_tool_index to find the right tool, then unifi_execute to call it. For multiple independent queries, use unifi_batch — it's significantly faster than sequential calls.
The server is "secure by default" because it controls real network infrastructure.
Read operations — always available. All list_*, get_*, and query tools work without special permissions.
Mutations — permission-gated with mixed defaults:
If a mutation fails with a permission error, tell the user the env var to set: UNIFI_POLICY_NETWORK_<CATEGORY>_<ACTION>=true
Confirmation flow — every mutation uses preview-then-confirm:
confirm=true → executes the mutationAlways preview first and show the user before confirming.
All tools return: {"success": true, "data": ...}, {"success": false, "error": "..."}, or {"success": true, "requires_confirmation": true, "preview": ...}. Always check success first.
Redacted secrets: Secret fields — WLAN passphrases (x_passphrase), VPN private/preshared keys, whole VPN config blobs (imported WireGuard/OpenVPN config files), and SNMP community strings — come back as ***REDACTED*** by default. Raw values are controlled by process policy (UNIFI_NETWORK_REDACT_SENSITIVE_FIELDS=false or global UNIFI_REDACT_SENSITIVE_FIELDS=false), not by tool arguments. On an update, send only the fields you are changing — to keep a secret unchanged, omit it; never echo ***REDACTED*** back, which is rejected so the placeholder can't overwrite the real secret.
unifi_list_devices returns a device_category field that accurately classifies devices:
ap — real access points (excludes USP Smart Power strips that report as uap type)switch — switchesgateway — UDM/USG gatewayspdu — smart power strips, UPS deviceswan — cable internet (UCI) devicesUse device_category (not type) when counting or filtering devices. The device_type filter parameter uses this classification.
Additional enriched fields: upgradable (bool), connection_network (VLAN name), uplink (topology), load_avg_1, mem_pct, model_eol.
unifi_batch for parallel queries (biggest efficiency win)unifi_get_network_health for quick "is everything OK?"device_category field, not type, for accurate AP/switch/PDU countsUsername and password are required (local admin credentials, not Ubiquiti SSO). API key support exists but is experimental — limited to read-only operations and a subset of tools.
To configure, run /unifi-network:unifi-network-setup or set env vars manually:
UNIFI_NETWORK_HOST=192.168.1.1
UNIFI_NETWORK_USERNAME=admin
UNIFI_NETWORK_PASSWORD=your-passwordIf the user also has cameras or door access control, other UniFi MCP plugins are available:
unifi-protect — security cameras, NVR, recordings, smart detectionsunifi-access — door locks, credentials, visitors, access policiesCameras and access readers appear as network clients — use unifi_lookup_by_ip to cross-reference if troubleshooting connectivity for those devices.
For the complete list of all 177 tools organized by category with descriptions, tips, and common scenarios, read references/network-tools.md.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.