Skip to content
Back to skills

Mikromcp

ASecurity

Use when managing, configuring, or troubleshooting MikroTik RouterOS devices through the MikroMCP server — picking the right tool, running safe (dry-run, confirmed, rollback-able) changes, fleet operations, and diagnosing network issues.

  • 72 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added August 30, 2026
ai-agentsgodocumentation

Works with

  • cli
  • mcp

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned October 7, 2026

npx -y skills add AliKarami/MikroMCP --skill mikromcp --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Mikromcp?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Mikromcp
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/alikarami-mikromcp/badge)](https://www.skillsdirectory.com/skills/alikarami-mikromcp)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: mikromcp
description: Use when managing, configuring, or troubleshooting MikroTik RouterOS devices through the MikroMCP server — picking the right tool, running safe (dry-run, confirmed, rollback-able) changes, fleet operations, and diagnosing network issues.
---

# Driving MikroMCP

MikroMCP exposes MikroTik RouterOS management as MCP tools (over stdio or HTTP).
This skill is about operating those tools well and safely. It does not reproduce
RouterOS documentation — when you need to know what a RouterOS field means, see
`references/routeros-docs.md` and fetch the linked official page.

## When to use

- Configuring, inspecting, or troubleshooting a MikroTik router via MikroMCP tools.
- Rolling a change across many routers.

## When not to use

- Devices that are not MikroTik/RouterOS.
- Tasks with no MikroMCP server connected.

## First moves

1. Establish the target router. Tools take an optional `routerId`. If omitted,
   MikroMCP uses `MIKROMCP_DEFAULT_ROUTER`, or the sole configured router. If
   several routers exist and none is defaulted, ask which one.
2. Orient before changing anything: `get_system_status`, then `list_interfaces`
   (and the relevant `list_*` for the area you're touching).

## Golden rules (the safety spine)

1. **Reads are safe; treat every write as consequential.**
2. **Dry-run first.** Call a write tool with `dryRun: true`, show the diff, then
   apply for real. Never skip this for a non-trivial change.
3. **Confirmation tokens.** Destructive tools may require a two-step confirm: the
   first call returns an approval requirement + token; repeat the call with
   `confirmationToken`. This is a guardrail — explain it, don't try to bypass it.
4. **Writes are idempotent.** `already_exists` and `no_change` are SUCCESS, not
   errors. A `CONFLICT` means the resource exists with different config — resolve
   it deliberately (see `references/safety-and-recovery.md`).
5. **Rollback exists.** Write tools snapshot+journal first. To undo, use
   `rollback_change` with the journal ID. Know this before bulk changes.
6. **Prefer dedicated tools over `run_command`.** Use `run_command` only when no
   dedicated tool covers the need.

## Intent → tool quick index

| I want to… | Tool |
|---|---|
| See device health/uptime/version | `get_system_status` |
| List interfaces | `list_interfaces` |
| Add/serve an IP on an interface | `manage_ip_address` |
| Block/allow traffic | `manage_firewall_rule` |
| Port-forward / NAT | `manage_firewall_rule` (table `nat`) |
| Add a static route | `manage_route` |
| Add a DNS record | `manage_dns_entry` |
| See/assign DHCP leases | `list_dhcp_leases`, `manage_dhcp_lease` |
| See who's connected (WiFi) | `list_wifi_clients` |
| Test connectivity | `ping`, `traceroute` |
| Read the same data across many routers | `bulk_read` |
| Run a change across many routers | `bulk_execute` |
| Undo a change | `rollback_change` |

Full enumeration of every tool by family: `references/tool-map.md`.

## Core workflows

### Make a safe config change
1. `list_*` the area to capture current state.
2. Call the `manage_*` tool with `dryRun: true`; read the returned diff.
3. If a confirmation token is required, re-issue with `confirmationToken`.
4. Apply for real; confirm the `action` in the result (`created`/`updated`).
5. Note the journal ID in case you need `rollback_change`.
6. Re-read with the same `list_*` and compare with the intent — RouterOS has no
   commit step, so this is the only check that the change landed as meant.

Several dependent writes (a routing table, then a route in it, then a rule that
uses it): `plan_changes` (up to 10 steps, all dry-run) → review → `apply_plan`.
It stops at the first failed step and journals each step separately.

### Diagnose connectivity
1. `get_system_status` and `list_interfaces` to confirm links are up.
2. `ping` the target from the router; `traceroute` if it fails partway.
3. Check `list_routes`, `list_firewall_rules`, `list_dns_entries` as the symptom
   suggests. Cross-check field meanings via `references/routeros-docs.md`.

### Fleet rollout
1. Capture current state across the fleet with `bulk_read` (read-only tools
   only; it refuses writes and `ping`/`traceroute`/`torch`/`bandwidth_test`).
2. Validate the change on ONE router first (dry-run → apply).
3. `bulk_execute` with the tool + params, targeting routerIds or a tag.
4. For any write tool, complete the fleet confirmation-token step: tell the user which
   routers and what change the token covers, and re-submit only after they agree.
5. Review per-router succeeded/failed counts; `rollback_change` per-router if needed.

### Advise on an upgrade or version-specific behaviour
1. Take the exact version from `get_system_status`, not `rosVersion` from
   `list_routers` and not the router's own update check — both can lag.
2. Read the release notes from MikroTik's upgrade server
   (`references/routeros-docs.md`): the newest release on the router's channel,
   and the notes of every release after the installed one. Do this before
   recommending anything, and say what they contain.

### Recover from an error
1. Read the error `code`/`category` and `suggestedAction`.
2. Map it to a next step via the error→action table in
   `references/safety-and-recovery.md`.

## Router permissions by transport

- `run_command`, `export_config` and `ping` log in over SSH: the router user's
  group needs the `ssh` policy, and a key in `/user ssh-keys` turns off password
  login for that user (`/ip ssh password-authentication`).
- `traceroute`, `torch` and every other tool run over REST: no `ssh` needed, but
  `traceroute` and `torch` need `test`, and `torch` also `sniff`.

## Pointers

- Need a tool not in the quick index → `references/tool-map.md`.
- Need RouterOS field meaning, defaults, or version differences →
  `references/routeros-docs.md` (fetch the linked page; don't guess).
- Hit an error, a CONFLICT, or a destructive/confirmation flow →
  `references/safety-and-recovery.md`.

Files in this skill

  • SKILL.md4.4 KB
  • references/routeros-docs.md2 KB
  • references/safety-and-recovery.md3.1 KB
  • references/tool-map.md12.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…