Skip to content
@mechubsec

mechub

sovereign network-security automation — deterministic decides · the model explains · a human approves

mechub mark

mechub

sovereign network-security automation
deterministic decides · the model explains · a human approves


mechub is an ecosystem of self-hosted, MCP-driven automation for the people who run firewalls, networks, and security operations at scale. It puts real AI leverage in every operator's hands without one byte of operational data leaving the building, and with better attribution than before AI arrived.

A gateway-brokered agent platform, not a chatbot with credentials: agents reach infrastructure only through MCP servers fronting each management plane, every tool call is scoped and audited, and autonomy is granted rung by rung, enforced by token scope at the server rather than by prompt.

The name

mechub — Machine Executed & Checked · Hub.

It started as mechanic hub: a workshop for network-security tools you can open up and work on. It now also says how they work — machines execute the change, deterministic checks decide whether it stands, a human approves, and the hub is where every vendor's MCP server meets, on hardware you own.

The ecosystem

Layer Projects
Foundation mecmcp · rustnetconf · rustez
MCP servers see maturity table below
Data ssdf — sovereign security data fabric
Evaluation mechubbench — tool-call benchmark corpus and runner for network-automation agents
Skills & tools fwskillsshare · firewallintentconverter · fwconfigsanitizer · srxsync

MCP server maturity

Version numbers alone don't carry the maturity story — a server can sit on a low 0.x for a long time because its vendor surface is small, not because it's less field-tested. The status column is the honest signal; read it alongside the version, not instead of it.

Server Latest release Status
rustjunosmcp v0.27.3 status
rustpanosmcp v0.14.0 status
rustproxmoxmcp v0.10.0 status
rustsdcmcp v0.1.0 status
rustmistmcp v0.3.2 status
rustunifimcp v0.5.0 status
rustfortimcp unreleased status
rustopnsmcp unreleased status

No server in the family is tagged stable yet; all are running in the maintainer's lab, not production, regardless of version number.

Principles

  • Self-hosted by default. Your realm, your models, your rules.
  • Deterministic decides. Code makes the safety-relevant call; the model explains it; a human approves it.
  • Honest maturity. If something is partial or unverified, we say so.

Public mechub projects are MIT licensed. Report vulnerabilities privately via the Security tab of the affected repository.

🌐 mechub.org

Popular repositories Loading

  1. fwskillsshare fwskillsshare Public

    33 skills for firewall and network security work — Juniper SRX design, NAT, VPN, and MNHA playbooks; Security Director On-Prem and ClearPass deployment; cross-vendor parse, audit, convert, and diff…

    Python 9 2

  2. rustnetconf rustnetconf Public

    A Rust network automation platform: async NETCONF client library, YANG code generation, vendor profiles, connection pooling, and a Terraform-like CLI for declarative network config management.

    Rust 4

  3. rustjunosmcp rustjunosmcp Public

    MCP server for Juniper Junos devices, built on rustnetconf.

    Rust 3 1

  4. fwconfigsanitizer fwconfigsanitizer Public

    simple tool to remove private data out of a fw configuration.

    HTML 2

  5. firewallintentconverter firewallintentconverter Public

    Working on LLM use of converting FW configurations

    JavaScript 1

  6. rustez rustez Public

    A Rust replacement for Juniper PyEZ — async-first Junos device automation built on rustnetconf.

    Rust 1

Repositories

Showing 10 of 19 repositories

Top languages

Loading…

Most used topics

Loading…