cmd-mcp-server
CMD MCP 服务器
一个模型上下文协议 (MCP) 服务器实现,用于在 Windows 和 Linux 上执行 CMD 命令,并允许 SSH 连接。此服务器允许您将命令行操作与兼容 MCP 的应用程序集成。
特征
通过MCP执行CMD命令
TypeScript 实现
基于官方 MCP SDK 构建
跨平台兼容性
Related MCP server: Globalping
安装
通过 Smithery 安装
要通过Smithery自动为 Claude Desktop 安装 CMD 服务器:
npx -y @smithery/cli install server-cmd --client claude手动安装
npm install server-cmd先决条件
Node.js(建议使用 v16 或更高版本)
npm 或 yarn 包管理器
用法
import { MCPCmdServer } from 'server-cmd';
// Initialize the server
const server = new MCPCmdServer();
// Start the server
server.start();配置
可以通过环境变量或配置对象来配置服务器:
const config = {
// Add your configuration options here
};
const server = new MCPCmdServer(config);发展
设置开发环境:
克隆存储库:
git clone https://github.com/PhialsBasement/CMD-MCP-Server.git
cd CMD-MCP-Server安装依赖项:
npm install构建项目:
npm run build脚本
npm run build将 TypeScript 编译为 JavaScriptnpm run prepare准备发布的包
依赖项
@modelcontextprotocol/sdk: ^1.0.1glob:^10.3.10zod-to-json-schema:^3.23.5
贡献
欢迎贡献代码!欢迎提交 Pull 请求。
执照
该项目根据 MIT 许可证获得许可 - 有关详细信息,请参阅 LICENSE 文件。
安全
请注意,执行命令行操作可能存在潜在危险。在生产环境中使用此服务器时,请务必实施适当的安全措施并进行输入验证。
支持
对于问题和功能请求,请使用GitHub 问题跟踪器。
Available Tools
2 toolsexecute_commandA
Execute a command and return its output. Commands run in a persistent shell session by default. Use newSession: true to run in a new shell instance.
| Name | Required | Description | Default |
|---|---|---|---|
| command | Yes | ||
| newSession | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It discloses that commands run in a persistent shell session by default and can be run in a new instance, which is useful behavioral context. However, it lacks details on permissions, security implications, error handling, or output format, which are important for a command execution tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is appropriately sized and front-loaded, with two clear sentences that efficiently convey key information without waste. Each sentence earns its place by explaining the core function and a critical parameter behavior.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (command execution with potential security and behavioral implications), no annotations, no output schema, and 0% schema coverage, the description is incomplete. It covers the basic operation and session behavior but lacks details on permissions, error handling, output structure, or safety warnings, which are crucial for such a tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate. It adds meaning by explaining the 'newSession' parameter's effect (running in a new shell instance vs. default persistent session) and implies 'command' is the input to execute. It doesn't detail the 'command' parameter's format or constraints, but provides enough context for basic usage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with a specific verb ('Execute') and resource ('a command'), and specifies it returns output. However, it doesn't explicitly differentiate from the sibling 'execute_ssh_command' tool, which likely has a different context or target.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context about when to use the 'newSession' parameter (to run in a new shell instance vs. the default persistent session). It doesn't explicitly mention when to use this tool versus the sibling 'execute_ssh_command' or other alternatives, which is a minor gap.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
execute_ssh_commandC
Execute a command on a remote server via SSH. Commands run in a persistent SSH session by default. Use newSession: true to run in a new session.
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | ||
| port | No | ||
| username | Yes | ||
| password | No | ||
| privateKey | No | ||
| command | Yes | ||
| newSession | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden for behavioral disclosure. It mentions the persistent session behavior and newSession option, which is helpful. However, it doesn't cover critical aspects like security implications, error handling, timeout behavior, or output format. For a tool that executes remote commands with authentication parameters, this leaves significant gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is appropriately concise with two sentences. The first sentence states the core purpose, and the second provides important behavioral context about session persistence. No wasted words, though it could be more comprehensive given the tool's complexity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with 7 parameters, 0% schema description coverage, no annotations, and no output schema, the description is insufficient. It doesn't explain authentication methods (password vs. privateKey), command execution context, error scenarios, or return values. The description should provide more guidance given the tool's security-sensitive nature and complexity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate for all 7 parameters. The description only mentions the 'newSession' parameter explicitly. It doesn't explain the purpose or relationships of host, port, username, password, privateKey, or command parameters. The description adds minimal value beyond what the bare schema provides.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Execute a command on a remote server via SSH.' It specifies the action (execute), resource (remote server), and method (SSH). However, it doesn't explicitly differentiate from the sibling tool 'execute_command' (which might be for local execution or different protocols).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides some usage context: 'Commands run in a persistent SSH session by default. Use newSession: true to run in a new session.' This gives guidance on session behavior but doesn't explain when to use this tool versus the sibling 'execute_command' or address authentication method selection (password vs. privateKey).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
v1.0.0- Added
execute_command - Added
execute_ssh_command
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: execute_command handles local shell commands, while execute_ssh_command handles remote SSH commands. There is no overlap or ambiguity between them, as each targets a different execution environment.
Both tools follow a consistent verb_noun pattern with 'execute_' as the prefix and descriptive suffixes ('command' and 'ssh_command'). The naming is perfectly uniform and predictable across the tool set.
With only 2 tools, the server feels thin for a command execution domain. It lacks essential operations like listing available commands, managing sessions, or handling file operations, which are common in such contexts. The count is too low for adequate coverage.
The tool set is severely incomplete for command execution. It covers basic local and remote command execution but misses critical functionalities such as session management tools, command history, file transfer, or environment configuration, leaving significant gaps for agent workflows.
Maintenance
Related MCP Connectors
A simple MCP server built with FastMCP and python
Related MCP Servers
- MIT

Globalpingofficial
FlicenseNot gradedqualityBmaintenanceRemote MCP server that gives LLMs access to run network commands64-- AlicenseNot gradedqualityCmaintenanceMCP server exposing pwntools 4.15.0 functionality for binary exploitation tasks.12 PyPIMIT
- FlicenseNot gradedqualityDmaintenanceMCP server providing filesystem operations, shell execution, and web search capabilities.-