Packetrove
Open-source IP address and CIDR tools for network calculations and public IP lookup.
使うべきか
品質と安全性
検出事項(11)
- HIGH
- MEDIUMcidr-cover 内
- MEDIUMcidr-subtract 内
- MEDIUMrange-to-cidrs 内
- MEDIUMcertificate-bundle 内
- MEDIUMpublic-ip 内
- LOWcidr-cover 内
- LOWcidr-subtract 内
- LOWrange-to-cidrs 内
- LOWcertificate-bundle 内
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"packetrove": {
"url": "https://api.packetrove.com/mcp"
}
}
}リモートエンドポイント
https://api.packetrove.com/mcpstreamable-httpできること
ツール一覧
ツール(5)
🟢cidr-cover(inputs)
Use when combining a selected group of firewall allowlist or blocklist entries into one smallest covering CIDR, or when checking the exact extra coverage. Accept 1 to 1,000 IP addresses or CIDRs from one address family, up to 64 characters each; normalize host bits and count overlaps once. Return the canonical CIDR, inclusive range, and exact decimal-string counts, including additionalAddressCount. The range may allow or block additional addresses. This computes one CIDR for the supplied inputs; it does not optimize an entire list against an entry limit or change firewall rules. Remote MCP calls submit inputs to this server; the calculation makes no outbound network requests. Operational events record the tool name, success or error, a controlled error code, and a traffic source classification. Verified automated checks may also record an automation run identifier. Events exclude inputs, results, raw request headers, and automation tokens. Cloudflare may attach platform metadata. Privacy policy: https://packetrove.com/privacy.
入力スキーマ
{
"type": "object",
"properties": {
"inputs": {
"minItems": 1,
"maxItems": 1000,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 64
},
"description": "IP addresses or CIDRs from one address family. Surrounding whitespace is ignored during parsing; CIDRs with host bits are normalized."
}
},
"required": [
"inputs"
],
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false
}出力スキーマ
{
"type": "object",
"properties": {
"family": {
"type": "string",
"enum": [
"ipv4",
"ipv6"
]
},
"normalizedInputs": {
"minItems": 1,
"maxItems": 1000,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 64
},
"description": "Canonical CIDRs in input order. Individual addresses become /32 or /128. Duplicates are retained here."
},
"cidr": {
"type": "string",
"minLength": 1,
"maxLength": 64,
"description": "The smallest single canonical CIDR containing every input address."
},
"range": {
"type": "object",
"properties": {
"first": {
"type": "string",
"minLength": 1
},
"last": {
"type": "string",
"minLength": 1
}
},
"required": [
"first",
"last"
],
"additionalProperties": false
},
"inputAddressCount": {
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "Number of distinct addresses in the union of the inputs."
},
"coveredAddressCount": {
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "Number of all addresses in the resulting CIDR."
},
"additionalAddressCount": {
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "Covered address count minus input address count."
}
},
"required": [
"family",
"normalizedInputs",
"cidr",
"range",
"inputAddressCount",
"coveredAddressCount",
"additionalAddressCount"
],
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false
}🟢cidr-subtract(include, exclude)
Use to prepare WireGuard AllowedIPs exceptions or calculate remaining address space relative to supplied include and exclude lists. Compute union(include) minus union(exclude) as a minimal sorted canonical CIDR list, without adding addresses. Use one address family, a nonempty include list, and at most 1000 entries across both lists, up to 64 characters each. Exclude may be empty. Normalize host bits and count overlaps once. Return cidrs, normalizedInclude, normalizedExclude, and exact decimal-string includedAddressCount, removedAddressCount, remainingAddressCount. Complete removal returns an empty list; more than 10000 output CIDRs returns an error without a partial result. Error issues identify include or exclude and the zero-based entry index. Remote calls submit inputs to this server; the browser calculates locally. This does not inspect live allocation, configure WireGuard, or change firewall rules. Operational events record the tool name, success or error, a controlled error code, and a traffic source classification. Verified automated checks may also record an automation run identifier. Events exclude inputs, results, raw request headers, and automation tokens. Cloudflare may attach platform metadata. Privacy policy: https://packetrove.com/privacy.
入力スキーマ
{
"type": "object",
"properties": {
"include": {
"minItems": 1,
"maxItems": 1000,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 64
},
"description": "The nonempty included address space. Use at most 1,000 entries across include and exclude, from one address family."
},
"exclude": {
"maxItems": 1000,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 64
},
"description": "Ranges to remove from the included address space. An empty array simplifies the exact include union."
}
},
"required": [
"include",
"exclude"
],
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false
}出力スキーマ
{
"type": "object",
"properties": {
"family": {
"type": "string",
"enum": [
"ipv4",
"ipv6"
]
},
"normalizedInclude": {
"minItems": 1,
"maxItems": 1000,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 64
}
},
"normalizedExclude": {
"maxItems": 1000,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 64
}
},
"cidrs": {
"maxItems": 10000,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 64
}
},
"includedAddressCount": {
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "Exact number of addresses as a base-10 string, including network and broadcast addresses."
},
"removedAddressCount": {
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "Exact number of addresses as a base-10 string, including network and broadcast addresses."
},
"remainingAddressCount": {
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "Exact number of addresses as a base-10 string, including network and broadcast addresses."
}
},
"required": [
"family",
"normalizedInclude",
"normalizedExclude",
"cidrs",
"includedAddressCount",
"removedAddressCount",
"remainingAddressCount"
],
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false
}🟢range-to-cidrs(start, end)
Use to prepare an exact CIDR allowlist from one inclusive start/end IPv4 or IPv6 range. Pass start and end IP addresses of the same family, without CIDR prefixes, at most 64 characters each; end must be at or after start. Return canonical range.first and range.last, minimal sorted cidrs, cidrCount, and exact decimal-string addressCount, without adding addresses. Equal endpoints return one /32 or /128; complete address spaces return /0. Invalid inputs identify the start or end field; reversed endpoints are never swapped. Browser calculations stay local; remote MCP calls submit endpoints to this server. This does not inspect live address usage, modify firewall rules, or export vendor-specific ACLs. Operational events record the tool name, success or error, a controlled error code, and a traffic source classification. Verified automated checks may also record an automation run identifier. Events exclude inputs, results, raw request headers, and automation tokens. Cloudflare may attach platform metadata. Privacy policy: https://packetrove.com/privacy.
入力スキーマ
{
"type": "object",
"properties": {
"start": {
"type": "string",
"minLength": 1,
"maxLength": 64,
"description": "Inclusive start IP address. Use IPv4 or IPv6 without a CIDR prefix; surrounding whitespace is ignored."
},
"end": {
"type": "string",
"minLength": 1,
"maxLength": 64,
"description": "Inclusive end IP address, in the same family and at or after start. Endpoints are never silently swapped."
}
},
"required": [
"start",
"end"
],
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false
}出力スキーマ
{
"type": "object",
"properties": {
"family": {
"type": "string",
"enum": [
"ipv4",
"ipv6"
]
},
"range": {
"type": "object",
"properties": {
"first": {
"type": "string"
},
"last": {
"type": "string"
}
},
"required": [
"first",
"last"
],
"additionalProperties": false,
"description": "Canonical inclusive start and end IP addresses."
},
"cidrs": {
"minItems": 1,
"maxItems": 254,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 64
},
"description": "Complete minimal CIDR list, sorted by network address, with no gaps, overlaps, or additional addresses."
},
"cidrCount": {
"type": "integer",
"minimum": 1,
"maximum": 254
},
"addressCount": {
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "Exact number of addresses as a base-10 string, including network and broadcast addresses."
}
},
"required": [
"family",
"range",
"cidrs",
"cidrCount",
"addressCount"
],
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false
}🟢certificate-bundle(pem, hostname, leafIndex)
Use to inspect a supplied PEM certificate bundle before TLS configuration. Accept pem with 1–16 CERTIFICATE blocks and at most 49152 UTF-8 bytes, optional ASCII DNS hostname, and optional zero-based leafIndex. Reject private keys and unsupported blocks without echoing them. Return original certificate positions, Subject, Issuer, Common Name, SANs, validity, CA and Key Usage flags, SHA-256 fingerprints, independently checked candidate links, explicit leaf ambiguity, and stable findings with severity, observed evidence, and nextAction. Verify signatures cryptographically; name matching alone is not verification. Missing supplied issuers are informational, and a failed candidate does not invalidate another viable path. Hostname checks use DNS SAN with one-label complete leftmost wildcards and no Common Name fallback. Results use this server's evaluation time and do not establish client trust, full RFC 5280 path validity, revocation status, or deployment safety. This remote call transmits certificates and hostname to the server; the website checks locally. Certificate input and details never enter application logs. Do not submit private keys. Operational events record the tool name, success or error, a controlled error code, and a traffic source classification. Verified automated checks may also record an automation run identifier. Events exclude inputs, results, raw request headers, and automation tokens. Cloudflare may attach platform metadata. Privacy policy: https://packetrove.com/privacy.
入力スキーマ
{
"type": "object",
"properties": {
"pem": {
"type": "string",
"maxLength": 49152,
"description": "One or more PEM CERTIFICATE blocks, with only whitespace between blocks. At most 48 KiB of UTF-8 and 16 blocks. Private keys and other block types are rejected."
},
"hostname": {
"description": "Optional ASCII DNS hostname, including pre-converted IDNA A-labels. No URL, port, IP address, or wildcard. Blank skips identity checking.",
"type": "string",
"maxLength": 255
},
"leafIndex": {
"description": "Zero-based original position of a non-CA certificate. Required to resolve multiple possible leaves for hostname checking.",
"type": "integer",
"minimum": 0,
"maximum": 15
}
},
"required": [
"pem"
],
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false
}出力スキーマ
{
"type": "object",
"properties": {
"evaluatedAt": {
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$",
"description": "Evaluation time from this runtime clock, not a deployment observation."
},
"certificates": {
"minItems": 1,
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"index": {
"type": "integer",
"minimum": 0,
"maximum": 15,
"description": "Zero-based original input position; duplicates retain their positions."
},
"line": {
"type": "integer",
"minimum": 1,
"maximum": 9007199254740991,
"description": "One-based input line of the BEGIN boundary."
},
"subject": {
"type": "string"
},
"issuer": {
"type": "string"
},
"commonName": {
"type": [
"string",
"null"
]
},
"serialNumber": {
"type": "string"
},
"sans": {
"type": "array",
"items": {
"type": "object",
"properties": {
"type": {
"type": "string"
},
"value": {
"type": "string"
}
},
"required": [
"type",
"value"
],
"additionalProperties": false
}
},
"notBefore": {
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$"
},
"notAfter": {
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$"
},
"ca": {
"type": "boolean"
},
"basicConstraintsPresent": {
"type": "boolean"
},
"keyCertSign": {
"type": [
"boolean",
"null"
]
},
"fingerprintSha256": {
"type": "string",
"pattern": "^(?:[0-9A-F]{2}:){31}[0-9A-F]{2}$"
},
"signatureAlgorithm": {
"type": "string"
},
"selfSignature": {
"anyOf": [
{
"type": "string",
"enum": [
"verified",
"failed",
"unsupported",
"unavailable"
]
},
{
"type": "null"
}
]
}
},
"required": [
"index",
"line",
"subject",
"issuer",
"commonName",
"serialNumber",
"sans",
"notBefore",
"notAfter",
"ca",
"basicConstraintsPresent",
"keyCertSign",
"fingerprintSha256",
"signatureAlgorithm",
"selfSignature"
],
"additionalProperties": false
}
},
"relationships": {
"maxItems": 240,
"type": "array",
"items": {
"type": "object",
"properties": {
"childIndex": {
"type": "integer",
"minimum": 0,
"maximum": 15
},
"issuerIndex": {
"type": "integer",
"minimum": 0,
"maximum": 15
},
"signature": {
"type": "string",
"enum": [
"verified",
"failed",
"unsupported",
"unavailable"
]
},
"issuerEligible": {
"type": "boolean",
"description": "basicConstraints CA=true and, if present, Key Usage permits keyCertSign. Does not include validity, trust, or full path constraints."
},
"keyIdentifierMatch": {
"type": [
"boolean",
"null"
]
}
},
"required": [
"childIndex",
"issuerIndex",
"signature",
"issuerEligible",
"keyIdentifierMatch"
],
"additionalProperties": false
}
},
"leafIndexes": {
"maxItems": 16,
"type": "array",
"items": {
"type": "integer",
"minimum": 0,
"maximum": 15
},
"description": "First occurrences of distinct non-CA certificates; these are possible leaves, not a verified deployment selection."
},
"selectedLeafIndex": {
"anyOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 15
},
{
"type": "null"
}
]
},
"hostname": {
"anyOf": [
{
"type": "object",
"properties": {
"expected": {
"type": "string"
},
"status": {
"type": "string",
"enum": [
"matched",
"mismatched",
"ambiguous",
"no-leaf"
]
}
},
"required": [
"expected",
"status"
],
"additionalProperties": false
},
{
"type": "null"
}
]
},
"findings": {
"type": "array",
"items": {
"type": "object",
"properties": {
"code": {
"type": "string",
"enum": [
"DUPLICATE_CERTIFICATE",
"CERTIFICATE_EXPIRED",
"CERTIFICATE_NOT_YET_VALID",
"SELF_SIGNED_CERTIFICATE",
"SELF_SIGNATURE_FAILED",
"SIGNATURE_UNSUPPORTED",
"SIGNATURE_CHECK_UNAVAILABLE",
"ISSUER_NOT_IN_BUNDLE",
"CANDIDATE_SIGNATURE_FAILED",
"ISSUER_NOT_CA",
"ISSUER_KEY_USAGE_REJECTED",
"ISSUER_KEY_ID_MISMATCH",
"MULTIPLE_ISSUERS",
"LEAF_SELECTION_REQUIRED",
"NO_LEAF_CERTIFICATE",
"HOSTNAME_MATCH",
"HOSTNAME_MISMATCH"
]
},
"severity": {
"type": "string",
"enum": [
"error",
"warning",
"info"
]
},
"certificateIndexes": {
"maxItems": 16,
"type": "array",
"items": {
"type": "integer",
"minimum": 0,
"maximum": 15
}
},
"observed": {
"type": "string"
},
"evidence": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {
"type": [
"string",
"number",
"boolean",
"null"
]
}
},
"nextAction": {
"type": "string"
}
},
"required": [
"code",
"severity",
"certificateIndexes",
"observed",
"evidence",
"nextAction"
],
"additionalProperties": false
}
}
},
"required": [
"evaluatedAt",
"certificates",
"relationships",
"leafIndexes",
"selectedLeafIndex",
"hostname",
"findings"
],
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"description": "Structural and cryptographic observations about the supplied bundle. Not full RFC 5280 path validation, client trust, revocation checking, or deployment safety. Candidate failures do not invalidate other paths."
}🟢public-ip
Use to inspect the public IPv4 or IPv6 address observed for the connection making this MCP tool call. Takes an empty object and returns ip and family. This is the MCP client connection: a hosted AI client may observe its own exit address, not the user device address. If the user needs their browser or computer connection, direct them to the web tool or a CLI running on that machine. A VPN or proxy changes the observed path. One call observes one address family; it does not discover private local addresses, an address before a proxy, or both address families. The application does not store or log results, and no firewall rules are changed. Cloudflare Worker subrequests can have platform-specific address semantics; the result is not an identity proof. Operational events record the tool name, success or error, a controlled error code, and a traffic source classification. Verified automated checks may also record an automation run identifier. Events exclude inputs, results, raw request headers, and automation tokens. Cloudflare may attach platform metadata. Privacy policy: https://packetrove.com/privacy.
入力スキーマ
{
"type": "object",
"properties": {},
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false
}出力スキーマ
{
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"oneOf": [
{
"type": "object",
"properties": {
"family": {
"type": "string",
"const": "ipv4"
},
"ip": {
"type": "string",
"format": "ipv4",
"pattern": "^(?:(?:25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9][0-9]|[0-9])\\.){3}(?:25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9][0-9]|[0-9])$"
}
},
"required": [
"family",
"ip"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"family": {
"type": "string",
"const": "ipv6"
},
"ip": {
"type": "string",
"format": "ipv6",
"pattern": "^(([0-9a-fA-F]{1,4}:){7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:))$"
}
},
"required": [
"family",
"ip"
],
"additionalProperties": false
}
],
"description": "The IP address observed for this request. A VPN, proxy, or hosted client can change whose exit address is observed. One request observes one address family."
}コミュニティ
エビデンス