Skip to main content
Glama
diegofornalha

MCP Shell Server

MCP 셸 서버

코드코브 대장간 엠블럼

셸 명령을 실행하기 위한 보안 서버로, MCP(Model Context Protocol)를 구현합니다. 이 서버는 stdin을 통한 입력을 지원하여 권한이 있는 셸 명령을 원격으로 실행할 수 있도록 합니다.

특징

  • 보안 명령 실행 : 권한이 있는 명령만 실행할 수 있습니다.

  • 표준 입력 지원 : stdin을 통해 명령에 입력을 전달합니다.

  • 종합 출력 : stdout, stderr, 종료 코드 및 실행 시간을 반환합니다.

  • 셸 연산자를 사용한 보안 : 셸 연산자(;, &&, ||, |) 뒤에 오는 명령을 검증합니다.

  • 시간 초과 제어 : 명령에 대한 최대 실행 시간을 설정합니다.

Related MCP server: Shell MCP Server

Claude.app에서 MCP 클라이언트 구성

출판된 버전

지엑스피1

{
  "mcpServers": {
    "shell": {
      "command": "uvx",
      "args": [
        "mcp-shell-server"
      ],
      "env": {
        "ALLOW_COMMANDS": "ls,cat,pwd,grep,wc,touch,find"
      }
    },
  }
}

로컬 버전

설정

code ~/Library/Application\ Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "shell": {
      "command": "uv",
      "args": [
        "--directory",
        ".",
        "run",
        "mcp-shell-server"
      ],
      "env": {
        "ALLOW_COMMANDS": "ls,cat,pwd,grep,wc,touch,find"
      }
    },
  }
}

설치

pip install mcp-shell-server

사용

서버 시작

ALLOW_COMMANDS="ls,cat,echo" uvx mcp-shell-server
# Ou usando o alias
ALLOWED_COMMANDS="ls,cat,echo" uvx mcp-shell-server

ALLOW_COMMANDS 환경 변수(또는 별칭 ALLOWED_COMMANDS )는 실행할 수 있는 명령을 지정합니다. 명령어는 쉼표로 구분할 수 있으며, 선택적으로 공백을 사용할 수 있습니다.

ALLOW_COMMANDS 또는 ALLOWED_COMMANDS에 유효한 형식:

ALLOW_COMMANDS="ls,cat,echo"          # Formato básico
ALLOWED_COMMANDS="ls ,echo, cat"      # Com espaços (usando alias)
ALLOW_COMMANDS="ls,  cat  , echo"     # Múltiplos espaços

요청 형식

# Execução básica de comando
{
    "command": ["ls", "-l", "/tmp"]
}

# Comando com entrada stdin
{
    "command": ["cat"],
    "stdin": "Hello, World!"
}

# Comando com timeout
{
    "command": ["long-running-process"],
    "timeout": 30  # Tempo máximo de execução em segundos
}

# Comando com diretório de trabalho e timeout
{
    "command": ["grep", "-r", "pattern"],
    "directory": "/path/to/search",
    "timeout": 60
}

응답 형식

성공적인 응답:

{
    "stdout": "saída do comando",
    "stderr": "",
    "status": 0,
    "execution_time": 0.123
}

오류 응답:

{
    "error": "Comando não permitido: rm",
    "status": 1,
    "stdout": "",
    "stderr": "Comando não permitido: rm",
    "execution_time": 0
}

보안

서버는 여러 가지 보안 조치를 구현합니다.

  1. 명령어 허용 목록 : 명시적으로 허용된 명령어만 실행할 수 있습니다.

  2. Shell 연산자 검증 : Shell 연산자(;, &&, ||, |) 뒤에 오는 명령도 허용 목록에 대해 검증됩니다.

  3. 셸 주입 없음 : 셸 해석 없이 명령이 직접 실행됩니다.

개발

개발 환경 설정

  1. 저장소를 복제합니다

git clone https://github.com/yourusername/mcp-shell-server.git
cd mcp-shell-server
  1. 테스트 요구 사항을 포함한 종속성 설치

pip install -e ".[test]"

테스트 실행

pytest

API 참조

요청 인수

필드

유형

필수적인

설명

명령

끈[]

예

명령과 해당 인수를 배열 요소로 사용

표준입력

끈

아니요

명령에 전달될 입력

예배 규칙서

끈

아니요

명령을 실행하기 위한 작업 디렉토리

타임아웃

전체

아니요

최대 실행 시간(초)

응답 필드

필드

유형

설명

표준 출력

끈

명령의 표준 출력

표준 에러

끈

명령 오류 출력

상태

전체

종료 상태 코드

실행 시간

뜨다

실행에 걸리는 시간(초)

오류

끈

오류 메시지(실패한 경우에만 표시됨)

요구 사항

  • Python 3.11 이상

  • mcp>=1.1.0

특허

MIT 라이선스 - 자세한 내용은 라이선스 파일을 참조하세요.

Available Tools

1 tool
shell_executeC

Execute um comando shell Comandos permitidos:

ParametersJSON Schema
NameRequiredDescriptionDefault
commandYesComando e seus argumentos como array
directoryYesDiretório de trabalho onde o comando será executado
stdinNoEntrada a ser passada para o comando via stdin
timeoutNoTempo máximo de execução em segundos

TDQS

C2.4/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden for behavioral disclosure. It mentions 'Comandos permitidos: ' but doesn't specify which commands are allowed, security implications, or output behavior. This is a significant gap for a shell execution tool, as it lacks critical safety and operational details.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness2/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is extremely brief but inefficiently structured, with 'Comandos permitidos: ' left incomplete. It fails to convey necessary information concisely, as the trailing text suggests missing content rather than purposeful brevity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a shell execution tool with no annotations and no output schema, the description is insufficient. It doesn't explain return values, error handling, security restrictions, or allowed commands, leaving critical gaps in understanding how the tool behaves and what results to expect.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with all parameters well-documented in the input schema. The description adds no additional parameter semantics beyond what the schema provides, such as examples or constraints on allowed commands. This meets the baseline for high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose3/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states 'Execute um comando shell' which translates to 'Execute a shell command', providing a clear verb+resource combination. However, it's incomplete with 'Comandos permitidos: ' trailing off, making it vague about what commands are actually allowed. No sibling tools exist for differentiation, but the incomplete nature reduces clarity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives, prerequisites, or exclusions. It only states the basic purpose without context about appropriate scenarios or limitations, leaving the agent with no usage direction beyond the obvious.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev1.0.0
    • First observedshell_execute

TDQS

C2.7/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is no possibility for confusion or overlap between tools. The tool 'shell_execute' has a single, clearly defined purpose of executing shell commands, so disambiguation is perfect.

Naming Consistency5/5

Since there is only one tool, naming consistency is inherently perfect. The tool name 'shell_execute' follows a clear verb_noun pattern, but with no other tools to compare, it sets no pattern to deviate from.

Tool Count2/5

A single tool is too few for a server named 'MCP Shell Server', which implies broader shell-related functionality. While the tool covers basic command execution, the scope feels thin, lacking tools for tasks like listing files, checking processes, or managing environment variables that are typical in shell operations.

Completeness2/5

The tool set is severely incomplete for a shell server. It only provides execution, missing essential operations like file manipulation (e.g., read, write, delete), directory navigation, process management, or system information retrieval. This will likely cause agent failures when trying to perform common shell tasks beyond simple command execution.

Maintenance

ActivityInactive
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    A secure shell command execution server implementing the Model Context Protocol (MCP). This server allows remote execution of whitelisted shell commands with support for stdin input.
    1
    198
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol server that allows LLMs to execute shell commands and receive their output in a controlled manner.
    7
    MIT