- Kind
- Open-source organization
- Focus
- AI × network & security tools
- Code
- github.com/wiresage
- License
- MIT, per repository
- Status
- Active · open to contributors
Language models, grounded in the wire.
Abstract. WireSage is an open-source organization building the interfaces between large language models and the tools network and security engineers already rely on: routers, firewalls, scanners and the protocols beneath them. We publish Model Context Protocol servers, agents and automation as permissively licensed code, with typed tools, documented behaviour and safe defaults that anyone can read, test and reproduce.
Motivation
Networks are described in RFCs, vendor manuals and decades of CLI habit. Language models read all of it fluently, but reading is not operating. Giving a model a raw shell on a production router is neither safe nor reproducible.
Our working hypothesis is that the gap is an interface problem, not a model problem. Give models small, typed, well-described tools that mirror what a careful engineer would do, and they become useful colleagues instead of risky ones. WireSage exists to build those interfaces in public, and to measure whether they work.
Repositories
| Repository | Scope | Interface | License | Status |
|---|---|---|---|---|
| mikrotik-mcp | MCP server for MikroTik RouterOS: VLANs, firewall, NAT, DHCP, DNS, routes, WireGuard, queues, backups and more. | 14 categories120+ operationsstdio · SSE · HTTP | MIT | Active |
2.1mikrotik-mcp
Lets any MCP-capable assistant manage a RouterOS device through typed tools such as mikrotik_create_vlan_interface, never through free-form commands.
- Runtime
- Python 3.8+, or Docker
- Transports
- stdio, SSE, streamable HTTP
- Safety
- RouterOS safe-mode sessions that auto-revert if management access is lost
- Context
- Scope tools per category with
--mcp.toolsfor small local models
# Exercise every tool by hand with MCP Inspector $ npx @modelcontextprotocol/inspector \ uvx mcp-server-mikrotik \ --host 192.168.88.1 \ --username admin \ --key-filename ~/.ssh/mikrotik_ed25519
2.2Open problems
- P1More network operating systems
Vendor-neutral MCP servers that share one tool vocabulary across platforms.
- P2Change review
Agents that read a configuration diff, explain its blast radius and ask before applying it.
- P3Evidence-first scanning
Scanners whose findings a model triages, with the raw output attached to every claim.
- P4Evaluation
Open benchmarks and lab topologies that measure how well models actually operate networks.
These are directions, not promises. Each one starts as a public discussion.
Method
3.1Typed tools, not raw shells
Every capability is a named tool with a schema the server validates before anything reaches a device.
3.2Reversible by default
Risky changes run inside safe-mode sessions or their equivalent, so a lost connection rolls back instead of locking you out.
3.3Credentials stay local
The model sees tool names and results. Passwords, keys and sessions never leave the server.
3.4Small context, local-first
Tool sets can be scoped by category, so smaller self-hosted models fit and nothing has to leave your network.
3.5Documented and inspectable
Every tool is listed in a public reference and can be called by hand, so behaviour can be checked, not assumed.
3.6Open by default
Code, issues, design discussions and roadmaps happen in public, under permissive licenses.
Contribute
From a bug report with a RouterOS version attached to a new server for a platform we haven’t touched yet, contributions are how this work moves forward.
- Use a project and report what breaks
Include the device model, OS version and the exact tool call.
- Pick up an issue
Look for good first issue labels across the organization.
- Propose an integration
Open a discussion describing the platform, its API and what “safe” means there.
Citing
If WireSage software supports your research or teaching, please cite the repository you used.
@software{wiresage_mikrotik_mcp,
author = {{WireSage contributors}},
title = {mikrotik-mcp: a Model Context Protocol server for MikroTik RouterOS},
year = {2026},
url = {https://github.com/wiresage/mikrotik-mcp},
note = {MIT License}
}