MCP Shell Server
Servidor Shell MCP
Un servidor seguro para ejecutar comandos de shell que implementa el Protocolo de Contexto de Modelo (MCP). Este servidor permite la ejecución remota de comandos de shell autorizados con soporte para entrada a través de stdin.
Características
Ejecución segura de comandos : solo se pueden ejecutar comandos autorizados
Soporte de entrada estándar : pasa la entrada a los comandos a través de la entrada estándar
Salida completa : devuelve stdout, stderr, código de salida y tiempo de ejecución
Seguridad con operadores de shell : valida los comandos después de los operadores de shell (;, &&, ||, |)
Control de tiempo de espera : establece el tiempo máximo de ejecución de los comandos
Related MCP server: Shell MCP Server
Configurando el cliente MCP en tu Claude.app
Versión publicada
code ~/Library/Application\ Support/Claude/claude_desktop_config.json{
"mcpServers": {
"shell": {
"command": "uvx",
"args": [
"mcp-shell-server"
],
"env": {
"ALLOW_COMMANDS": "ls,cat,pwd,grep,wc,touch,find"
}
},
}
}Versión local
Ajustes
code ~/Library/Application\ Support/Claude/claude_desktop_config.json{
"mcpServers": {
"shell": {
"command": "uv",
"args": [
"--directory",
".",
"run",
"mcp-shell-server"
],
"env": {
"ALLOW_COMMANDS": "ls,cat,pwd,grep,wc,touch,find"
}
},
}
}Instalación
pip install mcp-shell-serverUsar
Iniciando el servidor
ALLOW_COMMANDS="ls,cat,echo" uvx mcp-shell-server
# Ou usando o alias
ALLOWED_COMMANDS="ls,cat,echo" uvx mcp-shell-serverLa variable de entorno ALLOW_COMMANDS (o su alias ALLOWED_COMMANDS ) especifica qué comandos se pueden ejecutar. Los comandos se pueden separar mediante comas con espacios opcionales alrededor de ellos.
Formatos válidos para ALLOW_COMMANDS o ALLOWED_COMMANDS:
ALLOW_COMMANDS="ls,cat,echo" # Formato básico
ALLOWED_COMMANDS="ls ,echo, cat" # Com espaços (usando alias)
ALLOW_COMMANDS="ls, cat , echo" # Múltiplos espaçosFormato de solicitud
# Execução básica de comando
{
"command": ["ls", "-l", "/tmp"]
}
# Comando com entrada stdin
{
"command": ["cat"],
"stdin": "Hello, World!"
}
# Comando com timeout
{
"command": ["long-running-process"],
"timeout": 30 # Tempo máximo de execução em segundos
}
# Comando com diretório de trabalho e timeout
{
"command": ["grep", "-r", "pattern"],
"directory": "/path/to/search",
"timeout": 60
}Formato de respuesta
Respuesta exitosa:
{
"stdout": "saída do comando",
"stderr": "",
"status": 0,
"execution_time": 0.123
}Respuesta de error:
{
"error": "Comando não permitido: rm",
"status": 1,
"stdout": "",
"stderr": "Comando não permitido: rm",
"execution_time": 0
}Seguridad
El servidor implementa varias medidas de seguridad:
Lista blanca de comandos : solo se pueden ejecutar comandos explícitamente permitidos
Validación del operador de shell : los comandos después de los operadores de shell (;, &&, ||, |) también se validan con la lista blanca
Sin inyección de shell : los comandos se ejecutan directamente sin interpretación de shell
Desarrollo
Configuración del entorno de desarrollo
Clonar el repositorio
git clone https://github.com/yourusername/mcp-shell-server.git
cd mcp-shell-serverInstalar dependencias, incluidos los requisitos de prueba
pip install -e ".[test]"Ejecución de pruebas
pytestReferencia de API
Argumentos de solicitud
Campo | Tipo | Obligatorio | Descripción |
dominio | cadena[] | Sí | Comando y sus argumentos como elementos de matriz |
entrada estándar | cadena | No | Entrada que se pasará al comando |
directorio | cadena | No | Directorio de trabajo para ejecutar el comando |
se acabó el tiempo | entero | No | Tiempo máximo de ejecución en segundos |
Campos de respuesta
Campo | Tipo | Descripción |
salida estándar | cadena | Salida estándar del comando |
error de error estándar | cadena | Salida de error de comando |
estado | entero | Código de estado de salida |
tiempo de ejecución | flotar | Tiempo de ejecución (en segundos) |
error | cadena | Mensaje de error (presente sólo si falló) |
Requisitos
Python 3.11 o superior
mcp>=1.1.0
Licencia
Licencia MIT: consulte el archivo LICENCIA para obtener más detalles
Available Tools
1 toolshell_executeC
Execute um comando shell Comandos permitidos:
| Name | Required | Description | Default |
|---|---|---|---|
| command | Yes | Comando e seus argumentos como array | |
| directory | Yes | Diretório de trabalho onde o comando será executado | |
| stdin | No | Entrada a ser passada para o comando via stdin | |
| timeout | No | Tempo máximo de execução em segundos |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden for behavioral disclosure. It mentions 'Comandos permitidos: ' but doesn't specify which commands are allowed, security implications, or output behavior. This is a significant gap for a shell execution tool, as it lacks critical safety and operational details.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely brief but inefficiently structured, with 'Comandos permitidos: ' left incomplete. It fails to convey necessary information concisely, as the trailing text suggests missing content rather than purposeful brevity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a shell execution tool with no annotations and no output schema, the description is insufficient. It doesn't explain return values, error handling, security restrictions, or allowed commands, leaving critical gaps in understanding how the tool behaves and what results to expect.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, with all parameters well-documented in the input schema. The description adds no additional parameter semantics beyond what the schema provides, such as examples or constraints on allowed commands. This meets the baseline for high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states 'Execute um comando shell' which translates to 'Execute a shell command', providing a clear verb+resource combination. However, it's incomplete with 'Comandos permitidos: ' trailing off, making it vague about what commands are actually allowed. No sibling tools exist for differentiation, but the incomplete nature reduces clarity.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives, prerequisites, or exclusions. It only states the basic purpose without context about appropriate scenarios or limitations, leaving the agent with no usage direction beyond the obvious.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v1.0.0- First observed
shell_execute
TDQS
Scored across 1 tool
With only one tool, there is no possibility for confusion or overlap between tools. The tool 'shell_execute' has a single, clearly defined purpose of executing shell commands, so disambiguation is perfect.
Since there is only one tool, naming consistency is inherently perfect. The tool name 'shell_execute' follows a clear verb_noun pattern, but with no other tools to compare, it sets no pattern to deviate from.
A single tool is too few for a server named 'MCP Shell Server', which implies broader shell-related functionality. While the tool covers basic command execution, the scope feels thin, lacking tools for tasks like listing files, checking processes, or managing environment variables that are typical in shell operations.
The tool set is severely incomplete for a shell server. It only provides execution, missing essential operations like file manipulation (e.g., read, write, delete), directory navigation, process management, or system information retrieval. This will likely cause agent failures when trying to perform common shell tasks beyond simple command execution.
Maintenance
Related MCP Connectors
Enable secure connectivity between Sentry issues and debugging data, and LLM clients, using a Model Context Protocol (MCP) server.
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
An authenticated remote MCP server for user-owned devices and one-shot capability invocation.
Related MCP Servers
- AlicenseAqualityAmaintenanceA secure shell command execution server implementing the Model Context Protocol (MCP). This server allows remote execution of whitelisted shell commands with support for stdin input.1198MIT
- AlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that allows LLMs to execute shell commands and receive their output in a controlled manner.7MIT
- AlicenseBqualityDmaintenanceA secure terminal execution server that enables controlled command execution with security features and resource limits via the Model Context Protocol (MCP).130 npm11MIT
- AlicenseBqualityFmaintenanceA server that uses the Model Context Protocol (MCP) to allow AI agents to safely execute shell commands on a host system.1167 npm9MIT