marzban-mcp

MCPcon attestation
v0.3.0io.github.Ilmar7786UnknownActualizado hace 29 dnpmGitHub

Manage Marzban panels through the Model Context Protocol.

Funciona en
ClaudeCursorCopilotGemini

Inferido de los transportes que declara este listado (stdio). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Build con attestation
Una attestation de procedencia verificada vincula este artefacto al repositorio listado. Nadie ha reclamado todavía el listado: esto demuestra dónde se construyó el código, no quién lo respalda.
hace 29 dÚltima actualización
Necesita 1 credencial antes de poder ejecutarse
  • MARZBAN_PASSWORDClave de APIobligatoria

    Marzban administrator password.

Declarado por el autor en el registro oficial de MCP. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquete
Autorio.github.Ilmar7786
LicenciaUnknown
Versión0.3.0
Fuentenpm+mcp-registry
Estado de confianza
A
85/100Fiable
✓Listado en el índice de Forge+10/10
✓Identidad verificada · build con attestation+20/20
—Firma de publicación Ed25519+0/5
→ Se incluye automáticamente cuando el publicador ejecuta `forge publish`
—Verificación de dominio+0/5
→ Publicador: aloja /.well-known/forge.json en la página del paquete con { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Coincidencia de maintainer en npm+0/5
→ Publicador: añade el login de GitHub verificado a los maintainers del paquete de npm (npm owner add <login>)
✓Análisis CVE · limpio+30/30
✓Análisis estático · limpio+20/20
Pégalo en Claude Code, Cursor o cualquier asistente de IA para corregir todas las carencias
EstadoIdentidad verificada
PublicadorSin verificar
FirmaSin firmar
Dominio—
Procedencia✓ Verificado con Sigstore · fa0f7da
Dependencias✓ 20 resueltas+ · ninguna vulnerable
Superficie de herramientas24 herramientas · 1 privilegiadas
Análisis de seguridad✓ Limpiov0.3.0 · hace 4 d¿Qué tan bien funciona este análisis?
EvaluacionesNinguna
Indexado1 sept 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

24 herramientas · 1 privilegiadas
Extraído estáticamente del paquete publicadov0.3.0 · 4d ago

Leído del código que npm publica realmente, en el momento del análisis. El paquete nunca se ejecutó. Las herramientas registradas dinámicamente en tiempo de ejecución, o escondidas en código empaquetado o minificado, pueden pasarse por alto — así que esto es un mínimo de la superficie de herramientas, no un censo completo.

marzban_config_getReads the Xray core configuration. Defaults to a structural summary (inbound/outbound tags, ports, protocols, routing rule count) — the full config can be tens of KB and this is usually all that's needed. Pass `section` (e.g. "inbounds") for one key's raw JSON, or `section: "raw"` for the entire co…

Reads the Xray core configuration. Defaults to a structural summary (inbound/outbound tags, ports, protocols, routing rule count) — the full config can be tens of KB and this is usually all that's needed. Pass `section` (e.g. "inbounds") for one key's raw JSON, or `section: "raw"` for the entire co…

No se publicó ningún esquema de entrada para esta herramienta.

marzban_config_updateOverwrites the entire Xray core configuration and restarts the core — this is the single most disruptive operation on the whole panel, dropping every active connection while it restarts. Replaces the config wholesale, not a patch. Set `dryRun: true` first to preview the diff against the current con…

Overwrites the entire Xray core configuration and restarts the core — this is the single most disruptive operation on the whole panel, dropping every active connection while it restarts. Replaces the config wholesale, not a patch. Set `dryRun: true` first to preview the diff against the current con…

No se publicó ningún esquema de entrada para esta herramienta.

marzban_core_restartRestarts the Xray core and every connected node, dropping all active connections. Use marzban_config_update instead if the goal is to apply a config change — it restarts the core as part of applying, so a separate restart is rarely needed. Requires confirmation.

Restarts the Xray core and every connected node, dropping all active connections. Use marzban_config_update instead if the goal is to apply a config change — it restarts the core as part of applying, so a separate restart is rarely needed. Requires confirmation.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_hosts_getLists proxy host settings grouped by inbound tag. Flags host fields (remark/address/host/sni/path) that reference an unknown `{VARIABLE}` template token — almost always a typo, since Marzban leaves unknown tokens un-substituted rather than erroring.

Lists proxy host settings grouped by inbound tag. Flags host fields (remark/address/host/sni/path) that reference an unknown `{VARIABLE}` template token — almost always a typo, since Marzban leaves unknown tokens un-substituted rather than erroring.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_hosts_updateOverwrites the entire proxy host configuration (all inbound tags at once) — this replaces the whole map, not a per-tag patch, so include every tag you want to keep. May change subscription links/configs for affected users. Requires confirmation.

Overwrites the entire proxy host configuration (all inbound tags at once) — this replaces the whole map, not a per-tag patch, so include every tag you want to keep. May change subscription links/configs for affected users. Requires confirmation.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_nodes_listLists all connected nodes with their status and Xray version, plus bandwidth usage (uplink/downlink) over the given period. `start`/`end` (ISO datetimes) narrow the usage window; omit both for all-time.

Lists all connected nodes with their status and Xray version, plus bandwidth usage (uplink/downlink) over the given period. `start`/`end` (ISO datetimes) narrow the usage window; omit both for all-time.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_subscription_infoReads subscription status/usage/expiry using the token from a subscription URL (the same public, unauthenticated endpoint client apps use) — for diagnosing a broken subscription link without needing the username. For an admin-side lookup by username, use marzban_users_get instead.

Reads subscription status/usage/expiry using the token from a subscription URL (the same public, unauthenticated endpoint client apps use) — for diagnosing a broken subscription link without needing the username. For an admin-side lookup by username, use marzban_users_get instead.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_revoke_subscriptionIssues a new subscription link for a user and invalidates the old one. Use when a link has leaked or needs rotating — not for routine renewals (use marzban_users_extend for those). Requires confirmation.

Issues a new subscription link for a user and invalidates the old one. Use when a link has leaked or needs rotating — not for routine renewals (use marzban_users_extend for those). Requires confirmation.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_system_statsReports panel-wide stats: CPU/memory usage, user counts by status, and bandwidth totals/speeds, plus the Xray core version and whether it is currently running.

Reports panel-wide stats: CPU/memory usage, user counts by status, and bandwidth totals/speeds, plus the Xray core version and whether it is currently running.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_system_inboundsLists configured inbound proxies grouped by protocol, with tag, network, TLS mode, and port for each. For the raw Xray inbound JSON (routing, stream settings, etc.) use marzban_config_get with section: "inbounds" instead.

Lists configured inbound proxies grouped by protocol, with tag, network, TLS mode, and port for each. For the raw Xray inbound JSON (routing, stream settings, etc.) use marzban_config_get with section: "inbounds" instead.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_listLists users, optionally filtered by status or a search term (matches username/note). Paginated — default 25, max 100 per call; prefer `search` over paging through everyone. For one known username, use marzban_users_get instead.

Lists users, optionally filtered by status or a search term (matches username/note). Paginated — default 25, max 100 per call; prefer `search` over paging through everyone. For one known username, use marzban_users_get instead.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_getFetches one user by username, with a computed summary: data left, days left, usage percent, and whether they are effectively expired (covers the case where status has not caught up with an already-past expire yet).

Fetches one user by username, with a computed summary: data left, days left, usage percent, and whether they are effectively expired (covers the case where status has not caught up with an already-past expire yet).

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_createCreates a new user. `dataLimit` accepts a human size ("10GB"), `expire` a relative duration ("30d") or absolute date — both default to unlimited when omitted. `templateId` fills dataLimit/inbounds/expire from a user template; any field also given explicitly overrides the template value.

Creates a new user. `dataLimit` accepts a human size ("10GB"), `expire` a relative duration ("30d") or absolute date — both default to unlimited when omitted. `templateId` fills dataLimit/inbounds/expire from a user template; any field also given explicitly overrides the template value.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_updatePartially updates a user — only fields you provide are changed, everything else is left as-is. For status changes prefer marzban_users_activate/deactivate/hold (clearer intent, no need to know the raw status enum). For renewing an expiring/expired user prefer marzban_users_extend.

Partially updates a user — only fields you provide are changed, everything else is left as-is. For status changes prefer marzban_users_activate/deactivate/hold (clearer intent, no need to know the raw status enum). For renewing an expiring/expired user prefer marzban_users_extend.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_activateSets a user's status to active.

Sets a user's status to active.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_deactivateSets a user's status to disabled, immediately blocking their access without deleting them.

Sets a user's status to disabled, immediately blocking their access without deleting them.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_holdSets a user's status to on_hold — inactive until their first connection, at which point the on-hold timer starts. Useful for provisioning an account ahead of time without starting its clock.

Sets a user's status to on_hold — inactive until their first connection, at which point the on-hold timer starts. Useful for provisioning an account ahead of time without starting its clock.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_extendRenews a user: adds addDuration to their current expiration (or to now, if they have none or it already passed) and/or addData on top of their current data limit. If the user was expired or limited, status is moved back to active. Use this instead of marzban_users_update for renewals — it reads the…

Renews a user: adds addDuration to their current expiration (or to now, if they have none or it already passed) and/or addData on top of their current data limit. If the user was expired or limited, status is moved back to active. Use this instead of marzban_users_update for renewals — it reads the…

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_usageReports how much data a user has used: total, lifetime total, their current limit, and a breakdown by node. `start`/`end` (ISO datetimes) narrow the per-node breakdown to a period; omit both for all-time.

Reports how much data a user has used: total, lifetime total, their current limit, and a breakdown by node. `start`/`end` (ISO datetimes) narrow the per-node breakdown to a period; omit both for all-time.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_deleteprivilegiadaPermanently deletes a user, along with their subscription link and traffic history. Irreversible — requires confirmation. Prefer marzban_users_deactivate if you only need to block access without losing their data.

Permanently deletes a user, along with their subscription link and traffic history. Irreversible — requires confirmation. Prefer marzban_users_deactivate if you only need to block access without losing their data.

No se publicó ningún esquema de entrada para esta herramienta.

marzban_users_reset_trafficResets used traffic back to zero for one user, or for every user at once when `all: true`. Does not change data_limit or expire. Irreversible — requires confirmation; `all: true` affects every user on the panel in one call.

Resets used traffic back to zero for one user, or for every user at once when `all: true`. Does not change data_limit or expire. Irreversible — requires confirmation; `all: true` affects every user on the panel in one call.

No se publicó ningún esquema de entrada para esta herramienta.

expiring_users_auditFinds users whose subscription is expiring soon (or already expired/limited) and suggests next steps for each.

Finds users whose subscription is expiring soon (or already expired/limited) and suggests next steps for each.

No se publicó ningún esquema de entrada para esta herramienta.

node_diagnosticsInvestigates why a node might be unhealthy: connection status, Xray version, and recent bandwidth.

Investigates why a node might be unhealthy: connection status, Xray version, and recent bandwidth.

No se publicó ningún esquema de entrada para esta herramienta.

traffic_reportSummarizes bandwidth usage across the panel, nodes, and top users for a given period.

Summarizes bandwidth usage across the panel, nodes, and top users for a given period.

No se publicó ningún esquema de entrada para esta herramienta.

24 de 24 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

Manage Marzban panels through the Model Context Protocol.

Palabras clave
mcp
Alternativas
Comparando superficies de herramientas…

Árbol de dependencias

Lo que un análisis de Forge resolvió a partir de los metadatos de npm el 2026-10-01: resolución observada, no una declaración del publicador.

20 paquetes resueltos · 3 directos · ninguno con avisos de seguridad La resolución se detiene en la profundidad 4 y en 60 paquetes.

El rastreo se detuvo en el límite de profundidad 4. Nada por debajo de ese nivel llegó a resolverse.

Declaradas pero no resueltas

9 dependencias declaradas nunca llegaron al árbol. Faltan en la resolución de Forge, no en el paquete.

No se siguen: peerDependencies. Este árbol cubre solo dependencias en tiempo de ejecución, así que lo que estas arrastren nunca se resolvió.