sovereign AI operations for network and security teams
deterministic decides · the model explains · a human approves
mechub is an ecosystem of self-hosted, MCP-driven automation for the people who run firewalls, networks, and security operations at scale. It puts real AI leverage in every operator's hands without one byte of operational data leaving the building, and with better attribution than before AI arrived.
A gateway-brokered agent platform, not a chatbot with credentials: agents reach infrastructure only through MCP servers fronting each management plane, every tool call is scoped and audited, and autonomy is granted rung by rung, enforced by token scope at the server rather than by prompt.
mechub — Machine Executed & Checked · Hub.
It started as mechanic hub: a workshop for network-security tools you can open up and work on. It now also says how they work — machines execute the change, deterministic checks decide whether it stands, a human approves, and the hub is where every vendor's MCP server meets, on hardware you own.
| Layer | Projects |
|---|---|
| Foundation | mecmcp · rustnetconf · rustez |
| MCP servers | rustjunosmcp · rustpanosmcp · rustsdcmcp · rustmistmcp · rustproxmoxmcp · rustunifimcp · rustfortimcp · rustopnsmcp |
| Data | ssdf — sovereign security data fabric |
| Evaluation | mechubbench — tool-call benchmark corpus and runner for network-automation agents |
| Skills & tools | fwskillsshare · firewallintentconverter · fwconfigsantizer · srxsync |
- Self-hosted by default. Your realm, your models, your rules.
- Deterministic decides. Code makes the safety-relevant call; the model explains it; a human approves it.
- Honest maturity. If something is partial or unverified, we say so.
Public mechub projects are MIT licensed. Report vulnerabilities privately via the Security tab of the affected repository.