@akms/mcp-wsl
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| WSL_CWD | No | Directory new sessions start in | |
| WSL_NAME | No | Alias shown to the agent; defaults to the distro name | |
| WSL_USER | No | Linux user (`wsl -u`). The distro's default user when unset | |
| WSL_DISTRO | Yes | Distro name as `wsl -l -q` prints it. Required by name — following `wsl --set-default` would let a machine-wide setting silently redirect every command | |
| WSL_READONLY | No | Rejects write commands, output redirection, package installs, uploads and writes | false |
| WSL_ALLOW_SUDO | No | When false, rejects `sudo` / `su` / `doas` / `pkexec` / `runuser` / `chroot` | true |
| WSL_MAX_OUTPUT | No | stdout and stderr are each truncated past this | 100000 |
| WSL_DESCRIPTION | No | Shown to the agent — say what the distro is for | |
| WSL_ALLOWED_PATHS | No | When set, the file tools accept only absolute paths inside these prefixes | |
| WSL_ALLOW_WINDOWS | No | When false, rejects Windows interop executables (`powershell.exe`, `cmd.exe`, any `.exe`) and **writes** whose target is under `/mnt/<drive>/`. Reads and copies *out of* `/mnt` are always allowed | false |
| WSL_DENY_PATTERNS | No | Extra regex sources, compiled at startup and tested per command segment | |
| WSL_MCP_LOG_LEVEL | No | Picks the level — `silent` / `debug` / `info` / `warn` / `error` | info |
| WSL_ALLOW_COMMANDS | No | When set, only these binaries may run (`pwd` is added automatically so sessions can open) | |
| WSL_MAX_READ_BYTES | No | `wsl_read_file` ceiling | 200000 |
| WSL_EXEC_TIMEOUT_MS | No | Per-command wall clock; `wsl.exe` is killed when it elapses | 60000 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| wsl_list_hostsA | Show the WSL distro and user this server runs commands in, with its guard policy and current state (running or stopped, WSL version, networking mode, whether systemd is PID 1). Call this first: it is the only reachable distro, and its policy decides what the other tools will accept. The networking mode matters when reasoning about ports — in mirrored mode a port Windows holds cannot be bound inside the distro, and a listing inside the distro shows only its own namespace. |
| wsl_connectA | Open a session in the configured distro and return its session id. A session remembers the working directory, so a 'cd' in one wsl_exec still applies to the next. Each command is still its own process — nothing else (environment variables, background jobs) persists between calls. Close it with wsl_disconnect when done; idle sessions are forgotten automatically. |
| wsl_disconnectA | Close a session opened with wsl_connect. Nothing in the distro is affected — only this server's memory of the working directory. |
| wsl_list_sessionsA | List the sessions this server holds, with their working directory, command count and idle time. |
| wsl_execA | Run a shell command in the configured WSL distro (as the configured user, in a login bash) and return stdout, stderr and the exit code. Pass 'session' to reuse a session, which remembers its working directory; omit it for a one-off call. A non-zero exit code is reported as normal output, not as a tool error — read the exit code and stderr to judge the outcome. Almost everything is permitted: package installs, service restarts, sudo, interpreters. Refused outright: catastrophic operations (wiping the filesystem root, formatting a disk, powering off or shutting down the distro), and — unless the profile opens them — Windows interop executables and writes under /mnt//. stdin is closed. A job that must outlive the call needs all three descriptors detached: nohup cmd > log 2>&1 < /dev/null & |
| wsl_list_dirA | List a directory in the distro, with type, permissions, size and mtime. Cheaper and more structured than running 'ls -la' through wsl_exec, and it works on a read-only profile. |
| wsl_read_fileA | Read a text file in the distro and return its contents. Oversized files come back truncated to their leading bytes rather than failing, so pointing this at a large log is safe. Files that report size 0 but hold content (/proc, /sys) are read in full up to the ceiling. |
| wsl_write_fileA | Write or append UTF-8 text to a file in the distro. The content never passes through a shell, so quoting is not a concern. Prefer this over heredocs in wsl_exec. Parent directories must exist. Refused on a read-only profile, and under /mnt// unless the profile allows Windows writes. |
| wsl_uploadA | Copy a file from this machine into the distro. The local path is resolved on the Windows side (a POSIX-looking path becomes \…), and the reply prints it — check it. Credential files and MCP configuration on the local side are refused. |
| wsl_downloadA | Copy a file from the distro to this machine. The local path is resolved on the Windows side and printed in the reply — check it. The destination directory must already exist; credential locations and MCP configuration on the local side are refused. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 10 tools
Each tool has a clearly distinct role: host inspection, session lifecycle, command execution, directory listing, file read/write, and local-to-distro file transfer. The only conceptual overlap is wsl_exec with the specialized file/dir tools, but descriptions explicitly state when to prefer each and why.
All tools use the same wsl_ namespace and snake_case convention, with predictable action-oriented names such as wsl_list_hosts, wsl_read_file, and wsl_upload. The pattern is consistent and easy to scan.
Ten tools is well-scoped for interacting with a WSL distro: session management, command execution, file/directory access, and file transfer are all covered without excessive surface area.
The surface covers the core workflows: host info, sessions, execution, listing, reading, writing, uploading, and downloading. Explicit delete, rename, mkdir, or chmod operations are missing, but wsl_exec can perform them, so agents have workarounds rather than dead ends.