# Generic SCPI Instrument (pypi · labmcp-scpi)

Generic MCP server for any SCPI instrument over VISA, TCP or serial, with command allow/deny lists.

- Trust score: 82/100 (high trust)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-30

## Components

- pypi · `labmcp-scpi`: 82/100 (this document), [markdown](https://verifymcp.io/servers/k-dense-ai-labmcp-scpi/labmcp-scpi.md), [page](https://verifymcp.io/servers/k-dense-ai-labmcp-scpi/labmcp-scpi)

## Channel facts

- Registry: `pypi`
- Package: `labmcp-scpi`
- Version: `0.1.3`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-30.

- **Supply Chain Security**: 99/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - Runs hatchling.build at install time, a recognised build step with no custom scripting around it.
  - 2 of 17 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 100/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to K-Dense-AI/lab-instrument-mcps).
  - Clear OSI-approved license (Apache-2.0).
  - Actively maintained (last published 3 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 74/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1871 tokens (~133/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 13/100
  - Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 99/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 96% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 88/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 1 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "scpi_query" implies "send" and declares readOnlyHint instead, contradicting what its own name says it does.
  - An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the Generic SCPI Instrument MCP server?

Generic SCPI Instrument runs locally as a PyPI package, launched with uvx labmcp-scpi. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add k-dense-ai-labmcp-scpi -- uvx labmcp-scpi
```

### Cursor

```json
{
  "mcpServers": {
    "k-dense-ai-labmcp-scpi": {
      "command": "uvx",
      "args": [
        "labmcp-scpi"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "k-dense-ai-labmcp-scpi": {
      "command": "uvx",
      "args": [
        "labmcp-scpi"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add k-dense-ai-labmcp-scpi -- uvx labmcp-scpi
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "k-dense-ai-labmcp-scpi": {
      "type": "local",
      "command": [
        "uvx",
        "labmcp-scpi"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add k-dense-ai-labmcp-scpi --command uvx --arg labmcp-scpi
```

### Hermes

```yaml
mcp_servers:
  k-dense-ai-labmcp-scpi:
    command: "uvx"
    args: ["labmcp-scpi"]
```

### Netclaw

```json
{
  "McpServers": {
    "k-dense-ai-labmcp-scpi": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "labmcp-scpi"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add k-dense-ai-labmcp-scpi -t stdio -c uvx -a labmcp-scpi
```

### Other

```json
{
  "mcpServers": {
    "k-dense-ai-labmcp-scpi": {
      "command": "uvx",
      "args": [
        "labmcp-scpi"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-29 (score 82, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-28 (score 81, +42)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 39, −31)

- [security regression] Tool safety: pass → unverified
- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified
- [functional] Package version: 0.1.2 → 0.1.3

### 2026-09-26 (score 70)

First indexed and scored.

## MCP tools (14)

### `get_connection_info` (~40 tokens)

Get Connection Info

Report which instrument is connected (identity, address, simulated or real),
whether the server is read-only, and the active safety limits. Call this first.

### `get_command_log` (~46 tokens)

Get Command Log

Return the most recent raw commands sent to / replies received from the
instrument (newest last). Useful for debugging and for recording what was done.

Input parameters:

- `limit` (integer)

Output parameters:

- `result` (array)

### `reconnect` (~35 tokens)

Reconnect

Close and re-open the connection to the instrument (e.g. after it was power
cycled or a cable was re-plugged).

### `scpi_primer` (~51 tokens)

Scpi Primer

Concise SCPI syntax guide (long/short forms, queries, compound commands, common
commands, error queue, binary blocks) plus this server's active command policy. Works
without a connection.

### `identify` (~26 tokens)

Identify

Ask the instrument who it is (*IDN?): manufacturer, model, serial number, firmware.

Output parameters:

- `firmware` (string)
- `manufacturer` (string)
- `model` (string)
- `raw` (string): Raw *IDN? reply
- `serial` (string)
- `timestamp` (string)

### `list_visa_resources` (~98 tokens)

List Visa Resources

List GPIB / USBTMC / LAN (VXI-11, HiSLIP) instruments visible to VISA on this computer.
Works without --address. Raw-socket instruments (tcp://host:5025) are not discoverable.

Input parameters:

- `backend` (string): @py = pyvisa-py, @ivi = NI-VISA / Keysight / R&S VISA
- `query` (string): VISA resource filter

Output parameters:

- `available` (boolean): False if PyVISA or a VISA backend is not usable
- `backend` (string)
- `note` (string)
- `resources` (array)
- `simulated` (boolean)

### `scpi_query` (~175 tokens)

Scpi Query

Send ONE read-only SCPI query and return the instrument's text reply.

Only single queries are accepted: the header must end with '?' (parameters such as
'VOLT? MAX' are allowed), with no ';' and no line breaks. Queries with known side
effects (*TST?, *CAL?, CALibration, DIAGnostic) and anything in the lab's query
denylist are refused - use `scpi_write` for those. An unknown query gets no reply
(timeout); the error queue is then reported.

Input parameters:

- `command` (string, required): One SCPI query, e.g. '*IDN?', 'MEAS:VOLT:DC?', 'VOLT? MAX'
- `max_chars` (integer): Truncate longer replies
- `timeout_s`: Reply timeout (default: server's)

Output parameters:

- `command` (string)
- `elapsed_ms` (number)
- `length` (integer): Length of the full response in characters
- `response` (string)
- `timestamp` (string)
- `truncated` (boolean): True if the response was cut to max_chars

### `query_binary_block` (~284 tokens)

Query Binary Block

Read an IEEE 488.2 definite-length binary block (waveforms, trace data, screenshots,
FORMat REAL/INTeger readings). The query must pass the same read-only checks as
\`scpi_query`. Returns length, SHA-256 and (optionally) decoded values with summary
statistics, downsampled to max_points; use save_path for the full data. Blocks larger
than the `max_block_bytes` limit are discarded.

Input parameters:

- `byte_order` (string): big = SCPI FORMat:BORDer NORMal, little = SWAPped
- `command` (string, required): One SCPI query answering with #<n><len><data>
- `decode_as` (string): Interpret the payload as an array of this type (see the instrument's FORMat)
- `max_inline_bytes` (integer): Return the raw payload as base64 only up to this size
- `max_points` (integer): Max decoded values returned inline
- `overwrite` (boolean): Allow replacing an existing save_path
- `save_path`: Write the full data here: .csv with decode_as writes index,value rows; .bin/.dat/.raw/.txt/.png/.bmp/.jpg/.gif/.tif (or .csv with decode_as none) get the raw payload
- `timeout_s` (number): Timeout for the whole transfer

Output parameters:

- `command` (string)
- `data_base64`: Whole payload, only if <= max_inline_bytes
- `decoded`
- `length_bytes` (integer)
- `preview_hex` (string): First 32 bytes as hex
- `saved_to`
- `sha256` (string)
- `timestamp` (string)

### `get_errors` (~66 tokens)

Get Errors

Read and clear the instrument's error/event queue (SYSTem:ERRor? until 0,"No error").
Entries are returned oldest first; each can only be read once. An empty list means no
errors.

Input parameters:

- `max_errors` (integer): Stop after this many entries

Output parameters:

- `result` (array)

### `wait_operation_complete` (~54 tokens)

Wait Operation Complete

Wait until the instrument has finished all pending operations (*OPC? returns 1),
e.g. after starting a sweep, an acquisition or a settling source.

Input parameters:

- `timeout_s` (number): Longest time to wait

### `scpi_write` (~142 tokens)

Scpi Write

Send any SCPI program message (settings, compound 'A;B' messages, queries with side
effects) and then read the error queue. If the message contains a query, its reply is
returned. This can change the instrument's state, including switching outputs on;
say what the command does before calling it. Commands in the lab's denylist, or
outside its allowlist, are refused before anything is sent.

Input parameters:

- `command` (string, required): SCPI program message, e.g. 'VOLT 5;CURR 0.1' or 'OUTP ON'
- `timeout_s`: Reply timeout if it contains a query

Output parameters:

- `command` (string)
- `elapsed_ms` (number)
- `error_check` (string): 'ok', 'errors', or 'unavailable: ...' if the queue could not be read
- `errors` (array): Error-queue entries read after the command
- `ok` (boolean): True if the error queue was read and empty
- `response`: Reply, if the message contained a query
- `timestamp` (string)

### `scpi_batch` (~132 tokens)

Scpi Batch

Run a short sequence of SCPI commands and queries in order, checking the error queue
after every step. Every step is checked against the command policy BEFORE the first one
is sent, so a refused step means nothing was sent. Returns per-step replies and errors.
Steps not started within ~14 minutes are not sent (status not_run).

Input parameters:

- `delay_between_s` (number): Pause between steps
- `steps` (array, required): Commands/queries to send in order
- `stop_on_error` (boolean): Stop at the first step that reports an error
- `timeout_s`: Reply timeout per query

Output parameters:

- `completed` (integer): Number of steps sent to the instrument
- `steps` (array)
- `stopped_early` (boolean)
- `timestamp` (string)

### `reset_instrument` (~94 tokens)

Reset Instrument

Reset the instrument to its default settings (*RST, then *CLS), wait for completion and
check errors. SCPI requires outputs OFF after *RST, but every other setting (levels,
ranges, triggers, limits) returns to its default and some instruments differ: check the
manual before resetting anything connected to a device under test.

Input parameters:

- `clear_status` (boolean): Also send *CLS (clear status and error queue)

Output parameters:

- `command` (string)
- `elapsed_ms` (number)
- `error_check` (string): 'ok', 'errors', or 'unavailable: ...' if the queue could not be read
- `errors` (array): Error-queue entries read after the command
- `ok` (boolean): True if the error queue was read and empty
- `response`: Reply, if the message contained a query
- `timestamp` (string)

### `device_clear` (~99 tokens)

Device Clear

Recover a stuck or confused instrument: VISA device clear (or discard unread input on
socket/serial links), report the error queue, optionally ABORt, then *CLS. This does NOT
make an arbitrary instrument safe (outputs stay as they are): use `apply_safe_state` if
the lab configured one, or the instrument's own controls.

Input parameters:

- `send_abort` (boolean): Also send ABORt (stop sweeps / measurements)

## Diagnostics

Captured diagnostic sections: Provenance, Install scripts, Dependencies. The full working is on the page: https://verifymcp.io/servers/k-dense-ai-labmcp-scpi/labmcp-scpi#diagnostics

## Score history

- 2026-09-30: 82
- 2026-09-29: 82
- 2026-09-28: 81
- 2026-09-27: 39
- 2026-09-26: 70

## Common questions

### What is the Generic SCPI Instrument MCP server?

Generic SCPI Instrument is an MCP server listed in the public MCP registry as io.github.K-Dense-AI/labmcp-scpi. Generic MCP server for any SCPI instrument over VISA, TCP or serial, with command allow/deny lists. This page covers its PyPI package (labmcp-scpi).

### Is the Generic SCPI Instrument MCP server safe to use?

Generic SCPI Instrument scores 82 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 30 September 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Generic SCPI Instrument MCP server expose?

Generic SCPI Instrument exposes 14 tools: get_connection_info, get_command_log, reconnect, scpi_primer, identify, and 9 more. Their descriptions and schemas cost roughly 1,342 tokens of context every time the server is loaded.

### Is the Generic SCPI Instrument MCP server still maintained?

Generic SCPI Instrument is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the Generic SCPI Instrument MCP server under?

Generic SCPI Instrument declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- PyPI project: https://pypi.org/project/labmcp-scpi/
- Socket report: https://socket.dev/pypi/package/labmcp-scpi
- Repository: https://github.com/K-Dense-AI/lab-instrument-mcps
- Website: https://github.com/K-Dense-AI/lab-instrument-mcps/tree/main/servers/protocols/scpi-instrument
- Changelog RSS feed: https://verifymcp.io/servers/k-dense-ai-labmcp-scpi/labmcp-scpi.xml
- Changelog JSON feed: https://verifymcp.io/servers/k-dense-ai-labmcp-scpi/labmcp-scpi.json
- HTML version of this page: https://verifymcp.io/servers/k-dense-ai-labmcp-scpi/labmcp-scpi
