# ellmos ControlCenter (npm · ellmos-controlcenter-mcp)

MCP control plane: local server discovery, profiles, capability bundles, and policy audits.

- Trust score: 67/100 (medium)
- Change this week: +43
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-04

## Components

- npm · `ellmos-controlcenter-mcp`: 67/100 (this document), [markdown](https://verifymcp.io/servers/ellmos-ai-ellmos-controlcenter-mcp/ellmos-controlcenter-mcp.md), [page](https://verifymcp.io/servers/ellmos-ai-ellmos-controlcenter-mcp/ellmos-controlcenter-mcp)

## Channel facts

- Registry: `npm`
- Package: `ellmos-controlcenter-mcp`
- Version: `0.2.2`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-04.

- **Supply Chain Security**: 83/100
  - No malware found by supply-chain analysis.
  - CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (148 of 152), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 3 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 66/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 2023 tokens (~101/item across 20 items; 20 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 30/100
  - Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add ellmos-ai-ellmos-controlcenter-mcp -- npx -y ellmos-controlcenter-mcp
```

### Codex

```bash
codex mcp add ellmos-ai-ellmos-controlcenter-mcp -- npx -y ellmos-controlcenter-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "ellmos-ai-ellmos-controlcenter-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "ellmos-controlcenter-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add ellmos-ai-ellmos-controlcenter-mcp --command npx --arg -y --arg ellmos-controlcenter-mcp
```

### Hermes

```yaml
mcp_servers:
  ellmos-ai-ellmos-controlcenter-mcp:
    command: "npx"
    args: ["-y", "ellmos-controlcenter-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "ellmos-ai-ellmos-controlcenter-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "ellmos-controlcenter-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-04 (score 67, 0)

- [security regression] CVE-2026-69207 affects this package: medium
- [security regression] Known CVEs: partial → fail

### 2026-08-02 (score 67, +46)

- [security regression] Provenance: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Malware scan: unverified → pass
- [functional regression] Tool coverage: 100 → unverified
- [functional improvement] License: unverified → pass
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Stability: unverified → 0.23
- [functional improvement] Schema quality: unverified → good
- [functional improvement] Dependency health: unverified → partial
- [functional] Licence: MIT

### 2026-07-31 (score 21, −25)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 46, +22)

- [functional improvement] Tool coverage: unverified → 100

### 2026-07-28 (score 24, −22)

- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified

### 2026-07-27 (score 46)

First indexed and scored.

## MCP tools (20)

### `controlcenter_get_language` (~27 tokens)

ControlCenter Sprache anzeigen

Zeigt die aktuelle ControlCenter-Ausgabesprache und die unterstützten Sprachcodes.

### `controlcenter_set_language` (~44 tokens)

ControlCenter Sprache setzen

Setzt die ControlCenter-Ausgabesprache für diese laufende MCP-Serverinstanz.

Input parameters:

- `language` (string, required): Sprachcode für die ControlCenter-Ausgaben.

### `controlcenter_status` (~27 tokens)

ControlCenter Status

Zeigt einen Überblick über den lokalen MCP-Stack, lokale Server und Claude-Profile.

### `controlcenter_list_local_servers` (~59 tokens)

Lokale MCP-Server listen

Scannt den lokalen MCP-Root und listet gefundene MCP-Repos mit Metadaten auf.

Input parameters:

- `mcpRoot` (string): Optionaler MCP-Root. Standard ist der lokale ellmos-MCP-Ordner.

### `controlcenter_list_stacks` (~69 tokens)

Registrierte Stacks listen

Liest den neutralen Stack-Katalog und seine ellmos.stack.v2-Manifeste, ohne Stack-Komponenten auszuführen.

Input parameters:

- `stacksRoot` (string): Optionaler Pfad zum Ordner mit stacks.catalog.json. Standard ist der lokale .AI/.STACKS-Ordner.

### `controlcenter_describe_stack` (~80 tokens)

Registrierten Stack beschreiben

Zeigt typisierte Komponenten, Pflichtrollen, Policies und Validierungswarnungen für einen registrierten Stack.

Input parameters:

- `stackId` (string, required): Stabile Stack-ID aus stacks.catalog.json.
- `stacksRoot` (string): Optionaler Pfad zum Ordner mit stacks.catalog.json. Standard ist der lokale .AI/.STACKS-Ordner.

### `controlcenter_context_pack` (~81 tokens)

Stack-Kontextpaket erstellen

Erstellt ein kompaktes, rein lesendes Kontextpaket aus einem registrierten Stack-Manifest. Es führt keine Komponenten aus und liest weder Geheimnisse noch Live-Zustände.

Input parameters:

- `level` (string): Umfang des Kontextpakets: short, execution oder full.
- `stackId` (string, required): Stabile Stack-ID aus stacks.catalog.json.

### `controlcenter_list_tools` (~168 tokens)

MCP-Tools listen

Startet lokale oder profildefinierte MCP-Server kontrolliert und liest deren echte Tool-Liste per MCP list_tools aus.

Input parameters:

- `mcpRoot` (string): Optionaler MCP-Root. Standard ist der lokale ellmos-MCP-Ordner.
- `profileName` (string): Optionaler Profilname. Wenn gesetzt, werden die aufgelösten Server dieses Claude-Profils gescannt.
- `profileRoot` (string): Optionaler Profilordner. Standard ist ~/.claude/profiles.
- `serverName` (string): Optionaler Servername, Paketname, mcpName oder Profilservername für einen gezielten Scan.
- `timeoutMs` (integer): Timeout pro Connect- und list_tools-Anfrage in Millisekunden. Standard: 5000.

### `controlcenter_assign_tool_bundles` (~175 tokens)

Tools Capability-Bundles zuordnen

Ordnet echte MCP-Tools anhand ihrer Metadaten den ControlCenter-Capability-Bundles zu.

Input parameters:

- `bundleConfigPath` (string): Optionaler Pfad zu einer Capability-Bundle-Konfiguration.
- `mcpRoot` (string): Optionaler MCP-Root. Standard ist der lokale ellmos-MCP-Ordner.
- `profileName` (string): Optionaler Profilname. Wenn gesetzt, werden die aufgelösten Server dieses Claude-Profils gescannt.
- `profileRoot` (string): Optionaler Profilordner. Standard ist ~/.claude/profiles.
- `serverName` (string): Optionaler Servername für einen gezielten Scan.
- `timeoutMs` (integer): Timeout pro MCP-Tool-Scan in Millisekunden. Standard: 5000.

### `controlcenter_list_bundles` (~80 tokens)

Capability-Bundles listen

Gruppiert lokale MCP-Server in Aufgaben-Bundles wie Software, Filesystem, Automation und Control Plane.

Input parameters:

- `bundleConfigPath` (string): Optionaler Pfad zu einer Capability-Bundle-Konfiguration.
- `mcpRoot` (string): Optionaler MCP-Root. Standard ist der lokale ellmos-MCP-Ordner.

### `controlcenter_suggest_bundles` (~85 tokens)

Capability-Bundles empfehlen

Empfiehlt passende Capability-Bundles für eine Aufgabenbeschreibung.

Input parameters:

- `bundleConfigPath` (string): Optionaler Pfad zu einer Capability-Bundle-Konfiguration.
- `mcpRoot` (string): Optionaler MCP-Root. Standard ist der lokale ellmos-MCP-Ordner.
- `task` (string, required): Aufgabenbeschreibung oder Ziel der Session.

### `controlcenter_list_profiles` (~52 tokens)

Claude-Profile listen

Liest die lokalen Claude-Profile und zeigt Serveranzahl, Vererbung und Dateipfade.

Input parameters:

- `profileRoot` (string): Optionaler Profilordner. Standard ist ~/.claude/profiles.

### `controlcenter_suggest_profile` (~36 tokens)

Profil empfehlen

Empfiehlt ein Claude-Profil anhand der Aufgabenbeschreibung.

Input parameters:

- `task` (string, required): Aufgabenbeschreibung oder Ziel der Session.

### `controlcenter_resolve_profile` (~75 tokens)

Claude-Profil auflösen

Löst ein Claude-Profil inklusive optionaler Vererbung auf und zeigt die resultierenden MCP-Server.

Input parameters:

- `profileName` (string, required): Profilname ohne .json, zum Beispiel software oder ai-lab.
- `profileRoot` (string): Optionaler Profilordner. Standard ist ~/.claude/profiles.

### `controlcenter_switch_profile` (~156 tokens)

Profilwechsel vorbereiten

Bereitet einen Profilwechsel vor, indem ein aufgelöstes --mcp-config-File erzeugt oder als Vorschau angezeigt wird.

Input parameters:

- `launchTemplate` (string): Optionales Startbefehl-Template. Nutze {config} als Platzhalter für den Pfad zur generierten MCP-Config.
- `outputPath` (string): Optionaler Ausgabeort für die generierte MCP-Config.
- `profileName` (string, required): Profilname ohne .json, zum Beispiel software oder ai-lab.
- `profileRoot` (string): Optionaler Profilordner. Standard ist ~/.claude/profiles.
- `write` (boolean): Wenn true, wird die generierte Config geschrieben. Sonst nur Vorschau.

### `controlcenter_audit_profile` (~107 tokens)

Claude-Profil auditieren

Prüft ein aufgelöstes Claude-Profil auf erste Policy-Hinweise wie npx-Starts, Env-Secrets und ungültige Server-Konfigurationen.

Input parameters:

- `policyConfigPath` (string): Optionaler Pfad zu einer Policy-Regel-Konfiguration.
- `profileName` (string, required): Profilname ohne .json, zum Beispiel software oder ai-lab.
- `profileRoot` (string): Optionaler Profilordner. Standard ist ~/.claude/profiles.

### `controlcenter_build_catalog` (~223 tokens)

Lokalen Server-Katalog bauen

Erzeugt einen JSON-Katalog der lokal gefundenen MCP-Server.

Input parameters:

- `bundleConfigPath` (string): Optionaler Pfad zu einer Capability-Bundle-Konfiguration.
- `includeToolAssignments` (boolean): Wenn true, werden Tool-Bundle-Zuordnungen für gescannte Tools in den Katalog aufgenommen.
- `includeTools` (boolean): Wenn true, werden lokale MCP-Server gestartet und echte list_tools-Ergebnisse in den Katalog aufgenommen.
- `mcpRoot` (string): Optionaler MCP-Root. Standard ist der lokale ellmos-MCP-Ordner.
- `outputPath` (string): Optionaler Ausgabeort für den JSON-Katalog.
- `profileName` (string): Optionaler Profilname. Wenn gesetzt, werden die aufgelösten Server dieses Claude-Profils gescannt.
- `profileRoot` (string): Optionaler Profilordner. Standard ist ~/.claude/profiles.
- `timeoutMs` (integer): Timeout pro MCP-Tool-Scan in Millisekunden. Standard: 5000.

### `controlcenter_list_skills` (~134 tokens)

Claude Code Skills listen

Inventarisiert installierte Claude Code Skills aus dem deployte Skills-Ordner und der Quell-Skill-Bibliothek.

Input parameters:

- `deployedOnly` (boolean): Wenn true, werden nur deployte Skills zurückgegeben und die Quell-Skill-Bibliothek nicht gescannt.
- `skillsRoot` (string): Optionaler Pfad zum deployte Skills-Ordner. Standard ist ~/.claude/skills.
- `sourceSkillsRoot` (string): Optionaler Pfad zum Quell-Skill-Bibliotheks-Root. Standard ist der lokale .AI/.SKILLS/skills-Ordner.

### `controlcenter_find_skill` (~208 tokens)

Passende Skills finden

Erkennt, welche Skills zu einer Freitext-Aufgabe bzw. einem Intent passen. Bewertet den gescannten Skill-Katalog lexikalisch über Name, Aliases, Tags, Kategorie und Beschreibung und gibt die besten Kandidaten mit den getroffenen Begriffen zurück.

Input parameters:

- `deployedOnly` (boolean): Wenn true, werden nur deployte Skills zurückgegeben und die Quell-Skill-Bibliothek nicht gescannt.
- `intent` (string, required): Freitext-Aufgabe oder Intent, gegen den der Skill-Katalog gematcht wird.
- `limit` (integer): Maximale Anzahl gerankter Skill-Kandidaten. Standard: 5.
- `skillsRoot` (string): Optionaler Pfad zum deployte Skills-Ordner. Standard ist ~/.claude/skills.
- `sourceSkillsRoot` (string): Optionaler Pfad zum Quell-Skill-Bibliotheks-Root. Standard ist der lokale .AI/.SKILLS/skills-Ordner.

### `controlcenter_list_plugins` (~137 tokens)

Plugins und Module listen

Inventarisiert installierte Claude Code Plugins und lokale ellmos-Module mit ihren Fähigkeiten.

Input parameters:

- `modulesOnly` (boolean): Wenn true, werden nur lokale Module zurückgegeben und Claude Code Plugins nicht gescannt.
- `modulesRoot` (string): Optionaler Pfad zum ellmos-Module-Ordner. Standard ist der lokale .AI/.MODULES-Ordner.
- `pluginsOnly` (boolean): Wenn true, werden nur Claude Code Plugins zurückgegeben und lokale Module nicht gescannt.
- `pluginsRoot` (string): Optionaler Pfad zum Claude Code Plugins-Ordner. Standard ist ~/.claude/plugins.

## Diagnostics

Captured diagnostic sections: Provenance, Vulnerabilities, Dependencies. The full working is on the page: https://verifymcp.io/servers/ellmos-ai-ellmos-controlcenter-mcp/ellmos-controlcenter-mcp#diagnostics

## Score history

- 2026-08-04: 67
- 2026-08-03: 67
- 2026-08-02: 67
- 2026-08-01: 21
- 2026-07-31: 21
- 2026-07-30: 46
- 2026-07-28: 24
- 2026-07-27: 46

## Links

- npm package: https://www.npmjs.com/package/ellmos-controlcenter-mcp
- Socket report: https://socket.dev/npm/package/ellmos-controlcenter-mcp
- Repository: https://github.com/ellmos-ai/ellmos-controlcenter-mcp
- Changelog RSS feed: https://verifymcp.io/servers/ellmos-ai-ellmos-controlcenter-mcp/ellmos-controlcenter-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/ellmos-ai-ellmos-controlcenter-mcp/ellmos-controlcenter-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/ellmos-ai-ellmos-controlcenter-mcp/ellmos-controlcenter-mcp
