# Mcp Nettools MCP server

Agent View of the PolicyLayer registry record for Mcp Nettools: identity, probed posture, risk grade, and all 235 tools classified. HTML page: https://policylayer.com/tools/aaronckj-mcp-nettools

## Facts

- Server id: `aaronckj/mcp-nettools`
- Homepage: https://github.com/aaronckj/mcp-nettools
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 235
- Tool categories present: Destructive, Execute, Read, Write
- Tags: aaronckj mcp nettools, admin, automation
- Record last modified: 2026-07-03T08:04:43.487Z

## Tools (235)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `http_delete` | Destructive | Critical | https://policylayer.com/tools/aaronckj-mcp-nettools/http-delete.md |
| `check_mqtt` | Execute | High | https://policylayer.com/tools/aaronckj-mcp-nettools/check-mqtt.md |
| `check_rdp` | Execute | High | https://policylayer.com/tools/aaronckj-mcp-nettools/check-rdp.md |
| `http_post` | Execute | High | https://policylayer.com/tools/aaronckj-mcp-nettools/http-post.md |
| `ping` | Execute | High | https://policylayer.com/tools/aaronckj-mcp-nettools/ping.md |
| `port_scan` | Execute | High | https://policylayer.com/tools/aaronckj-mcp-nettools/port-scan.md |
| `speedtest` | Execute | High | https://policylayer.com/tools/aaronckj-mcp-nettools/speedtest.md |
| `traceroute` | Execute | High | https://policylayer.com/tools/aaronckj-mcp-nettools/traceroute.md |
| `wake_on_lan` | Execute | High | https://policylayer.com/tools/aaronckj-mcp-nettools/wake-on-lan.md |
| `arp_table` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/arp-table.md |
| `bgp_lookup` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/bgp-lookup.md |
| `cert_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/cert-check.md |
| `cert_check_bulk` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/cert-check-bulk.md |
| `check_actual_budget` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-actual-budget.md |
| `check_adguard` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-adguard.md |
| `check_alertmanager` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-alertmanager.md |
| `check_anythingllm` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-anythingllm.md |
| `check_appwrite` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-appwrite.md |
| `check_archivebox` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-archivebox.md |
| `check_audiobookshelf` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-audiobookshelf.md |
| `check_authelia` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-authelia.md |
| `check_authentik` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-authentik.md |
| `check_baikal` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-baikal.md |
| `check_bazarr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-bazarr.md |
| `check_beszel` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-beszel.md |
| `check_bitwarden` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-bitwarden.md |
| `check_bookstack` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-bookstack.md |
| `check_calibre_web` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-calibre-web.md |
| `check_cassandra` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-cassandra.md |
| `check_changedetection` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-changedetection.md |
| `check_checkmk` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-checkmk.md |
| `check_clickhouse` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-clickhouse.md |
| `check_cockpit` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-cockpit.md |
| `check_code_server` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-code-server.md |
| `check_collabora` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-collabora.md |
| `check_consul` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-consul.md |
| `check_couchdb` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-couchdb.md |
| `check_crowdsec` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-crowdsec.md |
| `check_dashdot` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-dashdot.md |
| `check_directus` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-directus.md |
| `check_discourse` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-discourse.md |
| `check_dkim` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-dkim.md |
| `check_dmarc` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-dmarc.md |
| `check_docker_api` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-docker-api.md |
| `check_docmost` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-docmost.md |
| `check_docuseal` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-docuseal.md |
| `check_dokuwiki` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-dokuwiki.md |
| `check_dozzle` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-dozzle.md |
| `check_elasticsearch` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-elasticsearch.md |
| `check_emby` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-emby.md |
| `check_etcd` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-etcd.md |
| `check_filebrowser` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-filebrowser.md |
| `check_firefly_iii` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-firefly-iii.md |
| `check_flame` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-flame.md |
| `check_flaresolverr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-flaresolverr.md |
| `check_forgejo` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-forgejo.md |
| `check_freshrss` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-freshrss.md |
| `check_frigate` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-frigate.md |
| `check_gatus` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-gatus.md |
| `check_ghost` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-ghost.md |
| `check_gitea` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-gitea.md |
| `check_gitlab` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-gitlab.md |
| `check_gitness` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-gitness.md |
| `check_glances` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-glances.md |
| `check_gotify` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-gotify.md |
| `check_grafana` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-grafana.md |
| `check_grist` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-grist.md |
| `check_grocy` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-grocy.md |
| `check_guacamole` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-guacamole.md |
| `check_headscale` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-headscale.md |
| `check_healthchecks` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-healthchecks.md |
| `check_hedgedoc` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-hedgedoc.md |
| `check_heimdall` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-heimdall.md |
| `check_hoarder` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-hoarder.md |
| `check_homarr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-homarr.md |
| `check_homeassistant` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-homeassistant.md |
| `check_homepage` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-homepage.md |
| `check_hoppscotch` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-hoppscotch.md |
| `check_icinga` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-icinga.md |
| `check_immich` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-immich.md |
| `check_influxdb` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-influxdb.md |
| `check_invidious` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-invidious.md |
| `check_invoiceninja` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-invoiceninja.md |
| `check_it_tools` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-it-tools.md |
| `check_jackett` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-jackett.md |
| `check_jaeger` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-jaeger.md |
| `check_jellyfin` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-jellyfin.md |
| `check_jellyseerr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-jellyseerr.md |
| `check_joplin_server` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-joplin-server.md |
| `check_kafka` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-kafka.md |
| `check_karakeep` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-karakeep.md |
| `check_kasm` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-kasm.md |
| `check_kavita` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-kavita.md |
| `check_keycloak` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-keycloak.md |
| `check_kibana` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-kibana.md |
| `check_kimai` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-kimai.md |
| `check_komga` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-komga.md |
| `check_kubernetes_api` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-kubernetes-api.md |
| `check_ldap` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-ldap.md |
| `check_leantime` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-leantime.md |
| `check_librenms` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-librenms.md |
| `check_lidarr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-lidarr.md |
| `check_limesurvey` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-limesurvey.md |
| `check_linkding` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-linkding.md |
| `check_linkwarden` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-linkwarden.md |
| `check_listmonk` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-listmonk.md |
| `check_loki` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-loki.md |
| `check_matomo` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-matomo.md |
| `check_matrix_synapse` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-matrix-synapse.md |
| `check_mattermost` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-mattermost.md |
| `check_maybe` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-maybe.md |
| `check_mealie` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-mealie.md |
| `check_memcached` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-memcached.md |
| `check_memos` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-memos.md |
| `check_mimir` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-mimir.md |
| `check_miniflux` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-miniflux.md |
| `check_minio` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-minio.md |
| `check_mongodb` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-mongodb.md |
| `check_monica` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-monica.md |
| `check_mylar3` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-mylar3.md |
| `check_n8n` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-n8n.md |
| `check_navidrome` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-navidrome.md |
| `check_neo4j` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-neo4j.md |
| `check_netbird` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-netbird.md |
| `check_netdata` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-netdata.md |
| `check_nextcloud` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-nextcloud.md |
| `check_nfs` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-nfs.md |
| `check_nitter` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-nitter.md |
| `check_nocodb` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-nocodb.md |
| `check_ntfy` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-ntfy.md |
| `check_ntopng` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-ntopng.md |
| `check_nzbget` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-nzbget.md |
| `check_ollama` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-ollama.md |
| `check_onlyoffice` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-onlyoffice.md |
| `check_open_webui` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-open-webui.md |
| `check_openproject` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-openproject.md |
| `check_opensearch` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-opensearch.md |
| `check_organizr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-organizr.md |
| `check_outline` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-outline.md |
| `check_overseerr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-overseerr.md |
| `check_paperless` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-paperless.md |
| `check_penpot` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-penpot.md |
| `check_photoprism` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-photoprism.md |
| `check_pihole` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-pihole.md |
| `check_planka` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-planka.md |
| `check_plausible` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-plausible.md |
| `check_plex` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-plex.md |
| `check_pocketbase` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-pocketbase.md |
| `check_portainer` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-portainer.md |
| `check_postgres` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-postgres.md |
| `check_prometheus` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-prometheus.md |
| `check_prowlarr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-prowlarr.md |
| `check_qbittorrent` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-qbittorrent.md |
| `check_rabbitmq` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-rabbitmq.md |
| `check_radarr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-radarr.md |
| `check_radicale` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-radicale.md |
| `check_rallly` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-rallly.md |
| `check_readarr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-readarr.md |
| `check_redis` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-redis.md |
| `check_redlib` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-redlib.md |
| `check_sabnzbd` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-sabnzbd.md |
| `check_scrutiny` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-scrutiny.md |
| `check_seafile` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-seafile.md |
| `check_searxng` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-searxng.md |
| `check_security_headers` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-security-headers.md |
| `check_shiori` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-shiori.md |
| `check_signoz` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-signoz.md |
| `check_sip` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-sip.md |
| `check_smb` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-smb.md |
| `check_snipe_it` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-snipe-it.md |
| `check_sonarr` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-sonarr.md |
| `check_speedtest_tracker` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-speedtest-tracker.md |
| `check_spf` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-spf.md |
| `check_stirling_pdf` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-stirling-pdf.md |
| `check_strapi` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-strapi.md |
| `check_syncthing` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-syncthing.md |
| `check_tandoor` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-tandoor.md |
| `check_tautulli` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-tautulli.md |
| `check_technitium` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-technitium.md |
| `check_tempo` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-tempo.md |
| `check_traefik` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-traefik.md |
| `check_transmission` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-transmission.md |
| `check_trilium` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-trilium.md |
| `check_tubearchivist` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-tubearchivist.md |
| `check_umami` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-umami.md |
| `check_uptime_kuma` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-uptime-kuma.md |
| `check_vault` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-vault.md |
| `check_vaultwarden` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-vaultwarden.md |
| `check_vector` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-vector.md |
| `check_victoriametrics` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-victoriametrics.md |
| `check_vikunja` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-vikunja.md |
| `check_vnc` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-vnc.md |
| `check_wallabag` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-wallabag.md |
| `check_wallos` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-wallos.md |
| `check_wazuh` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-wazuh.md |
| `check_whoogle` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-whoogle.md |
| `check_wikijs` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-wikijs.md |
| `check_windmill` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-windmill.md |
| `check_wordpress` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-wordpress.md |
| `check_zabbix` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-zabbix.md |
| `check_zipkin` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-zipkin.md |
| `check_zipline` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-zipline.md |
| `check_zookeeper` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/check-zookeeper.md |
| `dns_bulk_lookup` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/dns-bulk-lookup.md |
| `dns_lookup` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/dns-lookup.md |
| `dns_propagation` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/dns-propagation.md |
| `dnssec_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/dnssec-check.md |
| `ftp_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/ftp-check.md |
| `geolocation` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/geolocation.md |
| `get_public_ip` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/get-public-ip.md |
| `health_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/health-check.md |
| `http_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/http-check.md |
| `http_redirect_chain` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/http-redirect-chain.md |
| `http_security_headers` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/http-security-headers.md |
| `imap_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/imap-check.md |
| `local_ports` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/local-ports.md |
| `mac_lookup` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/mac-lookup.md |
| `mysql_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/mysql-check.md |
| `network_interfaces` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/network-interfaces.md |
| `ntp_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/ntp-check.md |
| `ping_sweep` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/ping-sweep.md |
| `pop3_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/pop3-check.md |
| `port_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/port-check.md |
| `reverse_dns` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/reverse-dns.md |
| `reverse_dns_bulk` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/reverse-dns-bulk.md |
| `scan_common_ports` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/scan-common-ports.md |
| `smtp_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/smtp-check.md |
| `snmp_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/snmp-check.md |
| `ssh_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/ssh-check.md |
| `subnet_info` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/subnet-info.md |
| `tcp_banner` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/tcp-banner.md |
| `tls_version_check` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/tls-version-check.md |
| `whois` | Read | Low | https://policylayer.com/tools/aaronckj-mcp-nettools/whois.md |
| `http_patch` | Write | Medium | https://policylayer.com/tools/aaronckj-mcp-nettools/http-patch.md |
| `http_put` | Write | Medium | https://policylayer.com/tools/aaronckj-mcp-nettools/http-put.md |

## Tool descriptions

- `http_delete` — Send an HTTP DELETE request. Some REST APIs require a body with DELETE (e.g. bulk delete). body: optional request body. headers: extra request headers as 'Name: Value' pairs separated by newlines or semicolons. Returns status code and re…
- `check_mqtt` — Connect to an MQTT broker and send a CONNECT packet (v3.1.1). Checks for a CONNACK response and decodes the return code. port: 1883 (plain) or 8883 (TLS). Does not authenticate (anonymous connect). Returns whether the broker accepted the…
- `ping` — Ping a host and return reachability, packet loss %, and RTT stats. count: 1-30. timeout: 1-60 s per packet.
- `port_scan` — Check multiple TCP ports on a host. ports: comma-separated or ranges (e.g., '22,80,443,8000-8080'). Max 500 ports. timeout: 1-30 s. open_only: if True, omit closed ports from the 'ports' dict (useful for large ranges).
- `speedtest` — Run a network speed test using the nearest server.
- `traceroute` — Trace the network path to a host. max_hops: 1-64. timeout: overall timeout in seconds. wait: per-hop probe wait time in seconds (1-10, default 2; increase to 5-10 for high-latency satellite/VPN links).
- `wake_on_lan` — Send a Wake-on-LAN magic packet to a MAC address.
- `arp_table` — Show ARP/neighbor table entries (IP-to-MAC mappings) as structured records. interface: optional filter by network interface name. Returns list with ip, mac, interface, and state fields.
- `bgp_lookup` — Look up BGP/ASN information for a public IP address using Team Cymru's WHOIS service. Returns the ASN, BGP prefix, country, registry, allocation date, and AS organization name. Useful for network forensics, attributing IPs to organizatio…
- `cert_check` — Check the SSL certificate on a host — expiry, issued date, issuer, SANs, and days remaining. timeout: 1-60 s.
- `cert_check_bulk` — Check TLS certificates for multiple hosts in one call. hosts: comma-separated hostnames (max 20). Returns expiry, days remaining, issuer, SANs, and validity for each. Useful for monitoring certificate renewals across many domains at once.
- `check_actual_budget` — Check Actual Budget personal finance server health via GET /health. Returns healthy state.
- `check_adguard` — Check AdGuard Home DNS filter health via GET /control/status. Returns running state and version. username/password: optional Basic auth credentials.
- `check_alertmanager` — Check Prometheus Alertmanager health via GET /-/healthy and /-/ready. Returns health/readiness status and version from the API.
- `check_anythingllm` — Check AnythingLLM (self-hosted RAG/AI workspace) health via GET /api/ping. Returns healthy status. Default port 3001.
- `check_appwrite` — Check Appwrite open-source BaaS health via GET /v1/health. Returns HTTP status. Default port 80 (HTTPS on 443).
- `check_archivebox` — Check ArchiveBox web archiving service reachability via GET /. Returns 200 or 302 when service is up. Default port 8000.
- `check_audiobookshelf` — Check Audiobookshelf audiobook and podcast server health via GET /api/health. Returns server version. Default port 13378.
- `check_authelia` — Check Authelia authentication server health via GET /api/health. Returns healthy when service is up. Default port 9091.
- `check_authentik` — Check Authentik identity provider health via GET /-/health/live/ and /-/health/ready/. Returns live and ready states.
- `check_baikal` — Check Baïkal CalDAV/CardDAV server reachability via GET /. Returns 200 or 302 when service is up. Default port 80.
- `check_bazarr` — Check Bazarr subtitle management server health via GET /api/system/status. Returns version string. 401 = running but API key required (still healthy). Default port 6767.
- `check_beszel` — Check Beszel server monitoring hub reachability via GET /api/health. Default port 8090.
- `check_bitwarden` — Check Bitwarden (Unified) server health via GET /api/alive. A 200 response confirms the server is operational. Default port 80.
- `check_bookstack` — Check BookStack wiki platform health via GET /status. Returns health status.
- `check_calibre_web` — Check Calibre-Web ebook library server health via GET /. 200 or redirect to /login = healthy. Default port 8083.
- `check_cassandra` — Check Apache Cassandra availability using the CQL binary protocol. Sends a CQL OPTIONS request and verifies a SUPPORTED response, confirming the Cassandra node is accepting connections.
- `check_changedetection` — Check changedetection.io web change monitoring server health via GET /api/v1/systeminfo. Returns version. Default port 5000.
- `check_checkmk` — Check Checkmk (IT monitoring) reachability via GET /. Default port 5000.
- `check_clickhouse` — Check ClickHouse OLAP database availability via HTTP /ping endpoint. Returns 'Ok.' on success. Port 8123 = HTTP interface, 8443 = HTTPS. Also returns version from the response header.
- `check_cockpit` — Check Cockpit Linux server management web UI health. Tries GET /cockpit/login — 200, 302, or 401 = healthy. Default port 9090 (most installs use HTTPS).
- `check_code_server` — Check code-server (VSCode in browser) health via GET /healthz. Returns 'OK'. Default port 8080.
- `check_collabora` — Check Collabora Online Office server health via GET /api/v1/config. 200 or 400 = server running. Default port 9980.
- `check_consul` — Check Consul agent health and cluster leader. Returns agent node name, datacenter, server/client role, leader address, and Consul version. host: IP or hostname. port: default 8500 (Consul HTTP API port).
- `check_couchdb` — Check Apache CouchDB availability via GET / which returns version and node name. Port 5984 = HTTP, 6984 = HTTPS.
- `check_crowdsec` — Check CrowdSec security agent local API reachability via GET /metrics. Default port 6060 (Prometheus metrics endpoint — no auth required).
- `check_dashdot` — Check Dashdot server stats dashboard health via GET /health. Returns healthy status and server info if available. Default port 3001.
- `check_directus` — Check Directus headless CMS health via GET /server/health. Returns status 'ok' and service checks. Default port 8055.
- `check_discourse` — Check Discourse forum health via GET /srv/status (returns JSON status) or /about.json for version info. Default port 80.
- `check_dkim` — Check whether a DKIM public key is published for a domain and selector. Looks up the TXT record at selector._domainkey.domain. selector: DKIM selector name (e.g. 'google', 'mail', 'default', 's1'). nameserver: optional custom resolver IP.
- `check_docker_api` — Check Docker daemon REST API availability via GET /_ping. Port 2375 = unencrypted, 2376 = TLS. Returns daemon version info from the response headers.
- `check_docmost` — Check Docmost collaborative wiki/documentation health via GET /api/health. Returns healthy/reachable status. Default port 3000.
- `check_docuseal` — Check DocuSeal document signing service reachability via GET /. Returns 200 or 302 when service is up. Default port 3000.
- `check_dokuwiki` — Check DokuWiki health via GET /doku.php. A 200 or redirect response confirms the wiki is running. Default port 80.
- `check_dozzle` — Check Dozzle Docker log viewer health via GET /healthcheck. Returns healthy/reachable status. Default port 8080.
- `check_elasticsearch` — Connect to an Elasticsearch or OpenSearch node and check cluster health. Returns cluster name, status (green/yellow/red), node counts, shard counts, and unassigned shards. host: IP or hostname. port: default 9200. https: use HTTPS instea…
- `check_emby` — Check Emby Media Server reachability via GET /System/Info/Public. Returns server name and version when healthy. Default port 8096.
- `check_etcd` — Check etcd v3 cluster health via its HTTP health endpoint. Returns health status and reason if unhealthy. host: IP or hostname. port: default 2379 (etcd client port).
- `check_filebrowser` — Check File Browser web-based file manager health via GET /api/health. Default port 80.
- `check_firefly_iii` — Check Firefly III personal finance manager health via GET /api/v1/about (returns 200 with version or 401 if unauthenticated — both confirm service is up). Default port 8080.
- `check_flame` — Check Flame startpage/dashboard reachability via GET /. Default port 5005.
- `check_flaresolverr` — Check FlareSolverr Cloudflare bypass proxy health via GET /v1. Returns version and number of active sessions. Default port 8191.
- `check_forgejo` — Check Forgejo (Gitea fork) git server health via GET /api/healthz. Returns status.
- `check_freshrss` — Check FreshRSS feed aggregator availability. FreshRSS has no dedicated health endpoint; checks if the main page or /i/ returns HTTP 200.
- `check_frigate` — Check Frigate NVR (network video recorder) health via GET /api/stats. Returns camera count, detection FPS, process load, and detector (GPU/CPU) stats. Default port 5000.
- `check_gatus` — Check Gatus health monitoring dashboard reachability via GET /health. Returns healthy=true when all configured endpoints are up. Default port 8080.
- `check_ghost` — Check Ghost blog platform health via GET /ghost/api/admin/site/. Returns version and site title. Default port 2368.
- `check_gitea` — Check Gitea/Forgejo git server health via GET /api/healthz. Returns status and availability.
- `check_gitlab` — Check GitLab instance health via GET /-/health. Confirms the application is running and can accept requests. Default port 80.
- `check_gitness` — Check Gitness (Harness git hosting) health via GET /api/v1/health. Returns 200 when service is up. Default port 3000.
- `check_glances` — Check Glances system monitoring server health via GET /api/3/status. Returns version. Default port 61208.
- `check_gotify` — Check Gotify push notification server health via GET /health. Returns healthy state and version.
- `check_grafana` — Check Grafana observability platform health via GET /api/health. Returns version, commit hash, database status, and memory usage.
- `check_grist` — Check Grist spreadsheet/database service health via GET /api/docs. Returns 200 or 401 when service is up. Default port 8484.
- `check_grocy` — Check Grocy grocery and household management server via GET /api/system/info. Returns version and PHP info.
- `check_guacamole` — Check Apache Guacamole clientless remote desktop gateway via GET /guacamole/api/ (returns API version). path: context path if non-default (e.g. '/guacamole').
- `check_headscale` — Check Headscale (self-hosted Tailscale control server) health via GET /health. Returns healthy/reachable status. Default port 8080.
- `check_healthchecks` — Check Healthchecks.io (self-hosted) cron job monitoring reachability via GET /. Returns 200 when service is up. Default port 8000.
- `check_hedgedoc` — Check HedgeDoc collaborative markdown notes server health via GET /api/v2/status. Returns version and connection count. Default port 3000.
- `check_heimdall` — Check Heimdall application dashboard reachability via GET /. Default port 80.
- `check_hoarder` — Check Hoarder bookmarks manager reachability via GET /api/v1/health. Default port 3000.
- `check_homarr` — Check Homarr dashboard reachability via GET /api/health. Default port 7575.
- `check_homeassistant` — Check Home Assistant health via GET /api/. Returns running state and version. token: optional long-lived access token for authenticated response (otherwise returns 401 which still confirms HA is running).
- `check_homepage` — Check Homepage dashboard (gethomepage.dev) health via GET /api/healthcheck. Returns healthy status. Default port 3000.
- `check_hoppscotch` — Check Hoppscotch self-hosted API testing platform backend health via GET /api/health or root path. Default backend port 3170 (frontend is 3000).
- `check_icinga` — Check Icinga (monitoring) reachability via GET /icingaweb2/. Default port 80.
- `check_immich` — Check Immich photo management server health via GET /api/server-info/ping. Returns ping response.
- `check_influxdb` — Check InfluxDB server health. Supports both InfluxDB v2 (GET /health → JSON status/pass) and v1 (GET /ping → 204 No Content). Returns version, status, and commit information when available. host: IP or hostname. port: default 8086. https…
- `check_invidious` — Check Invidious YouTube frontend reachability via GET /api/v1/stats. Returns software version when healthy. Default port 3000.
- `check_invoiceninja` — Check Invoice Ninja health via GET /api/v1/ping. Returns version if the API responds. A 401/403 response also indicates the server is running. Default port 80.
- `check_it_tools` — Check IT Tools developer utility hub reachability via GET /. Default port 80.
- `check_jackett` — Check Jackett indexer proxy reachability via GET /health. Returns healthy when service responds. Default port 9117.
- `check_jaeger` — Check Jaeger distributed tracing UI and query API via GET / (UI) and /api/services. Returns whether the UI is reachable and whether the query API is responding with valid JSON. port: 16686 (default UI/query). For Jaeger collector, use po…
- `check_jellyfin` — Check Jellyfin media server health via GET /health. Returns health status and version from public system info.
- `check_jellyseerr` — Check Jellyseerr media request and discovery manager health via GET /api/v1/status. Returns version string. Default port 5055.
- `check_joplin_server` — Check Joplin Server note-syncing backend health via GET /api/ping. Returns status 'ok'. Default port 22300.
- `check_kafka` — Check Apache Kafka broker availability. Sends a minimal API Versions request (Kafka protocol v0) and verifies a valid Kafka response frame is returned.
- `check_karakeep` — Check Karakeep (formerly Hoarder) AI bookmark manager health via GET /api/v1/health. Returns healthy/reachable status. Default port 3000.
- `check_kasm` — Check Kasm Workspaces containerized desktop reachability via GET /. Default port 443 with HTTPS.
- `check_kavita` — Check Kavita manga, comic, and book reader server health via GET /api/health. Default port 5000.
- `check_keycloak` — Check Keycloak identity server health via GET /health/live and /health/ready (Keycloak 20+). Falls back to /auth/health for older versions. Returns live and ready states.
- `check_kibana` — Check Kibana (Elastic Stack UI) reachability via GET /api/status. Default port 5601. Returns overall status color (green/yellow/red) from the health response.
- `check_kimai` — Check Kimai time-tracking application health via GET /api/version. Returns version string. Default port 80.
- `check_komga` — Check Komga comics/manga server health via GET /actuator/health. Returns healthy status, server version if available, and library count. Default port 25600.
- `check_kubernetes_api` — Check Kubernetes API server health via the /healthz and /version endpoints. Returns API server liveness, individual health check details, and Kubernetes version. host: IP or hostname. port: default 6443. https: use HTTPS (default True).
- `check_ldap` — Check LDAP server connectivity and verify it speaks the LDAP protocol. Sends an anonymous LDAPv3 bind request and checks for a valid response. port: 389 (LDAP), 636 (LDAPS). use_ssl: connect with TLS (default False; automatically True fo…
- `check_leantime` — Check Leantime project management service reachability via GET /. Returns 200 or 302 when service is up. Default port 80.
- `check_librenms` — Check LibreNMS (network monitoring) reachability via GET /. Default port 80.
- `check_lidarr` — Check Lidarr music collection manager health via GET /api/v1/system/status. Returns version and startup time. Default port 8686.
- `check_limesurvey` — Check LimeSurvey survey platform health via GET /index.php. A 200 or redirect response confirms the service is running. Default port 80.
- `check_linkding` — Check Linkding bookmark manager health via GET /health. Returns healthy/reachable status. Default port 9090.
- `check_linkwarden` — Check Linkwarden bookmark manager availability via GET /api/v1/auth/session (returns 401 without auth, confirming service is running).
- `check_listmonk` — Check listmonk newsletter/mailing list manager health via GET /api/health. Returns healthy/reachable status and version. Default port 9000.
- `check_loki` — Check Grafana Loki log aggregation service via GET /ready and /loki/api/v1/status/buildinfo. Returns readiness status and build version.
- `check_matomo` — Check Matomo web analytics health via the API ping endpoint. Returns version if the API responds. Default port 80.
- `check_matrix_synapse` — Check Matrix Synapse homeserver health via GET /_matrix/federation/v1/version (public endpoint). Returns server version.
- `check_mattermost` — Check Mattermost team messaging server health via GET /api/v4/system/ping. Returns status and database health.
- `check_maybe` — Check Maybe personal finance manager reachability via GET /. Returns 200 or 302 when service is up. Default port 3000.
- `check_mealie` — Check Mealie recipe manager health via GET /api/about. Returns version and build info.
- `check_memcached` — Connect to a Memcached server and request its version. Returns whether the server is reachable and its version string. Useful for verifying caching layer availability.
- `check_memos` — Check Memos self-hosted lightweight notes server health via GET /api/v1/workspace/profile. Returns version. Default port 5230.
- `check_mimir` — Check Grafana Mimir (scalable Prometheus) reachability via GET /ready. Default port 8080. Returns ready status from response body.
- `check_miniflux` — Check Miniflux RSS reader health via GET /healthcheck. Returns healthy state.
- `check_minio` — Check MinIO object storage availability via GET /minio/health/live (liveness) and /minio/health/ready (readiness). Port 9000 = default, 9001 = console. Returns liveness and readiness status separately.
- `check_mongodb` — Connect to a MongoDB server and send a hello command via the MongoDB wire protocol (OP_MSG). Returns whether the server is reachable and responds as a MongoDB instance. Does not authenticate. Useful for verifying MongoDB/Atlas-compatible…
- `check_monica` — Check Monica personal CRM availability. Monica has no dedicated health endpoint; checks if the main page returns HTTP 200 or redirect.
- `check_mylar3` — Check Mylar3 comics manager health via GET /api?apikey=nokey&cmd=getVersion (returns 401/403 if auth required, but proves service is up). Default port 8090.
- `check_n8n` — Check n8n workflow automation platform health via GET /healthz. Returns status 'ok'. Default port 5678.
- `check_navidrome` — Check Navidrome music streaming server health via GET /app/manifest.json (public endpoint). Returns reachable state.
- `check_neo4j` — Check Neo4j graph database availability via the HTTP API. GET / returns server version and available endpoints. Port 7474 = HTTP, 7473 = HTTPS, 7687 = Bolt (use port_check for Bolt).
- `check_netbird` — Check NetBird VPN management server health via GET /api/v1/self-hosted/setup-keys (returns 200 or 401 when service is up). Default port 8080.
- `check_netdata` — Check Netdata real-time performance monitoring server health via GET /api/v1/info. Returns version and operating system. Default port 19999.
- `check_nextcloud` — Check Nextcloud/ownCloud instance health via GET /status.php. Returns installed, maintenance mode, and version.
- `check_nfs` — Check NFS file server availability. Verifies TCP connectivity on both the portmapper (111) and NFS (2049) ports. Both ports must be reachable for NFS mounts to work.
- `check_nitter` — Check Nitter Twitter/X frontend reachability via GET /. Default port 8080.
- `check_nocodb` — Check NocoDB no-code database platform health via GET /api/v1/health. Returns status 'ok'. Default port 8080.
- `check_ntfy` — Check ntfy push notification server health via GET /v1/health. Returns healthy state and version.
- `check_ntopng` — Check ntopng (network traffic monitoring) reachability via GET /. Default port 3000.
- `check_nzbget` — Check NZBGet usenet downloader health via GET /. 200 or 401 (basic auth) = healthy. Default port 6789.
- `check_ollama` — Check Ollama LLM server health via GET /api/version. Returns version string. Default port 11434.
- `check_onlyoffice` — Check OnlyOffice Document Server health via GET /healthcheck. Returns 'true' on success. Default port 80.
- `check_open_webui` — Check Open WebUI (Ollama/LLM frontend) health via GET /health. Returns healthy status. Default port 3000.
- `check_openproject` — Check OpenProject project management reachability via GET /api/v3/configuration. Returns 200 or 401 when service is up. Default port 80.
- `check_opensearch` — Check OpenSearch (or Elasticsearch-compatible) cluster health via GET /_cluster/health. Returns cluster name, status (green/yellow/red), node counts, and shard stats. Port 9200 = default HTTP, 9300 = transport.
- `check_organizr` — Check Organizr v2 dashboard reachability via GET /api/v2/apps. Default port 80.
- `check_outline` — Check Outline wiki/knowledge base health via GET /api/_healthcheck. Returns healthy state.
- `check_overseerr` — Check Overseerr media request manager reachability via GET /api/v1/status. Returns version when healthy. Default port 5055.
- `check_paperless` — Check Paperless-NGX document management health. Attempts GET /api/ (returns 401 without auth, confirming service is running). Returns reachable state.
- `check_penpot` — Check Penpot open-source design tool health via GET /api/rpc/command/get-profile. 401 = running (auth required). Default port 9001.
- `check_photoprism` — Check PhotoPrism photo management server health via GET /api/v1/status. Returns running state and version.
- `check_pihole` — Check Pi-hole DNS ad blocker status via the admin API. Returns enabled, blocking status, DNS queries today, and ads blocked. api_token: Pi-hole API token from Settings > API/Web interface (optional — some stats available without auth). D…
- `check_planka` — Check Planka kanban project management board health via GET /api/health or root path. 200 or 401 = healthy. Default port 1337.
- `check_plausible` — Check Plausible Analytics health via GET /api/health. Returns database and clickhouse status.
- `check_plex` — Check Plex Media Server reachability via GET /identity. Returns server version and machine identifier when healthy. Default port 32400.
- `check_pocketbase` — Check PocketBase backend health via GET /api/health. Returns healthy status. Default port 8090.
- `check_portainer` — Check Portainer container management UI health via GET /api/status. Returns version and instance ID.
- `check_postgres` — Connect to a PostgreSQL server and read the server version from the startup response. Does not authenticate. Useful for verifying database server reachability and version.
- `check_prometheus` — Check Prometheus monitoring service health. Queries /-/healthy and /-/ready endpoints and returns status. Also fetches basic TSDB stats from /api/v1/status/tsdb if healthy.
- `check_prowlarr` — Check Prowlarr indexer manager health via GET /api/v1/system/status. Returns version and startup time. Default port 9696.
- `check_qbittorrent` — Check qBittorrent Web UI health via GET /api/v2/app/version. Returns version string. 403 = running but not logged in (still healthy). Default port 8080.
- `check_radarr` — Check Radarr movie manager reachability via GET /api/v3/health. Returns healthy when service responds. Default port 7878.
- `check_radicale` — Check Radicale CalDAV/CardDAV server reachability via GET /. Returns 200 or 401 when service is up. Default port 5232.
- `check_rallly` — Check Rallly open-source scheduling and polls application health via GET /api/health or root. Default port 3000.
- `check_readarr` — Check Readarr book/eBook collection manager health via GET /api/v1/system/status. Returns version and startup time. Default port 8787.
- `check_redlib` — Check Redlib (private Reddit frontend) reachability via GET /. Default port 8080.
- `check_sabnzbd` — Check SABnzbd usenet downloader health via GET /sabnzbd/. 200 or redirect to login page = healthy. path: context path if non-default (e.g. '/sabnzbd'). Default port 8080.
- `check_scrutiny` — Check Scrutiny disk health monitoring health via GET /api/health. Returns healthy/reachable status. Default port 8080.
- `check_seafile` — Check Seafile file sync and share server health via GET /api2/ping/. Returns 'pong' on success. Default port 80.
- `check_searxng` — Check SearXNG meta-search engine availability via GET /healthz. Falls back to checking the homepage returns 200.
- `check_security_headers` — Fetch HTTP response headers and report which security headers are present or missing: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection. Returns a score.
- `check_shiori` — Check Shiori bookmark manager reachability via GET /. Returns 200 or 302 (redirect to login) when service is up. Default port 8080.
- `check_signoz` — Check SigNoz (OpenTelemetry observability) reachability via GET /api/v1/health. Default port 3301. Returns status from health response.
- `check_sip` — Check a SIP (Session Initiation Protocol) server by sending an OPTIONS probe. port: default 5060 (UDP/TCP) or 5061 (TLS). transport: 'udp' (default) or 'tcp'. Returns whether the server is reachable and responds with a valid SIP message.…
- `check_smb` — Check SMB/CIFS file-sharing service reachability. Sends an SMB2 Negotiate request and verifies the response magic bytes. Port 445 = direct SMB, 139 = NetBIOS over TCP.
- `check_snipe_it` — Check Snipe-IT IT asset management application health via GET /api/v1/settings/general (401 without token = running). Default port 80.
- `check_sonarr` — Check Sonarr TV series manager reachability via GET /api/v3/health. Returns healthy when service responds. Default port 8989.
- `check_speedtest_tracker` — Check Speedtest Tracker reachability via GET /api/healthcheck. Default port 80.
- `check_spf` — Check the SPF (Sender Policy Framework) record for a domain. Looks up TXT records at the domain root and extracts the v=spf1 policy. nameserver: optional custom resolver IP. Multiple SPF records is a misconfiguration (RFC 7208 §3.2).
- `check_stirling_pdf` — Check Stirling-PDF tools server health via GET /api/v1/info. Returns healthy state and version.
- `check_strapi` — Check Strapi headless CMS reachability via GET /api/health-check. Returns status when healthy. Default port 1337.
- `check_syncthing` — Check Syncthing file sync service health via GET /rest/noauth/health. Returns status and version. api_key: optional Syncthing API key for authenticated endpoints.
- `check_tandoor` — Check Tandoor recipe manager health via GET /api/schema/ (public OpenAPI schema endpoint). Returns reachable state.
- `check_tautulli` — Check Tautulli Plex statistics reachability via GET /status. Returns healthy when service responds. Default port 8181.
- `check_technitium` — Check Technitium DNS Server reachability via GET /api/user/login (returns an API error indicating the server is up). Default port 5380.
- `check_tempo` — Check Grafana Tempo distributed tracing service via GET /ready and /api/echo. Returns readiness status and whether the API is responding. port: 3200 (default HTTP), 9095 (gRPC — use port_check for gRPC).
- `check_traefik` — Check Traefik reverse proxy health via GET /ping (returns 'OK') and GET /api/version. Port 8080 is the default Traefik dashboard/API port. Returns Traefik version if the API is accessible.
- `check_transmission` — Check Transmission BitTorrent client RPC health via GET /transmission/rpc. A 409 response (CSRF token required) confirms Transmission is running. Default port 9091.
- `check_trilium` — Check Trilium Notes hierarchical note-taking app reachability via GET /. Default port 8080.
- `check_tubearchivist` — Check TubeArchivist (YouTube archiver) health via GET /api/ping/. Returns healthy status and version info. Default port 8000.
- `check_umami` — Check Umami privacy-focused analytics server health via GET /api/heartbeat. Returns 'OK' text response. Default port 3000.
- `check_uptime_kuma` — Check Uptime Kuma monitoring service health via GET /api/health. Returns health status and version if available.
- `check_vaultwarden` — Check Vaultwarden (Bitwarden-compatible) password manager health via GET /alive. Returns health status.
- `check_vector` — Check Vector (log pipeline) reachability via GET /health. Default port 8686. Returns healthy status and component details from health response.
- `check_victoriametrics` — Check VictoriaMetrics (time-series database) health via GET /health and retrieve /api/v1/status/tsdb summary. Returns healthy, version if available, and time series count. Default port 8428. Set https=True for HTTPS.
- `check_vikunja` — Check Vikunja task manager health via GET /api/v1/info. Returns version and build information.
- `check_vnc` — Connect to a VNC server and read the RFB protocol banner. Returns whether the server is reachable, the RFB version string (e.g. 'RFB 003.008'), and the supported security types. Does not authenticate. port: 5900 (default), 5901, 5902, et…
- `check_wallabag` — Check Wallabag read-it-later service availability. Checks GET /api/info (401 without auth = running) or homepage.
- `check_wallos` — Check Wallos subscription tracker reachability via GET /. Default port 8282.
- `check_wazuh` — Check Wazuh security platform API reachability via GET /. Default port 55000 with HTTPS. Returns 401 when up (auth required but server is responding).
- `check_whoogle` — Check Whoogle search engine reachability via GET /. Returns healthy when main page loads. Default port 5000.
- `check_wikijs` — Check Wiki.js health via GET /healthcheck. Returns healthy status. Default port 3000.
- `check_windmill` — Check Windmill workflow automation platform health via GET /api/version. Returns version string. Default port 8000.
- `check_wordpress` — Check WordPress site health via GET /wp-json/. Returns site name and description. Default port 80.
- `check_zabbix` — Check Zabbix (enterprise monitoring) reachability via GET /zabbix/. Default port 80.
- `check_zipkin` — Check Zipkin (distributed tracing) health via GET /health and retrieve service count from /api/v2/services. Returns healthy, status, and service names. Default port 9411. Set https=True for HTTPS.
- `check_zipline` — Check Zipline file sharing server health via GET /api/server/info. Returns version and build info.
- `check_zookeeper` — Check ZooKeeper server health using the 'ruok' four-letter word command. Also attempts 'stat' to return mode (leader/follower/standalone) and client count. host: IP or hostname. port: default 2181.
- `dns_bulk_lookup` — Look up DNS records for multiple hostnames in one call. hosts: comma-separated list (e.g., 'google.com,github.com,cloudflare.com'). Max 20 hosts. record_type: A, AAAA, MX, TXT, etc. nameserver: optional custom resolver IP.
- `dns_lookup` — Look up DNS records for a hostname. record_type: A, AAAA, MX, TXT, NS, CNAME, PTR, SOA, SRV. nameserver: optional custom resolver IP (e.g., '8.8.8.8' for Google DNS, '1.1.1.1' for Cloudflare).
- `dns_propagation` — Check DNS propagation across 4 major public resolvers (Google 8.8.8.8, Cloudflare 1.1.1.1, Quad9 9.9.9.9, OpenDNS 208.67.222.222). Reports records from each and whether they are consistent. Useful after DNS changes to verify global propa…
- `dnssec_check` — Check DNSSEC status for a domain: whether DNSKEY records are published, RRSIG signatures are present on A records, and the DS (Delegation Signer) record exists in the parent zone. Returns key algorithm, key tag, and whether validation ap…
- `ftp_check` — Connect to an FTP server and read its banner. Also tests whether anonymous login is accepted. Useful for verifying FTP service availability.
- `geolocation` — Look up geolocation data for a public IP address: country, region, city, ISP, and coordinates. Uses ipinfo.io (no API key required for basic lookups).
- `get_public_ip` — Return the public IP address of the machine running this MCP server, plus basic geolocation (country, region, city, ISP). Useful for verifying internet connectivity, checking what IP external services see, and confirming NAT is working a…
- `health_check` — Health check endpoint for container monitoring.
- `http_redirect_chain` — Follow an HTTP/HTTPS URL through all redirects and return every hop with status code and Location header. Useful for debugging redirect loops or verifying HTTPS redirect configuration.
- `http_security_headers` — Audit HTTP security headers on a web server. Checks for: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and X-XSS-Protection. Returns which are present wi…
- `imap_check` — Check IMAP server connectivity. Reads server greeting and capabilities. Tests STARTTLS for port 143; uses implicit TLS for port 993. Does not authenticate.
- `local_ports` — List listening TCP and UDP ports on the local machine. protocol: 'tcp', 'udp', or 'all'. show_processes: include process names (requires root on some systems; set to false to skip). Uses ss (Linux) with fallback to netstat.
- `mac_lookup` — Look up the vendor/manufacturer for a MAC address (OUI database).
- `mysql_check` — Connect to a MySQL/MariaDB server and read the server greeting to extract the server version. Does not authenticate. Useful for verifying database server reachability and version.
- `network_interfaces` — List all local network interfaces with their IP addresses, subnet prefix length, and link state. Structured output from 'ip addr' (Linux) or 'ifconfig' (macOS/BSD).
- `ntp_check` — Check an NTP server: reachability and clock offset relative to local system time. Uses NTPv3 client packet over UDP. offset_seconds > 0 means server is ahead of local clock.
- `ping_sweep` — Ping all hosts in an IPv4 CIDR range and report which respond. Max /24 (256 addresses). Runs parallel pings. timeout: per-host wait in seconds. Returns list of alive IPs.
- `pop3_check` — Check POP3 server connectivity. Reads server greeting and tests STARTTLS capability for port 110; uses implicit TLS for port 995. Does not authenticate.
- `port_check` — Check if a TCP port is open on a host. port: 1-65535. timeout: 1-300 s. Supports IPv4 and IPv6.
- `reverse_dns` — Reverse DNS lookup for an IP address — returns the PTR hostname.
- `reverse_dns_bulk` — Reverse DNS lookup for multiple IP addresses at once. ips: comma-separated IPv4 or IPv6 addresses (max 50). Returns PTR hostname for each IP, or an error if lookup fails.
- `scan_common_ports` — Scan 17 commonly used ports on a host and report which are open (FTP, SSH, HTTP, HTTPS, SMTP, DNS, MySQL, PostgreSQL, RDP, SMB, etc.). Faster alternative to running port_check 17 times.
- `smtp_check` — Check an SMTP server: connectivity, banner, advertised capabilities, and STARTTLS support. port: 25 (SMTP), 465 (SMTPS/SSL), 587 (submission). check_starttls: attempt STARTTLS upgrade on port 25/587.
- `snmp_check` — Send an SNMPv2c GetRequest for sysDescr (OID 1.3.6.1.2.1.1.1.0) over UDP and verify the response. community: SNMP community string (default 'public'). Returns whether SNMP is reachable and the raw response bytes length.
- `ssh_check` — Check SSH server connectivity and retrieve the server banner (SSH version string, e.g. 'SSH-2.0-OpenSSH_8.9'). Does not attempt authentication.
- `subnet_info` — Parse an IPv4 or IPv6 CIDR block: network address, host range, host count, and whether it is a private range. IPv4 also returns broadcast and netmask.
- `tcp_banner` — Connect to any TCP port and read the initial server banner. Useful for identifying unknown services or verifying custom TCP servers. Returns raw banner text.
- `tls_version_check` — Test which TLS protocol versions a server accepts (TLS 1.2, TLS 1.3). Also returns the negotiated cipher suite and certificate subject for each accepted version. Useful for security audits — TLS 1.0 and 1.1 should be disabled.
- `whois` — Look up WHOIS registration data for a domain or IP address. Output is truncated at 8000 characters.

## Related servers

- UnClick (1658 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- Yaver (812 tools) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- Crow (587 tools) — https://policylayer.com/tools/kh0pper-crow.md
- Fortimanager (584 tools) — https://policylayer.com/tools/jmpijll-fortimanager-mcp.md
- TinyFn (572 tools) — https://policylayer.com/tools/io-tinyfn-tinyfn.md
- Mcp (571 tools) — https://policylayer.com/tools/io-github-2s-io-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=aaronckj-mcp-nettools · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/aaronckj-mcp-nettools
