remnawave-mcp (TrackLine/mcp-remnawave) is an MCP server listed on the M8ven Trust Index. It scores 60 out of 100, grade C. It declares 153 tools. No publisher has claimed this listing.

C
Caution
60/100

remnawave-mcp

An MCP server that enables LLM clients to manage Remnawave VPN panels through 51 specialized tools for user, node, and subscription administration. It provides real-time access to panel statistics, health checks, and guided workflows for system diagnostics.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

TrackLine

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 2 credentials: REMNAWAVE_API_KEY, REMNAWAVE_API_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes153 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

api_tokens_list

List all API tokens

api_tokens_create

Create a new API token

api_tokens_delete

Delete an API token

external_squads_list

List all external squads

external_squads_get

Get an external squad by UUID

external_squads_create

Create a new external squad

external_squads_update

Update an external squad

external_squads_delete

Delete an external squad

external_squads_add_users

Add users to an external squad

external_squads_remove_users

Remove users from an external squad

external_squads_reorder

Reorder external squads

hosts_list

List all Remnawave hosts

hosts_get

Get a specific host by UUID

hosts_tags_list

List all host tags

hosts_create

Create a new host in Remnawave

hosts_update

Update an existing host

hosts_delete

Delete a host from Remnawave

hosts_bulk_enable

Bulk enable selected hosts

hosts_bulk_disable

Bulk disable selected hosts

hosts_bulk_delete

Bulk delete selected hosts

hosts_bulk_set_inbound

Bulk set inbound for selected hosts

hosts_bulk_set_port

Bulk set port for selected hosts

hwid_devices_list

List HWID devices for a specific user

hwid_devices_list_all

List all HWID devices across all users

hwid_stats

Get HWID device statistics

hwid_top_users

Get users with most HWID devices

hwid_device_create

Create a HWID device entry for a user

hwid_device_delete

Delete a specific HWID device

hwid_devices_delete_all

Delete all HWID devices for a user

config_profiles_list

List all config profiles

config_profiles_get

Get a config profile by UUID

inbounds_list

List all inbounds from all config profiles

config_profiles_get_inbounds

Get inbounds for a specific config profile

config_profiles_get_computed_config

Get computed configuration for a config profile

config_profiles_create

Create a new config profile

config_profiles_update

Update a config profile

config_profiles_delete

Delete a config profile

config_profiles_reorder

Reorder config profiles

billing_providers_list

List all infrastructure billing providers

billing_provider_get

Get a billing provider by UUID

billing_nodes_list

List all billing nodes

billing_history_list

List billing history

billing_provider_create

Create a new billing provider

billing_provider_update

Update a billing provider

billing_provider_delete

Delete a billing provider

billing_node_create

Create a billing node

billing_node_update

Update a billing node

billing_node_delete

Delete a billing node

billing_history_create

Create a billing history entry

billing_history_delete

Delete a billing history entry

ip_control_fetch_ips

Fetch active IPs for a user (async job)

ip_control_get_fetch_ips_result

Get result of an IP fetch job

ip_control_fetch_users_ips

Fetch IPs for all users on a node (async job)

ip_control_get_fetch_users_ips_result

Get result of a users IP fetch job

ip_control_drop_connections

Drop active connections for specified IPs

keygen_get

Generate a new SECRET_KEY for node configuration

metadata_node_get

Get metadata for a specific node

metadata_user_get

Get metadata for a specific user

metadata_node_upsert

Create or update metadata for a node

metadata_user_upsert

Create or update metadata for a user

node_plugins_list

List all node plugins

node_plugins_get

Get a node plugin by UUID

node_plugins_torrent_reports

Get torrent blocker reports

node_plugins_torrent_stats

Get torrent blocker statistics

node_plugins_create

Create a new node plugin

node_plugins_update

Update a node plugin

node_plugins_delete

Delete a node plugin

node_plugins_reorder

Reorder node plugins

node_plugins_clone

Clone a node plugin

node_plugins_execute

Execute a node plugin

node_plugins_torrent_truncate

Truncate all torrent blocker reports

nodes_list

List all Remnawave nodes

nodes_get

Get a specific node by UUID

nodes_tags_list

List all node tags

nodes_create

Create a new node in Remnawave

nodes_update

Update an existing node

nodes_delete

Delete a node from Remnawave

nodes_enable

Enable a disabled node

nodes_disable

Disable a node

nodes_restart

Restart a specific node

nodes_restart_all

Restart all nodes

nodes_reset_traffic

Reset traffic counter for a node

nodes_reorder

Reorder nodes by providing an ordered array of UUIDs

nodes_bulk_profile_modification

Bulk modify config profile for selected nodes

nodes_bulk_actions

Bulk actions on selected nodes (enable/disable/restart)

nodes_bulk_update

Bulk update properties for selected nodes

settings_get

Get Remnawave panel settings

settings_update

Update Remnawave panel settings

snippets_list

List all configuration snippets

snippets_create

Create a new configuration snippet

snippets_update

Update an existing snippet

snippets_delete

Delete a snippet

squads_list

List all internal squads

squads_accessible_nodes

Get nodes accessible to a specific squad

squads_create

Create a new internal squad

squads_update

Update an internal squad

squads_delete

Delete an internal squad

squads_add_users

Add users to an internal squad

squads_remove_users

Remove users from an internal squad

sub_page_configs_list

List all subscription page configurations

53 further tools are not listed here. The complete surface is in the source.

// known CVEs in dependencies3 high1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

lowtsup@8.0.0GHSA-3mv9-4h5g-vhg3

tsup DOM Clobbering vulnerability

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretREMNAWAVE_API_KEYNo API key for Caddy reverse proxy authentication
🔐 secretREMNAWAVE_API_TOKENYes API token from panel settings
configREMNAWAVE_BASE_URLYes Panel URL (e.g. https://vpn.example.com)
configREMNAWAVE_READONLYNo Set to true to enable readonly mode
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

153/153 tools missing one or more hints — api_tokens_list (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); api_tokens_create (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); api_tokens_delete (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +150 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

115/153 tool handlers declare input schemas (75%)

Declare an inputSchema with zod/joi/yup on every tool definition.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/trackline/mcp-remnawave?variant=verified)](https://m8ven.ai/mcp/trackline/mcp-remnawave)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 5a20e7f69cd218359c8cc723eacccfb84f95d733
code hash: e990a32be9727b15f79d39d6978f838e906bd381c1d20a1deaac2d682b981ce0
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client