keenetic-mcp
MCP server that runs on the Keenetic router itself (Entware, Python stdlib only): lets an AI assistant monitor and manage clients, Wi-Fi, port forwarding, DNS and backups, with dry-run writes and an event watcher.
Install / Use
claude mcp add st412m -- npx -y github:st412m/keenetic-mcpIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
OperationsSupported Platforms
Our assessment of keenetic-mcp
keenetic-mcp scores 74/100 on our quality scale, 553rd of 633 Operations skills we index.
Its MCP Server is 9.9 KB long, well organised into 18 sections and no code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 10 days ago, so keenetic-mcp is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-01. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
keenetic-mcp compared with similar skills
All 4 of these similar skills score higher than keenetic-mcp; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| keenetic-mcp (this skill)by st412m | 74 | 3 | 10d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 87.2k | 16d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install keenetic-mcp?
- Run
claude mcp add st412m -- npx -y github:st412m/keenetic-mcp. The install tabs above show the steps for each supported agent. - Which AI agents does keenetic-mcp work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is keenetic-mcp safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is keenetic-mcp still maintained?
- The repository was last updated 10 days ago, so keenetic-mcp is actively maintained.
Skill content
View source on GitHubKeenetic MCP Server
MCP (Model Context Protocol) server for Keenetic routers. It runs directly on the router via Entware, with no dependencies outside the Python standard library. It gives an AI assistant 49 tools for monitoring and managing the router, reachable over MCP and over plain HTTP, plus a background watcher that calls out from the router when a rule matches.
Requirements
| Item | Requirement |
|---|---|
| Router | Keenetic with Entware support |
| Storage | USB drive formatted as ext4, Entware installed on it |
| Python | Python 3.x, standard library only (requirements.txt lists no packages) |
| Port | 9584 by default |
| Architecture | Models | Status | |---|---|---| | mipsel | KN-1010/1011, KN-1810, KN-1910, KN-2310, KN-3810 | Tested | | mips | KN-2410, KN-2510, KN-2010, KN-2110, KN-3610 | Should work, not tested |
Tested on Keenetic Giga KN-1010 + KN-1011 (Mesh), KeeneticOS 5.1.5 (5.01.C.5.0-0), Entware mipselsf.
Installation
Step 1 — Install Entware
Format a USB drive as ext4 and plug it into the router. In the router web interface go to Applications -> OPKG and make sure the drive is selected as the storage.
Download the installer for the router model and copy it to the install folder on the USB drive via SMB (\\192.168.1.1):
- KN-1010/1011, KN-1810, KN-1910, KN-2310, KN-3810: https://bin.entware.net/mipselsf-k3.4/installer/mipsel-installer.tar.gz
- KN-2410, KN-2510, KN-2010, KN-2110, KN-3610: https://bin.entware.net/mipssf-k3.4/installer/mips-installer.tar.gz
Entware installs automatically. Check the router system log for:
[5/5] Installation of the "Entware" package system is complete!
Step 2 — SSH into the router
ssh root@192.168.1.1 -p 222
Default password: keenetic. Change it immediately:
passwd
Step 3 — Install dependencies
opkg update
opkg install python3 git git-http nano curl rsync
Step 4 — Clone and configure
cd /opt
git clone https://github.com/st412m/keenetic-mcp.git
cd keenetic-mcp
cp .env.example .env
nano .env
Step 5 — Set up autostart
cp init.d/S99keenetic-mcp /opt/etc/init.d/
chmod +x /opt/etc/init.d/S99keenetic-mcp
/opt/etc/init.d/S99keenetic-mcp start
Verify it is running:
/opt/etc/init.d/S99keenetic-mcp status
curl http://localhost:9584/YOUR_MCP_SECRET
Step 6 — Configure external HTTPS access
In the Keenetic web interface go to Network Rules -> Domain name -> Web application access and click Add:
- Name:
keenetic-mcp - Internet access: Open access
- Device: This Keenetic device
- Protocol: HTTP
- TCP Port: 9584
Step 7 — Connect to Claude
Updating
cd /opt/keenetic-mcp
git pull --ff-only
/opt/etc/init.d/S99keenetic-mcp restart
/opt/etc/init.d/S99keenetic-mcp status
.env and watch_rules.json are gitignored, so a pull never touches credentials or rules. The autostart script is not updated by a pull of the working copy — after a release that changes it, copy it over again from init.d/. All three are what backup_mcp_config preserves.
After adding or removing tools, start a new chat: MCP clients cache tools/list for the lifetime of a session.
Configuration
Settings live in .env next to server.py, read once at startup. The minimum:
KEENETIC_HOST=http://192.168.1.1
KEENETIC_USER=admin
KEENETIC_PASS=your_router_password
MCP_SECRET=some…[redacted]
MCP_PORT=9584
| Variable | Default | Purpose |
|---|---|---|
| KEENETIC_HOST / KEENETIC_USER / KEENETIC_PASS | http://192.168.1.1, admin | Router connection for RCI |
| MCP_SECRET / MCP_PORT | changeme, 9584 | Secret token in the URL path, and the listening port |
| MCP_PROTECTED_PORTS | empty | External ports the write tools must never forward or remove |
| MCP_PROTECTED_PROXY_NAMES | empty | KeenDNS proxy names the write tools must never change |
| MCP_PROTECTED_UPSTREAMS | empty | host:port upstreams the write tools must never point at |
| MCP_HTTP_TOOLS | true | Plain-HTTP tool route on or off |
| MCP_HTTP_TOOL_ALLOWLIST | empty | State-changing tools allowed over that route |
| MCP_WATCH / MCP_WATCH_RULES | true, watch_rules.json | Event watcher, and its rules file |
| BACKUP_ENABLED / BACKUP_SCHEDULE | false, 0 11 * * 0 | Scheduled router config backup, in cron format |
| BACKUP_RSYNC_HOST / _USER / _KEY / _PATH | empty | rsync-over-SSH destination; without it backups stay local |
| BACKUP_MCP_CONFIG | true | Also back up .env, watch_rules.json and the init script |
Full reference, including the protected-object rules: docs/configuration.md.
The watcher stays idle until it has rules. To turn it on, copy the example and edit it:
cp watch_rules.example.json watch_rules.json
nano watch_rules.json
Connecting to claude.ai
After Step 6 the server is reachable at:
https://keenetic-mcp.YOUR_DDNS.keenetic.link/YOUR_MCP_SECRET
In Claude.ai go to Settings -> Integrations -> Add custom connector and paste that URL.
Tools
49 tools. One line per group; full descriptions in docs/tools.md.
- System —
get_system_info,get_internet_status,get_interfaces,get_traffic,get_vpn_status - WiFi —
get_wifi,get_wifi_stations,get_site_survey,get_channel_analysis - Clients —
get_clients,get_unregistered_clients,get_dhcp_leases,get_dhcp_static,register_client,update_client,block_client,unblock_client - Config, read-only —
get_config,get_config_state,diff_saved_config,get_port_forwarding,get_firewall_rules,get_keendns_mappings,get_dns_proxy,get_schedule,rci_query - Config, write —
set_port_forwarding,remove_port_forwarding,set_keendns_mapping,remove_keendns_mapping,set_dhcp_host,remove_dhcp_host,set_dns_host,remove_dns_host - Diagnostics —
get_log,get_log_by_device,run_ping,get_watch_status,test_watch_rule - Mesh —
get_mesh_nodes,get_extender_log - Storage —
get_media,get_opkg_status - Backups and management —
backup_config,backup_mcp_config,list_backups,dump_log,reboot - Security —
get_web_access
Every write tool takes dry_run, defaulting to true: it returns the payload it would send and changes nothing.
Beyond MCP, the tools are also reachable as GET /<MCP_SECRET>/tool/<name>?arg=value — see docs/http-api.md. The push side, where the router calls out on a matching event, is docs/watcher.md. Backups are docs/backup.md.
Limitations
- The server is single-threaded: it handles one request at a time, so a polling loop blocks MCP calls. Keep poll intervals at 60 s or more
get_logallows the router 30 s to answer and typically takes around ten.get_site_surveyandget_channel_analysisare also slow. None of them belong in a polling loop- A write tool polls for up to 7 s waiting for the save to land on disk, then answers
pendingrather than claiming success - MCP clients cache
tools/listfor the lifetime of a session. A changed tool list needs a new chat - The plain-HTTP route serves read-only tools only. State-changing tools return 403 unless allowlisted
- The watcher keeps its state in
/tmp(RAM), so a router reboot resets its baseline mipsarchitecture is untested.mipselis tested on KeeneticOS 5.1.5; other firmware branches are not- Log timestamps from before NTP syncs are wrong.
get_logflags them but asince/untilwindow still matches them
Troubleshooting
| Symptom | Command |
|---|---|
| Port 9584 does not answer | /opt/etc/init.d/S99keenetic-mcp status then grep ' /opt ' /proc/mounts |
| Address already in use, old version answers | /opt/etc/init.d/S99keenetic-mcp status — it reports every live instance |
| Nothing in the log | cat /tmp/keenetic-mcp.log |
⚠️ If /opt is not mounted, never rebind the OPKG drive over SSH on the router itself: dropbear lives on /opt and the rebind kills the session before it completes. Use the web interface or another machine.
More symptoms: docs/troubleshooting.md.
Security
- The endpoint is protected by a secret token in the URL path. HTTPS is handled by the Keenetic built-in SSL certificate
- Never commit
.env— it is in.gitignore. Change the default SSH password after installation rci_queryis GET-only and cannot modify the router;crypto,ppp,userandrunning-configsubtrees are refused outrightget_configmasks secrets by default.include_secrets: trueputs passwords and keys into the chat transcript- The write tools always protect the server's own port, upstream and proxy name. Add anything else via
MCP_PROTECTED_*. Protection applies to creating a rule as well as removing one, so listing a port also forbids re-publishing that service to the WAN set_dns_hostis not covered byMCP_PROTECTED_*. What guards an existing record is that a name already resolving elsewhere is refused- The plain-HTTP route serves read-only tools only. Adding a tool to
MCP_HTTP_TOOL_ALLOWLISThands out a write key: the URL secret ends up in config files, automation traces and proxy logs.MCP_HTTP_TOOLS=falseturns the route off - Treat
watch_rules.jsonas credential material — it can carry bot tokens and internal URLs. Prefer$NAMEplaceholders resolved from.env backup_mcp_configcopies.envandwatch_rules.jsonto the backup destination in clear text. Restrict that share to one accounttest_watch_rulemasks credentials in what it renders, not in what it sends:dry_run: falsesends the real values
Links
- docs/ — configuration, tools, HTTP API, watcher, backups, troubleshooting, internals
- CHANGELOG.md — version history
- LICENSE — MIT
Related Skills
Agent-Reach
87.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.6k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
