Command Executor MCP Server
Servidor MCP ejecutor de comandos
Un servidor de protocolo de contexto modelo para ejecutar comandos previamente aprobados de forma segura.
🎥 Demostración
https://github.com/user-attachments/assets/ed763a12-b685-4e0b-b9a5-bc948a590f51
Related MCP server: MCP Shell Server
✨ Características
Ejecución segura de comandos con una lista de comandos previamente aprobada
Comandos permitidos configurables a través de variables de entorno
Desarrollado con TypeScript y MCP SDK
Comunicación a través de stdio para una integración perfecta
Manejo de errores y validaciones de seguridad
Transmisión de salida de comandos en tiempo real
🚀 Instalación
Instalar dependencias:
npm installConstruir el servidor:
npm run buildPara desarrollo con reconstrucción automática:
npm run watch⚙️ Configuración
🔒 Comandos permitidos
De forma predeterminada, se permiten los siguientes comandos:
git
es
mkdir
cd
npm
npx
pitón
Puede personalizar los comandos permitidos configurando la variable de entorno ALLOWED_COMMANDS :
export ALLOWED_COMMANDS=git,ls,mkdir,python🔌 Integración de escritorio de Claude
Para utilizar con Claude Desktop, agregue la configuración del servidor:
En MacOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonEn Windows:
%APPDATA%/Claude/claude_desktop_config.jsonEjemplo de configuración:
{
"mcpServers": {
"command-executor": {
"command": "/path/to/command-executor/build/index.js"
}
}
}🛡️ Consideraciones de seguridad
El servidor ejecutor de comandos implementa varias medidas de seguridad:
Lista de comandos preaprobada
Sólo se pueden ejecutar comandos explícitamente permitidos
La lista predeterminada es restrictiva y se centra en la seguridad.
Los comandos se validan mediante prefijo para evitar la inyección.
Validación de comandos
La validación del prefijo de comando evita la inyección de comandos
No se ejecuta el shell para mejorar la seguridad
Las variables de entorno se desinfectan adecuadamente
Manejo de errores
Manejo integral de errores para comandos no autorizados
Borrar mensajes de error para depuración
Los comandos fallidos no bloquean el servidor
Aislamiento ambiental
El servidor se ejecuta en su propio entorno
Las variables de entorno se pueden controlar
Acceso limitado al sistema
💻 Desarrollo
📁 Estructura del proyecto
command-executor/
├─ src/
│ └─ index.ts # Main server implementation
├─ build/
│ └─ index.js # Compiled JavaScript
├─ assets/
│ └─ header.svg # Project header image
└─ package.json # Project configuration🐛 Depuración
Dado que los servidores MCP se comunican a través de stdio, la depuración puede ser complicada. Recomendamos usar el Inspector MCP :
npm run inspectorEl Inspector proporcionará una URL para acceder a las herramientas de depuración en su navegador.
🛠️ API de herramientas
El servidor proporciona una única herramienta:
ejecutar_comando
Ejecuta un comando previamente aprobado.
Parámetros:
command(cadena, obligatorio): el comando a ejecutar
Ejemplo de solicitud:
{
"name": "execute_command",
"arguments": {
"command": "git status"
}
}Ejemplo de respuesta:
{
"content": [
{
"type": "text",
"text": "On branch main\nNothing to commit, working tree clean"
}
]
}Respuesta de error:
{
"content": [
{
"type": "text",
"text": "Command execution failed: Command not allowed"
}
],
"isError": true
}❌ Manejo de errores
El servidor proporciona mensajes de error detallados para varios escenarios:
Comandos no autorizados
{ "code": "InvalidParams", "message": "Command not allowed: [command]. Allowed commands: git, ls, mkdir, cd, npm, npx, python" }Fallos de ejecución
{ "content": [ { "type": "text", "text": "Command execution failed: [error message]" } ], "isError": true }
🤝 Contribuyendo
Bifurcar el repositorio
Crea tu rama de funciones
Confirme sus cambios
Empujar hacia la rama
Crear una nueva solicitud de extracción
📄 Licencia
Este proyecto está licenciado bajo la licencia MIT: consulte el archivo de LICENCIA para obtener más detalles.
Available Tools
1 toolexecute_commandC
事前に許可されたコマンドを実行します
| Name | Required | Description | Default |
|---|---|---|---|
| command | Yes | 実行するコマンド |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Without annotations, the description carries the full burden. It mentions 'pre-authorized commands' implying an authorization check, but does not disclose what happens if unauthorized, potential side effects, or return values. This is insufficient for a command execution tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that is front-loaded and efficient. Every word earns its place with no redundancy or fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the simplicity (1 parameter, no output schema), the description is minimal. It fails to cover important behavioral aspects like success/failure modes, authorization details, or examples. For a potentially powerful tool, it leaves significant gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with a single parameter 'command' described as '実行するコマンド' (command to execute). The tool description adds the constraint that commands must be pre-authorized, which adds meaning beyond the schema. Baseline of 3 is appropriate as the description adds some value but not extensive detail.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'execute' and the resource 'pre-authorized commands', distinguishing it well. It is specific about the pre-authorization constraint, which adds clarity, though no siblings exist to differentiate from.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives, nor any when-not or prerequisites. It merely states what it does without context for appropriate usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v1.0.0- Added
execute_command
TDQS
Scored across 1 tool
With only one tool, there is no possibility of confusion between tools. The agent can only select 'execute_command', so disambiguation is perfect.
The single tool is named 'execute_command', following a clear verb_noun pattern, which is consistent and intuitive.
One tool is minimal for a command executor. While it covers the core functionality of executing pre-approved commands, it lacks supporting tools for listing or managing commands, making the set feel thin.
The tool surface is severely incomplete. It only provides execution but lacks tools to list available commands, check execution status, or retrieve results, which are essential for effective agent interaction.
Maintenance
Related MCP Connectors
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
A Model Context Protocol server for Wix AI tools
The Mercado Pago MCP Server implements the Model Context Protocol to provide AI agents and LLMs with access to Mercado Pago's APIs and tools within compatible development environments. It acts as an intermediary that translates Mercado Pago resources into executable functions (tools) that AI applications can invoke to perform actions and automate flows. The server simplifies integration, enables using documentation to implement or improve code, and optimizes operations through natural language interactions without manual implementations.
Enable secure connectivity between Sentry issues and debugging data, and LLM clients, using a Model Context Protocol (MCP) server.
Related MCP Servers
- AlicenseCqualityCmaintenanceA server that enables AI assistants to execute terminal commands and retrieve outputs via the Model Context Protocol (MCP).326MIT
- AlicenseBqualityFmaintenanceA server that uses the Model Context Protocol (MCP) to allow AI agents to safely execute shell commands on a host system.1167 npm9MIT
- AlicenseNot gradedqualityDmaintenanceA comprehensive Model Context Protocol server implementation that enables AI assistants to interact with file systems, databases, GitHub repositories, web resources, and system tools while maintaining security and control.42 npm2MIT
- AlicenseBqualityDmaintenanceA secure Model Context Protocol server that allows AI assistants and LLM applications to safely execute Python and JavaScript code snippets in containerized environments.2204MIT