
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
utility-network-mcp
Advanced tools
MCP server for the Esri ArcGIS Utility Network: trace, subnetworks, dirty areas and associations over the UtilityNetworkServer REST API
An MCP server that lets AI assistants (Claude Desktop, Claude Code, VS Code, Cursor, and others) work with an Esri ArcGIS Utility Network published on ArcGIS Enterprise — run traces, find dirty subnetworks, summarise errors, and inspect associations through the UtilityNetworkServer REST API.
Not affiliated with or endorsed by Esri. ArcGIS and ArcGIS Utility Network are trademarks of Esri.
| Tool | Type | What it answers |
|---|---|---|
describe_network | read | Domain networks, tiers, network attributes, categories, system layers |
list_trace_configurations | read | Named trace configurations stored in the service |
trace | read | Connected / upstream / downstream / subnetwork / isolation / shortest path / loops — returns a summary by asset group and type (names added when the service exposes them), not 100k raw elements |
query_associations | read | Containment, attachment and connectivity associations for given features |
query_subnetworks | read | Rows from the Subnetworks table; ISDIRTY holds clean / dirty / invalid (check the stored codes on your service before filtering on a number) |
dirty_area_summary | read | Dirty areas grouped by Status, decoded, with whether Validate will evaluate each and the next action (error-only rows such as 8 and 40 need a feature edit, not another validate) |
find_features | read | Look up a feature by asset ID (for example CB-1042); returns globalId, layer and asset group / type names to feed trace. Field set by UN_ASSET_ID_FIELD (default ASSETID) |
network_moments | read | Whether topology is valid; when it was last enabled |
job_status | read | Poll an async job |
validate_network_topology | write | Only when UN_ALLOW_WRITES=true, and each call needs confirm=true |
update_subnetwork | write | Same gating as above |
pip install utility-network-mcp # or: uvx utility-network-mcp
utility-network-mcp --selftest # offline checks
| Variable | Required | Meaning |
|---|---|---|
UN_FEATURE_SERVICE_URL | yes | https://host/server/rest/services/<Service>/FeatureServer |
UN_PORTAL_URL | for login auth | Portal URL |
UN_CLIENT_ID / UN_CLIENT_SECRET | option A | OAuth app (client credentials) |
UN_USERNAME / UN_PASSWORD | option B | Portal login via generateToken (not for SAML-only portals) |
UN_TOKEN | option C | Pre-issued token |
UN_DEFAULT_VERSION | no | Default sde.DEFAULT |
UN_ALLOW_WRITES | no | true registers the write tools |
UN_MAX_IDS | no | Sample globalIds per group in summaries (default 25) |
{
"mcpServers": {
"utility-network": {
"command": "uvx",
"args": ["utility-network-mcp"],
"env": {
"UN_FEATURE_SERVICE_URL": "https://gis.example.com/server/rest/services/Electric/FeatureServer",
"UN_PORTAL_URL": "https://gis.example.com/portal",
"UN_CLIENT_ID": "...",
"UN_CLIENT_SECRET": "..."
}
}
}
}
Read-only by default. Write tools need both the server switch and an explicit per-call confirmation, so the agent must ask a human first. Use an account scoped to the one service; never the utility network owner account.
See the companion skill's references/mcp/03-building-a-utility-network-mcp-server.md in this repository for the design, REST shapes, auth patterns and pitfalls.
FAQs
MCP server for the Esri ArcGIS Utility Network: trace, subnetworks, dirty areas and associations over the UtilityNetworkServer REST API
We found that utility-network-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.