Skip to main content
Glama
hdresearch
by hdresearch

シェルMCPサーバー

セキュアなシェルコマンド実行機能を提供するモデルコンテキストプロトコル(MCP)のNode.js実装です。このサーバーにより、AIモデルはセキュリティ対策が組み込まれた制御された環境でシェルコマンドを実行できます。Claude Desktopと簡単に統合でき、Claudeをシェルに接続できます。

特徴

  • MCP準拠のサーバー実装

  • ブラックリスト保護による安全なコマンド実行

  • コマンドの存在検証

  • 標準I/Oベースのトランスポート

  • エラー処理と正常なシャットダウン

Related MCP server: MCP Shell Server

インストール

npx mcp-shellを実行します。

Claude Desktopに追加するには、 npx mcp-shell config実行します。または、 npx -y mcp-shell手動で設定に追加します。

Claude Desktop を起動 (または再起動) すると、ランディング ページに MCP ツールが表示されます。

セキュリティ機能

サーバーはいくつかのセキュリティ対策を実装しています。

  1. コマンドブラックリスト

    • 危険なシステムコマンドの実行を防止します

    • 重要なシステム変更へのアクセスをブロック

    • ファイルシステムの破壊から保護します

    • 権限昇格を防止

  2. コマンド検証

    • 実行前にコマンドの存在を確認する

    • ブラックリストを検証する

    • 無効なコマンドに対して明確なエラーメッセージを返します

利用可能なツール

サーバーは次のツールを 1 つ提供します。

実行コマンド

シェル コマンドを実行し、その出力を返します。

入力スキーマ:

{
  "type": "object",
  "properties": {
    "command": { "type": "string" }
  }
}

応答:

  • 成功: コマンド出力はプレーンテキストとして出力されます

  • エラー: エラー メッセージがプレーン テキストで表示されます

ブラックリストに登録されたコマンド

次のコマンド カテゴリはセキュリティ上の理由によりブロックされています。

  • ファイルシステム破壊コマンド (rm、rmdir、del)

  • ディスク/ファイルシステムコマンド(format、mkfs、dd)

  • 権限/所有権コマンド (chmod、chown)

  • 権限昇格コマンド (sudo、su)

  • コード実行コマンド (exec、eval)

  • システム通信コマンド(write、wall)

  • システム制御コマンド (シャットダウン、再起動、初期化)

エラー処理

サーバーには包括的なエラー処理が含まれています。

  • コマンドが見つからないエラー

  • ブラックリストに登録されたコマンドエラー

  • 実行エラー

  • MCPプロトコルエラー

  • SIGINT による正常なシャットダウン

実装の詳細

サーバーは以下を使用して構築されます:

  • モデルコンテキストプロトコルSDK

  • 通信用のStdioServerTransport

  • コマンド実行用のexeca

  • コマンド検証のためのコマンド存在

発達

セキュリティ設定を変更するには、次の操作を行います。

  1. ブロックされたコマンドを調整するには、 BLACKLISTED_COMMANDSセットを編集します。

  2. 追加の検証ルールを追加するには、 validateCommand関数を変更します。

  3. CallToolRequestSchemaハンドラーのコマンド解析ロジックを強化します

Available Tools

1 tool
run_commandC

Run a shell command

ParametersJSON Schema
NameRequiredDescriptionDefault
commandNo

TDQS

C2.6/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden but only states the action without disclosing behavioral traits. It doesn't cover critical aspects like whether the command runs locally or remotely, if it requires elevated privileges, potential side effects (e.g., file modifications), error handling, or output format. This leaves significant uncertainty for safe and effective use.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is extremely concise with just three words, front-loaded and zero waste. It efficiently conveys the core action without unnecessary elaboration, making it easy to parse quickly. However, this conciseness comes at the cost of completeness, as noted in other dimensions.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity of running shell commands (which can be high-risk with mutations and side effects), no annotations, no output schema, and low parameter coverage, the description is incomplete. It lacks essential context such as execution environment, security implications, error responses, and usage scenarios, making it inadequate for safe agent operation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 1 parameter with 0% description coverage, and the description adds no meaning beyond the schema. It doesn't explain what the 'command' parameter should contain (e.g., syntax, examples, allowed commands) or any constraints. Since schema coverage is low, the description fails to compensate, leaving the parameter poorly documented.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose3/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description 'Run a shell command' clearly states the action (run) and target (shell command), providing a basic understanding of purpose. However, it lacks specificity about what kind of shell command or execution environment, making it somewhat vague. Since there are no sibling tools, differentiation isn't required, but the description could be more detailed.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool, such as for administrative tasks, automation, or debugging. It doesn't mention prerequisites like permissions, security considerations, or alternatives, leaving the agent with no context for decision-making. With no sibling tools, this is less critical but still a gap.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 1 tool updatev1.0.0
    • First observedrun_command

TDQS

C2.9/5.0
Disambiguation5/5

With only one tool, there is no possibility of ambiguity or overlap between tools. The single tool 'run_command' has a clear and distinct purpose that cannot be confused with any other tool in this set.

Naming Consistency5/5

The naming is perfectly consistent as there is only one tool. It follows a clear verb_noun pattern ('run_command'), and with no other tools to compare against, there is no inconsistency in naming conventions.

Tool Count2/5

A single tool is too few for a server named 'Shell MCP Server', which implies broader shell-related functionality. This minimal set feels thin and under-scoped, as it only covers basic command execution without supporting common shell operations like listing files, checking processes, or managing environment variables.

Completeness2/5

The tool set is severely incomplete for a shell server. While 'run_command' covers arbitrary command execution, it lacks tools for specific shell tasks (e.g., file operations, process management, directory navigation), leaving significant gaps that will likely cause agent failures when trying to perform common shell workflows.

Maintenance

ActivityInactive
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol server that allows LLMs to execute shell commands and receive their output in a controlled manner.
    7
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    A secure interface that enables language models to execute shell commands on the host operating system through the Model Context Protocol.
    1
    -
  • F
    license
    A
    quality
    D
    maintenance
    A local Model Context Protocol server that allows LLMs to securely execute shell commands on remote Linux and Windows systems via SSH connections.
    6
    17
    2
    -
  • F
    license
    B
    quality
    D
    maintenance
    A Model Context Protocol server that enables LLM applications to safely execute shell commands with error handling and timeout settings.
    1
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/hdresearch/mcp-shell'

If you have feedback or need assistance with the MCP directory API, please join our Discord server