wiresage
Kind
Open-source organization
Focus
AI × network & security tools
Code
github.com/wiresage
License
MIT, per repository
Status
Active · open to contributors
wiresage.dev

Language models, grounded in the wire.

Abstract. WireSage is an open-source organization building the interfaces between large language models and the tools network and security engineers already rely on: routers, firewalls, scanners and the protocols beneath them. We publish Model Context Protocol servers, agents and automation as permissively licensed code, with typed tools, documented behaviour and safe defaults that anyone can read, test and reproduce.

Keywords: MCP · network automation · RouterOS · LLM agents · security tooling
ClientLanguage modelClaude, GPT or a local model, via any MCP client
WireSageServerschemas · validation · safe mode · credentials
NetworkDeviceRouterOS today; more platforms proposed
Fig. 1 The pattern every WireSage project follows. The model only ever sees typed tools and their results; credentials and device sessions stay with the server, which turns each call into native operations.
§1

Motivation

Networks are described in RFCs, vendor manuals and decades of CLI habit. Language models read all of it fluently, but reading is not operating. Giving a model a raw shell on a production router is neither safe nor reproducible.

Our working hypothesis is that the gap is an interface problem, not a model problem. Give models small, typed, well-described tools that mirror what a careful engineer would do, and they become useful colleagues instead of risky ones. WireSage exists to build those interfaces in public, and to measure whether they work.

§2

Repositories

One published project so far. More start as open discussions.
Table 1 Published repositories.
RepositoryScopeInterfaceLicenseStatus
mikrotik-mcp MCP server for MikroTik RouterOS: VLANs, firewall, NAT, DHCP, DNS, routes, WireGuard, queues, backups and more. 14 categories120+ operationsstdio · SSE · HTTP MIT Active

2.1mikrotik-mcp

Lets any MCP-capable assistant manage a RouterOS device through typed tools such as mikrotik_create_vlan_interface, never through free-form commands.

Runtime
Python 3.8+, or Docker
Transports
stdio, SSE, streamable HTTP
Safety
RouterOS safe-mode sessions that auto-revert if management access is lost
Context
Scope tools per category with --mcp.tools for small local models
# Exercise every tool by hand with MCP Inspector
$ npx @modelcontextprotocol/inspector \
    uvx mcp-server-mikrotik \
    --host 192.168.88.1 \
    --username admin \
    --key-filename ~/.ssh/mikrotik_ed25519

2.2Open problems

  • P1More network operating systems

    Vendor-neutral MCP servers that share one tool vocabulary across platforms.

  • P2Change review

    Agents that read a configuration diff, explain its blast radius and ask before applying it.

  • P3Evidence-first scanning

    Scanners whose findings a model triages, with the raw output attached to every claim.

  • P4Evaluation

    Open benchmarks and lab topologies that measure how well models actually operate networks.

These are directions, not promises. Each one starts as a public discussion.

§3

Method

Design rules every WireSage project is held to.

3.1Typed tools, not raw shells

Every capability is a named tool with a schema the server validates before anything reaches a device.

3.2Reversible by default

Risky changes run inside safe-mode sessions or their equivalent, so a lost connection rolls back instead of locking you out.

3.3Credentials stay local

The model sees tool names and results. Passwords, keys and sessions never leave the server.

3.4Small context, local-first

Tool sets can be scoped by category, so smaller self-hosted models fit and nothing has to leave your network.

3.5Documented and inspectable

Every tool is listed in a public reference and can be called by hand, so behaviour can be checked, not assumed.

3.6Open by default

Code, issues, design discussions and roadmaps happen in public, under permissive licenses.

§4

Contribute

Maintained by volunteers. Every contribution size counts.

From a bug report with a RouterOS version attached to a new server for a platform we haven’t touched yet, contributions are how this work moves forward.

  1. Use a project and report what breaks

    Include the device model, OS version and the exact tool call.

  2. Pick up an issue

    Look for good first issue labels across the organization.

  3. Propose an integration

    Open a discussion describing the platform, its API and what “safe” means there.

§5

Citing

If WireSage software supports your research or teaching, please cite the repository you used.

@software{wiresage_mikrotik_mcp,
  author = {{WireSage contributors}},
  title  = {mikrotik-mcp: a Model Context Protocol server for MikroTik RouterOS},
  year   = {2026},
  url    = {https://github.com/wiresage/mikrotik-mcp},
  note   = {MIT License}
}