Industrial-AIOps energy edition: IEC-104/DNP3/IEC-61850 read-only OT connectors on iaiops.core.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
English Β· δΈζ
The energy edition of Industrial-AIOps,
split out into its own repo: read-only OT connectors for substation / utility
telecontrol protocols, built on top of iaiops.core.
c104) β RTU / substation telemetrypydnp3) β outstation monitoringpyiec61850, linux-only wheel) β substation IED readsIt reuses the base package's shared governance (audit / budget / risk-tier / undo), cross-protocol brain (data-flow / alarm / OEE / downtime RCA on the normalized ISA-95/18.2 model), and MCP server infrastructure β this repo only adds the three energy connectors + their session builders + MCP tools. Read-first: no control-direction writes are exposed.
Current release: 0.1.11 (requires iaiops>=0.20.3,<1.0). New in 0.1.11 β all three
monitor paths are CI-gated for the first time, and a skipped live test now fails the build
instead of passing it. DNP3 was the holdout: pip install pydnp3 fails on any current Linux,
so this repo inherited the ecosystem's "unbuildable on hosted runners" and
tests/test_dnp3_live.py skipped on every build. It is not unbuildable β opendnp3 compiles
clean, and the 2019 binding layer needed three mechanical fixes, now scripted in
scripts/build_pydnp3.sh and running on real GitHub runners. Also inherits two governance
fixes from iaiops 0.20.3 (pin raised): a call that failed is no longer audited as a
success (which also mis-informed the pattern circuit breaker on every failure), and the
runaway guard can now see a caller retrying a denial forever. Previously in 0.1.10 β a security
fix inherited from the base package: three egress tools this edition mirrors
(stream_publish, stream_publish_event, historian_push) wrote their credential β a NATS
auth token, a TSDB password β into the audit log in the clear, and audit_forward shipped
that row to the configured SIEM. They are defined in iaiops, so this edition could not fix
it alone; the pin moves to iaiops>=0.20.2, and a contract test now fails the build if the
whole registered surface ever again carries an undeclared credential parameter. If you have
passed a token or historian password to these tools, rotate it and check existing audit
rows. The energy connectors themselves take no credential parameters. Previously in 0.1.9 β every tool
ships the MCP ToolAnnotations hints (readOnlyHint / destructiveHint / openWorldHint),
derived from the @governed_tool harness rather than hand-written, so a client can tell a
monitor read from a tool that acts without parsing the [READ]/[WRITE] docstring tag. On the
wire that is 59 tools, 55 read-only and 0 destructive β this edition exposes no control
direction, and that is now enforced by a test rather than only documented. They are hints, not a
gate: the MCP spec forbids relying on annotations for security decisions, and enforcement stays in
@governed_tool. The base pin moved to iaiops>=0.20.1 so the hint derivation is imported from
mcp_server.hints instead of duplicated here.
Previously in 0.1.8 β the base
IAIOPS_READ_ONLY gate was removed in iaiops 0.19.0 (read/write authorisation is the
caller's decision β agent judgement / account management β not the tap's; every tool is
governed and audited via the base @governed_tool harness), so this edition drops it too.
It keeps the IAIOPS_NO_EGRESS=1 gate β a data-exfiltration / airgap axis that withholds
data-shipping tools from list_tools() at registration time. This edition runs its own
FastMCP instance, so the gate is wired into its own main(); without it IAIOPS_NO_EGRESS=1
would still expose historian_push, rca_narrate and the stream_publish* pair mirrored in
from the base brain. The energy connectors themselves are monitor-only and survive the gate
intact. See CHANGELOG.md.
Previously in 0.1.6 β an
audit-hardening pass over the three read-only connectors: DNP3 no longer reports an
offline outstation as online or returns a partial integrity-poll database; IEC-61850 gained
a bounded connect/request timeout and stopped fabricating 0.0/empty-success on failure; the
substation analyzer no longer calls a lone breaker-open a "selective trip"; tests isolate
IAIOPS_HOME; and the base pin was raised to iaiops>=0.14 so the governance endpoint-scoping
fix applies. See CHANGELOG.md Β§0.1.6. (0.1.5 verified the IEC-104 monitor path β a real c104
clientβserver round-trip in a Linux container, tests/test_iec104_live.py.)
Physical RTU / IED remains unverified. Since 0.1.3 the server has
its own MCP identity β iaiops-energy-mcp runs a dedicated FastMCP("iaiops-energy")
instance with energy-specific instructions (IEC-104 / DNP3 / IEC-61850, read-first,
no control/operate), with the base cross-protocol brain tools mirrored onto it β plus
an edition skill (skills/iaiops-energy/SKILL.md, anti-drift-tested against the
registered tool surface) and protocol-consistency contract tests (every tool must
carry the governance marker, a [READ]-style risk tag, an Args: section, and the
canonical {error, hint} error shape; the server refuses to start if any registered
tool lacks the governance marker).
Live substation RTU / IED / IEC-104 field testing is what this package needs most.
The IEC-104, DNP3 and IEC-61850 monitor paths are library-loopback-verified, and all three
now run on every CI build β a skip fails the build rather than passing it. (Since
2026-08-01: DNP3's evidence used to be a single manual run on 2026-07-02, because pydnp3
was believed unbuildable on hosted runners. That belief was wrong β see
scripts/build_pydnp3.sh.) Real RTU / IED hardware remains unverified. If you can run
iaiops doctor against real substation gear in an authorised test environment, we would
very much like to hear the result β verified devices are credited by name in the support
matrix. Report results (protocol + device model + iaiops doctor output) via the base
repo's pinned issue:
π industrial-aiops#28 β Call for field-testing partners (v0.10.0)
Energy targets a distinct buyer (utilities / substations), has heavier
platform-specific deps (pyiec61850 is a linux-only SWIG wheel; pydnp3 builds a
native ext), and its own compliance surface (China's Security Protection of Power
Monitoring Systems regime). Splitting keeps
the base install light. See the base repo's docs/ENERGY-SPINOUT.md for the plan.
iaiops-energy pulls in iaiops (the shared core) automatically.
Point a target at your substation gear in ~/.iaiops/config.yaml
(protocol: iec104|dnp3|iec61850, host, port, common_address / unit_id).
Like the base package, the energy edition rides on a hardened, centrally-managed edge host as a
portable, governed edge application β mapping onto the Margo
edge-interoperability roles (immutable host Β· compliant orchestrator Β· iaiops-energy = the
OT-domain app), deployable as an OCI Managed Container (outbound-only to substation RTUs/IEDs,
no inbound). A container + margo.org/v1-alpha1 application-description skeleton is in
deploy/margo/; the full alignment + honest gap analysis lives in the base repo's
docs/MARGO-ALIGNMENT.md.
The descriptor is validated against Margo's published margo.org/v1-alpha1 LinkML schema on every
PR (CI job margo-descriptor) and passes clean β structural validity only, see
deploy/margo/schema/PROVENANCE.md.
Honest status: a natural Margo edge application, but NOT Margo-compliant yet β image build, hosted+signed package, and a published conformance result are roadmap
β³. No claim of compliance until that result exists, and the schema pass above is not a step toward it: the compliance test suite cannot be run today because it does not exist yet (no conformance repo in themargoorg; a first PR1 vertical slice was still being scoped as of 2026-01-15).
The same honesty ladder as the base repo. Driver codec / API surface is verified
against the real libraries; the mock/monkeypatched unit tests run in CI without
hardware. See the base repo's docs/PREVIEW-VERIFICATION.md runbook for how a
protocol is promoted.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/ot-aiops-energy-edition)<a href="https://allmcps.com/mcp/ot-aiops-energy-edition"><img src="https://allmcps.com/api/badge/ot-aiops-energy-edition?style=directory" alt="OT AIops β Energy edition on AllMCPs" /></a>