Skip to main content
Glama
Sunwood-ai-labs

Command Executor MCP Server

コマンド実行者 MCP サーバー

事前に承認されたコマンドを安全に実行するためのモデル コンテキスト プロトコル サーバー。

🎥 デモ

https://github.com/user-attachments/assets/ed763a12-b685-4e0b-b9a5-bc948a590f51

Related MCP server: MCP Shell Server

✨ 特徴

  • 事前承認されたコマンドリストによる安全なコマンド実行

  • 環境変数を通じて許可されるコマンドを設定可能

  • TypeScriptとMCP SDKで構築

  • シームレスな統合のためのstdio経由の通信

  • エラー処理とセキュリティ検証

  • リアルタイムコマンド出力ストリーミング

🚀 インストール

依存関係をインストールします:

npm install

サーバーを構築します。

npm run build

自動リビルドを使用した開発の場合:

npm run watch

⚙️ 構成

🔒 許可されたコマンド

デフォルトでは、次のコマンドが許可されます。

  • ギット

  • ls

  • mkdir

  • CD

  • npm

  • npx

  • パイソン

ALLOWED_COMMANDS環境変数を設定することで、許可されるコマンドをカスタマイズできます。

export ALLOWED_COMMANDS=git,ls,mkdir,python

🔌 クロード デスクトップ統合

Claude Desktop で使用するには、サーバー設定を追加します。

MacOSの場合:

~/Library/Application Support/Claude/claude_desktop_config.json

Windowsの場合:

%APPDATA%/Claude/claude_desktop_config.json

設定例:

{
  "mcpServers": {
    "command-executor": {
      "command": "/path/to/command-executor/build/index.js"
    }
  }
}

🛡️ セキュリティに関する考慮事項

コマンド実行サーバーは、いくつかのセキュリティ対策を実装しています。

  1. 事前承認済みコマンドリスト

    • 明示的に許可されたコマンドのみ実行できます

    • デフォルトのリストは制限的でセキュリティに重点を置いています

    • コマンドはプレフィックスによって検証され、インジェクションを防止します

  2. コマンド検証

    • コマンドプレフィックス検証によりコマンドインジェクションを防止

    • セキュリティ強化のためシェル実行なし

    • 環境変数は適切にサニタイズされている

  3. エラー処理

    • 不正なコマンドに対する包括的なエラー処理

    • デバッグのためにエラーメッセージをクリアする

    • 失敗したコマンドはサーバーをクラッシュさせません

  4. 環境分離

    • サーバーは独自の環境で実行されます

    • 環境変数を制御できる

    • システムアクセスの制限

💻 開発

📁 プロジェクト構造

command-executor/
├─ src/
│  └─ index.ts      # Main server implementation
├─ build/
│  └─ index.js      # Compiled JavaScript
├─ assets/
│  └─ header.svg    # Project header image
└─ package.json     # Project configuration

🐛 デバッグ

MCPサーバーはstdio経由で通信するため、デバッグが困難になる場合があります。MCP Inspectorの使用をお勧めします。

npm run inspector

インスペクターは、ブラウザでデバッグ ツールにアクセスするための URL を提供します。

🛠️ ツールAPI

サーバーは次の単一のツールを提供します:

実行コマンド

事前に承認されたコマンドを実行します。

パラメータ:

  • command (文字列、必須): 実行するコマンド

リクエスト例:

{
  "name": "execute_command",
  "arguments": {
    "command": "git status"
  }
}

応答例:

{
  "content": [
    {
      "type": "text",
      "text": "On branch main\nNothing to commit, working tree clean"
    }
  ]
}

エラー応答:

{
  "content": [
    {
      "type": "text",
      "text": "Command execution failed: Command not allowed"
    }
  ],
  "isError": true
}

❌ エラー処理

サーバーは、さまざまなシナリオに対して詳細なエラー メッセージを提供します。

  1. 不正なコマンド

    {
      "code": "InvalidParams",
      "message": "Command not allowed: [command]. Allowed commands: git, ls, mkdir, cd, npm, npx, python"
    }
  2. 実行失敗

    {
      "content": [
        {
          "type": "text",
          "text": "Command execution failed: [error message]"
        }
      ],
      "isError": true
    }

🤝 貢献する

  1. リポジトリをフォークする

  2. 機能ブランチを作成する

  3. 変更をコミットする

  4. ブランチにプッシュする

  5. 新しいプルリクエストを作成する

📄 ライセンス

このプロジェクトは MIT ライセンスに基づいてライセンスされています - 詳細については LICENSE ファイルを参照してください。

Available Tools

1 tool
execute_commandC

事前に許可されたコマンドを実行します

ParametersJSON Schema
NameRequiredDescriptionDefault
commandYes実行するコマンド

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Without annotations, the description carries the full burden. It mentions 'pre-authorized commands' implying an authorization check, but does not disclose what happens if unauthorized, potential side effects, or return values. This is insufficient for a command execution tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence that is front-loaded and efficient. Every word earns its place with no redundancy or fluff.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the simplicity (1 parameter, no output schema), the description is minimal. It fails to cover important behavioral aspects like success/failure modes, authorization details, or examples. For a potentially powerful tool, it leaves significant gaps.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with a single parameter 'command' described as '実行するコマンド' (command to execute). The tool description adds the constraint that commands must be pre-authorized, which adds meaning beyond the schema. Baseline of 3 is appropriate as the description adds some value but not extensive detail.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb 'execute' and the resource 'pre-authorized commands', distinguishing it well. It is specific about the pre-authorization constraint, which adds clarity, though no siblings exist to differentiate from.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives, nor any when-not or prerequisites. It merely states what it does without context for appropriate usage.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev1.0.0
    • Addedexecute_command

TDQS

B3.2/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is no possibility of confusion between tools. The agent can only select 'execute_command', so disambiguation is perfect.

Naming Consistency5/5

The single tool is named 'execute_command', following a clear verb_noun pattern, which is consistent and intuitive.

Tool Count3/5

One tool is minimal for a command executor. While it covers the core functionality of executing pre-approved commands, it lacks supporting tools for listing or managing commands, making the set feel thin.

Completeness2/5

The tool surface is severely incomplete. It only provides execution but lacks tools to list available commands, check execution status, or retrieve results, which are essential for effective agent interaction.

Maintenance

ActivityInactive
ResponsivenessUnresponsive

Related MCP Connectors

Related MCP Servers

  • A
    license
    C
    quality
    C
    maintenance
    A server that enables AI assistants to execute terminal commands and retrieve outputs via the Model Context Protocol (MCP).
    3
    26
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A comprehensive Model Context Protocol server implementation that enables AI assistants to interact with file systems, databases, GitHub repositories, web resources, and system tools while maintaining security and control.
    42 npm
    2
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    A secure Model Context Protocol server that allows AI assistants and LLM applications to safely execute Python and JavaScript code snippets in containerized environments.
    2
    204
    MIT