sovereign network-security automation
deterministic decides · the model explains · a human approves
mechub is an ecosystem of self-hosted, MCP-driven automation for the people who run firewalls, networks, and security operations at scale. It puts real AI leverage in every operator's hands without one byte of operational data leaving the building, and with better attribution than before AI arrived.
A gateway-brokered agent platform, not a chatbot with credentials: agents reach infrastructure only through MCP servers fronting each management plane, every tool call is scoped and audited, and autonomy is granted rung by rung, enforced by token scope at the server rather than by prompt.
mechub — Machine Executed & Checked · Hub.
It started as mechanic hub: a workshop for network-security tools you can open up and work on. It now also says how they work — machines execute the change, deterministic checks decide whether it stands, a human approves, and the hub is where every vendor's MCP server meets, on hardware you own.
| Layer | Projects |
|---|---|
| Foundation | mecmcp · rustnetconf · rustez |
| MCP servers | see maturity table below |
| Data | ssdf — sovereign security data fabric |
| Evaluation | mechubbench — tool-call benchmark corpus and runner for network-automation agents |
| Skills & tools | fwskillsshare · firewallintentconverter · fwconfigsanitizer · srxsync |
Version numbers alone don't carry the maturity story — a server can sit on a low 0.x for a long time because its vendor surface is small, not because it's less field-tested. The status column is the honest signal; read it alongside the version, not instead of it.
| Server | Latest release | Status |
|---|---|---|
rustjunosmcp |
v0.27.3 | |
rustpanosmcp |
v0.14.0 | |
rustproxmoxmcp |
v0.10.0 | |
rustsdcmcp |
v0.1.0 | |
rustmistmcp |
v0.3.2 | |
rustunifimcp |
v0.5.0 | |
rustfortimcp |
unreleased | |
rustopnsmcp |
unreleased |
No server in the family is tagged stable yet; all are running in the
maintainer's lab, not production, regardless of version number.
- Self-hosted by default. Your realm, your models, your rules.
- Deterministic decides. Code makes the safety-relevant call; the model explains it; a human approves it.
- Honest maturity. If something is partial or unverified, we say so.
Public mechub projects are MIT licensed. Report vulnerabilities privately via the Security tab of the affected repository.