🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

keel-mcp

Package Overview
Dependencies
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

keel-mcp

Network diagnostics MCP server — ping, DNS, traceroute, SSL, port scanning, and more.

pipPyPI
Version
0.2.1
Weekly downloads
38
-5%
Maintainers
1
Weekly downloads
 

Keel

Network Diagnostics MCP Server

License: MIT

Probing what lies beneath the surface -- network diagnostics for AI tools.

What It Does

Keel is a Model Context Protocol (MCP) server that gives AI assistants 14 network diagnostic tools. It handles the things you'd normally reach for ping, dig, nmap, or openssl to do -- but exposed as structured, validated MCP tool calls.

Tools

ToolDescriptionKey Parameters
healthServer version and status check--
pingTCP connect ping (port 80) with latency statshost, count (1--100), timeout
tracerouteTrace network route to a hosthost, max_hops (1--64)
dns_lookupResolve DNS records (A, AAAA, MX, CNAME, TXT, NS)domain, record_type, nameserver
reverse_dnsReverse DNS lookup for an IP addressip
port_checkCheck if a single TCP port is openhost, port, timeout
port_scanScan common TCP ports (rate-limited, max 100)host, ports
check_ssl_certInspect SSL/TLS certificate details and expiryhost, port
whois_lookupWHOIS domain registration lookupdomain
http_checkHTTP request with status, timing, headers, sizeurl
subnet_scanDiscover live hosts on a local subnet (RFC 1918 only)subnet (CIDR, max /20)
get_public_ipGet the machine's public IP address--
speed_testMeasure download speed (Mbps) and latency--
dns_propagationCheck DNS propagation across public resolversdomain, record_type

Installation

From PyPI:

pip install keel-mcp

Or isolated with pipx:

pipx install keel-mcp

Usage

Run the server directly (stdio transport):

keel

Claude Code

Register as a local MCP server:

claude mcp add keel -- keel

Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "keel": {
      "command": "keel",
      "args": []
    }
  }
}

If installed in a virtual environment, use the full path to the binary:

{
  "mcpServers": {
    "keel": {
      "command": "/path/to/.venv/bin/keel",
      "args": []
    }
  }
}

Security

Keel is designed to be safe for AI-driven use:

  • SSRF protection -- http_check resolves hostnames and blocks requests to internal, private, loopback, and link-local IP addresses (including IPv4-mapped IPv6). Cloud metadata endpoints (169.254.x.x) are blocked.
  • Input validation -- All inputs pass through validators that reject shell metacharacters, malformed hostnames, and invalid ports before reaching any network call or subprocess.
  • Rate limiting -- port_scan enforces a minimum 1-second interval between scans to prevent abuse.
  • Subnet restriction -- subnet_scan only allows RFC 1918 private subnets and caps at /20 (4096 addresses) with concurrency limiting.
  • No shell injection -- Subprocess calls (traceroute, whois) use exec-style invocation, never shell interpolation.

Development

git clone https://github.com/seayniclabs/keel.git
cd keel
python -m venv .venv
source .venv/bin/activate
pip install -e ".[test]"
python -m pytest tests/ -q

License

MIT

Keywords

diagnostics

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts