NetsCLI

io.github.fstubnerv0.3.4Updated Oct 4, 2026

Network scanner for AI agents: discover hosts, scan TCP and UDP ports, query DNS and mDNS.

Overview

AI-generated overview

Lets an assistant discover hosts and scan TCP/UDP ports, query DNS and mDNS, and inspect network devices from the local machine.

What it does
NetsCLI exposes a network scanner to an agent as MCP tools. Nine tools are available by default: discover, scan, ping, DNS, ARP, inspect, sweep, interfaces and mDNS; packet-capture builds add four more. It can find hosts on the local subnet, check whether specific ports are open, resolve DNS records, and look up ARP entries with vendor information. The same core also ships as a CLI, terminal UI and desktop app.
When to use it
Useful when an assistant needs to answer questions about the local network, such as which device just joined or whether a port is open on a host, without shelling out and parsing human-readable output. It suits home-lab and LAN troubleshooting on a desktop machine.
Requirements
Runs locally over stdio as the npm package netscli, started with the serve argument; a Rust toolchain or a platform package manager (Homebrew, winget, cargo) is used to install it. Desktop only, no web execution. No accounts or API keys are declared. The environment variable NETSCLI_MCP_ALLOW_PUBLIC_TARGETS controls whether targets outside your own networks are allowed.
Before you install
By default scanning is limited to your own networks; setting NETSCLI_MCP_ALLOW_PUBLIC_TARGETS to 1 lets the assistant scan targets outside them, which can be intrusive or unlawful against systems you do not own. Scanning sends traffic to hosts and may be logged or blocked. Packet-capture builds need elevated capture permissions.

Installation

In SourceWeft

  1. Open NetsCLI in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

[NETSCLI]

A network scanner written in Rust. CLI, terminal UI, desktop app, and MCP server. One library behind all four.

[CI] [crates.io] [Release] [Downloads] [License: MIT]

Documentation · Install · Changelog

Why this exists

The terminal UI came first. I wanted to understand how the newer TUIs work, the ones coding agents like Claude Code have put real effort into. Autocomplete, command history, in-place progress, and a UI that does not take over the terminal, so scrollback and copying text keep working. Building one seemed like the way to learn it, and a network scanner gave it something to do.

The MCP server came next. I thought it would be interesting to let an agent work with a network that way. Ask which device just joined, or whether port 22 is open on some host, instead of shelling out to another tool and parsing output that was written for a person to read.

Then the CLI, for programmatic use. A script or a cron job wants one command and JSON back, not an interactive session.

The desktop app came last. Some people would rather have a GUI than a terminal, and honestly I sometimes prefer it myself over running the commands locally.

Three of them are the same binary. netscli <command> is the CLI, netscli on its own opens the terminal UI, and netscli serve starts the MCP server. The desktop app is a separate download over the same core.

Screenshots

Install

bash
# macOS / Linuxbrew tap fstubner/tap && brew install netscli
# Windowswinget install netscli        # CLI, TUI and MCP serverwinget install netscli-gui    # desktop app
# Any platform, via cargocargo install netscli

Desktop installers for Windows, macOS and Linux are attached to every release.

Scoop, the AUR, the one-line install scripts, packet-capture builds and signature verification are all covered in the install guide.

Usage

bash
netscli discover                     # find hosts on the local subnetnetscli scan 192.168.1.10 -p 22,80,443netscli inspect example.com          # ping + scan + resolvenetscli dns example.com              # all record typesnetscli arp                          # ARP table with vendor lookupnetscli interfaces

Every non-interactive command takes --json or --yaml, so results pipe straight into jq, and the ones that return a list also take --csv and --md.

Run netscli with no arguments for the terminal UI: slash commands with autocomplete, command history, scrollback and /export.

Full command reference: CLI · TUI · desktop app

MCP server

json
{  "mcpServers": {    "netscli": {      "command": "netscli",      "args": ["serve"]    }  }}

Nine tools by default: discover, scan, ping, DNS, ARP, inspect, sweep, interfaces and mDNS. Packet-capture builds add four more. Details and the full schemas are in the MCP guide.

Documentation

PageCovers
OverviewWhat it does, the interface model, safety limits
InstallationEvery install route, per platform
CLICommands, flags, structured output
Terminal UISlash commands and session behaviour
Desktop appTabs, filters, exports
MCP serverTools, schemas, agent setup
OperationsWhat each scan actually does
Result modelShape of the JSON and YAML output
Packet captureRequirements and the pcap builds
Core libraryUsing netscli-core directly

Contributing

Issues and pull requests are welcome. Building from source, the desktop app dev loop, packet-capture builds and the repository layout are all in CONTRIBUTING.md.

License

MIT

Source: README.md at commit 7a84ca7

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.3.4LatestOct 4, 2026