Command Executor MCP Server
命令执行器 MCP 服务器
用于安全地执行预先批准的命令的模型上下文协议服务器。
🎥 演示
https://github.com/user-attachments/assets/ed763a12-b685-4e0b-b9a5-bc948a590f51
Related MCP server: MCP Shell Server
✨ 特点
使用预先批准的命令列表来确保命令执行的安全
通过环境变量配置允许的命令
使用 TypeScript 和 MCP SDK 构建
通过 stdio 进行通信,实现无缝集成
错误处理和安全验证
实时命令输出流
🚀 安装
安装依赖项:
npm install构建服务器:
npm run build对于使用自动重建的开发:
npm run watch⚙️ 配置
🔒 允许的命令
默认情况下,允许以下命令:
git
ls
mkdir
光盘
npm
NPX
Python
您可以通过设置ALLOWED_COMMANDS环境变量来自定义允许的命令:
export ALLOWED_COMMANDS=git,ls,mkdir,python🔌 Claude 桌面集成
要与 Claude Desktop 一起使用,请添加服务器配置:
在 MacOS 上:
~/Library/Application Support/Claude/claude_desktop_config.json在 Windows 上:
%APPDATA%/Claude/claude_desktop_config.json配置示例:
{
"mcpServers": {
"command-executor": {
"command": "/path/to/command-executor/build/index.js"
}
}
}🛡️ 安全注意事项
命令执行器服务器实现了多项安全措施:
预先批准的命令列表
只能执行明确允许的命令
默认列表具有限制性且注重安全性
通过前缀验证命令以防止注入
命令验证
命令前缀验证可防止命令注入
无需执行任何 shell,安全性更高
环境变量已正确清理
错误处理
针对未经授权的命令的全面错误处理
清除错误信息以便调试
失败的命令不会导致服务器崩溃
环境隔离
服务器在其自己的环境中运行
环境变量可以控制
限制系统访问
💻 开发
📁 项目结构
command-executor/
├─ src/
│ └─ index.ts # Main server implementation
├─ build/
│ └─ index.js # Compiled JavaScript
├─ assets/
│ └─ header.svg # Project header image
└─ package.json # Project configuration🐛 调试
由于 MCP 服务器通过 stdio 进行通信,调试起来可能比较困难。我们建议使用MCP Inspector :
npm run inspector检查器将提供一个 URL 来访问浏览器中的调试工具。
🛠️ 工具 API
服务器提供一个单一工具:
执行命令
执行预先批准的命令。
参数:
command(字符串,必需):要执行的命令
示例请求:
{
"name": "execute_command",
"arguments": {
"command": "git status"
}
}响应示例:
{
"content": [
{
"type": "text",
"text": "On branch main\nNothing to commit, working tree clean"
}
]
}错误响应:
{
"content": [
{
"type": "text",
"text": "Command execution failed: Command not allowed"
}
],
"isError": true
}❌错误处理
服务器针对各种场景提供了详细的错误消息:
未经授权的命令
{ "code": "InvalidParams", "message": "Command not allowed: [command]. Allowed commands: git, ls, mkdir, cd, npm, npx, python" }执行失败
{ "content": [ { "type": "text", "text": "Command execution failed: [error message]" } ], "isError": true }
🤝 贡献
分叉存储库
创建你的功能分支
提交你的更改
推送到分支
创建新的 Pull 请求
📄 许可证
该项目根据 MIT 许可证获得许可 - 有关详细信息,请参阅 LICENSE 文件。
Available Tools
1 toolexecute_commandC
事前に許可されたコマンドを実行します
| Name | Required | Description | Default |
|---|---|---|---|
| command | Yes | 実行するコマンド |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Without annotations, the description carries the full burden. It mentions 'pre-authorized commands' implying an authorization check, but does not disclose what happens if unauthorized, potential side effects, or return values. This is insufficient for a command execution tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that is front-loaded and efficient. Every word earns its place with no redundancy or fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the simplicity (1 parameter, no output schema), the description is minimal. It fails to cover important behavioral aspects like success/failure modes, authorization details, or examples. For a potentially powerful tool, it leaves significant gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with a single parameter 'command' described as '実行するコマンド' (command to execute). The tool description adds the constraint that commands must be pre-authorized, which adds meaning beyond the schema. Baseline of 3 is appropriate as the description adds some value but not extensive detail.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'execute' and the resource 'pre-authorized commands', distinguishing it well. It is specific about the pre-authorization constraint, which adds clarity, though no siblings exist to differentiate from.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives, nor any when-not or prerequisites. It merely states what it does without context for appropriate usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v1.0.0- Added
execute_command
TDQS
Scored across 1 tool
With only one tool, there is no possibility of confusion between tools. The agent can only select 'execute_command', so disambiguation is perfect.
The single tool is named 'execute_command', following a clear verb_noun pattern, which is consistent and intuitive.
One tool is minimal for a command executor. While it covers the core functionality of executing pre-approved commands, it lacks supporting tools for listing or managing commands, making the set feel thin.
The tool surface is severely incomplete. It only provides execution but lacks tools to list available commands, check execution status, or retrieve results, which are essential for effective agent interaction.
Maintenance
Related MCP Connectors
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
A Model Context Protocol server for Wix AI tools
The Mercado Pago MCP Server implements the Model Context Protocol to provide AI agents and LLMs with access to Mercado Pago's APIs and tools within compatible development environments. It acts as an intermediary that translates Mercado Pago resources into executable functions (tools) that AI applications can invoke to perform actions and automate flows. The server simplifies integration, enables using documentation to implement or improve code, and optimizes operations through natural language interactions without manual implementations.
Enable secure connectivity between Sentry issues and debugging data, and LLM clients, using a Model Context Protocol (MCP) server.
Related MCP Servers
- AlicenseCqualityCmaintenanceA server that enables AI assistants to execute terminal commands and retrieve outputs via the Model Context Protocol (MCP).326MIT
- AlicenseBqualityFmaintenanceA server that uses the Model Context Protocol (MCP) to allow AI agents to safely execute shell commands on a host system.1167 npm9MIT
- AlicenseNot gradedqualityDmaintenanceA comprehensive Model Context Protocol server implementation that enables AI assistants to interact with file systems, databases, GitHub repositories, web resources, and system tools while maintaining security and control.42 npm2MIT
- AlicenseBqualityDmaintenanceA secure Model Context Protocol server that allows AI assistants and LLM applications to safely execute Python and JavaScript code snippets in containerized environments.2204MIT