MCP Terminal Server
MCP 终端服务器
模型上下文协议 (MCP) 的安全命令行界面服务器,使 AI 模型能够与您的终端交互,同时保持安全性和控制力。
特征
🔒 通过可配置的权限来安全执行命令
📁 允许路径内的文件系统操作
🌍 环境变量管理
💻 跨平台支持(Windows、macOS、Linux)
🔌 通过命令执行支持远程系统连接
Related MCP server: Shell MCP Server
与 Claude Desktop 一起使用
将服务器配置添加到您的 Claude Desktop 配置文件:
{
"mcpServers": {
"terminal": {
"command": "npx",
"args": [
"@dillip285/mcp-terminal",
"--allowed-paths",
"/path/to/allowed/directory"
]
}
}
}重启 Claude Desktop 以应用更改。现在,您可以通过 Claude 使用终端功能,实现安全的文件访问和命令执行。
可用工具
execute_command:安全地运行终端命令(包括 SSH 和远程命令)
安全
所有操作均限制在指定的允许路径内
命令在执行前经过验证和清理
环境变量得到精心管理
正确处理与安全相关的问题的错误
发展
# Clone the repository
git clone https://github.com/dillip285/mcp-terminal.git
# Install dependencies
npm install
# Configure npm authentication
cp .npmrc.example .npmrc
# Edit .npmrc and add your NPM_TOKEN
# Run tests
npm test
# Build the project
npm run build出版
要发布包:
将
.npmrc.example复制到.npmrc将您的 npm 身份验证令牌添加到
.npmrc运行
npm publish --access public
注意:切勿提交带有身份验证令牌的.npmrc文件。它已添加到.gitignore中。
贡献
分叉存储库
创建你的功能分支(
git checkout -b feature/amazing-feature)提交您的更改(
git commit -m 'feat: Add amazing feature')推送到分支(
git push origin feature/amazing-feature)打开拉取请求
执照
MIT 许可证 - 有关详细信息,请参阅LICENSE文件。
相关项目
支持
对于错误报告和功能请求,请打开一个问题。
Available Tools
1 toolexecute_commandC
Execute a command in the local system
| Name | Required | Description | Default |
|---|---|---|---|
| args | No | Command arguments | |
| command | Yes | Command to execute | |
| cwd | No | Working directory for command execution |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. While 'execute a command' implies a potentially powerful/mutating operation, it doesn't disclose critical behavioral traits like security implications, permission requirements, side effects, error handling, or output format. This leaves significant gaps for an AI agent to understand the tool's behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise - a single sentence that directly states the tool's purpose without any unnecessary words. It's perfectly front-loaded with the essential information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool that executes system commands (a potentially dangerous operation with no output schema), the description is severely lacking. It doesn't address security implications, permission requirements, typical use cases, error handling, or what kind of output/result to expect. The absence of annotations exacerbates these gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema description coverage is 100%, meaning all parameters are documented in the schema itself. The description doesn't add any meaningful parameter semantics beyond what's already in the schema (command, args, cwd). This meets the baseline expectation when schema coverage is complete.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('execute') and target ('a command in the local system'), providing a specific verb+resource combination. However, since there are no sibling tools mentioned, it cannot demonstrate differentiation from alternatives, preventing a perfect score of 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives, nor does it mention any prerequisites, constraints, or typical use cases. It simply states what the tool does without contextual usage information.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v1.0.0- First observed
execute_command
TDQS
Scored across 1 tool
With only one tool, there is no possibility of ambiguity or overlap between tools. The tool 'execute_command' has a clear and distinct purpose that cannot be confused with any other tool in this set.
The single tool name 'execute_command' follows a verb_noun pattern, and with only one tool, the naming is inherently consistent. There are no other tools to compare against, so no inconsistencies can arise.
A single tool for a terminal server feels too minimal for the apparent scope. While it covers basic command execution, typical terminal operations might include listing files, navigating directories, or managing processes, suggesting a gap in functionality.
The tool surface is severely incomplete for a terminal server domain. It only allows command execution, missing essential operations like file browsing, process management, or environment inspection, which are core to terminal workflows and will likely cause agent failures.
Maintenance
Related MCP Connectors
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
- emisarOAuthdev.emisar
Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.
I run shell commands on your private cloud environment (bash, sh, zsh)
Real Linux labs your AI agent deploys, routes and runs, with domains, TLS, DBs and an audit log.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceA secure server that allows LLM applications like Claude to execute whitelisted system commands with user confirmation and comprehensive security features.-
- AlicenseBqualityFmaintenanceA secure server that enables AI applications to execute shell commands in specified directories, supporting multiple shell types (bash, sh, cmd, powershell) with built-in security features like directory isolation and timeout control.121Apache 2.0
- AlicenseAqualityFmaintenanceAn MCP server that enables secure terminal command execution, directory navigation, and file system operations through a standardized interface for LLMs.1034 PyPI97MIT
- AlicenseBqualityDmaintenanceA secure terminal execution server that enables controlled command execution with security features and resource limits via the Model Context Protocol (MCP).130 npm11MIT