claude-host-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| HOST_MCP_PROFILE | No | Profile: safe (read-only) / developer / full. | developer |
| HOST_MCP_LOG_LEVEL | No | Python log level. | WARNING |
| HOST_MCP_AUDIT_FILE | No | Audit trail path; empty disables. | ~/.local/share/claude-host-mcp/audit.jsonl |
| HOST_MCP_MAX_OUTPUT | No | Output truncation cap, chars. | 50000 |
| HOST_MCP_RATE_LIMIT | No | N/seconds per tool family. | 60/60 |
| HOST_MCP_READ_ROOTS | No | Readable roots (OS path separator). Default is $HOME:/etc:/var/log on Linux/macOS, $HOME on Windows. | $HOME:/etc:/var/log |
| HOST_MCP_MAX_TIMEOUT | No | Max run_command timeout, seconds. | 180 |
| HOST_MCP_WRITE_ROOTS | No | Writable roots (OS path separator). | $HOME |
| HOST_MCP_MAX_DOWNLOAD | No | Download/fetch cap, bytes (20 MB). | 20971520 |
| HOST_MCP_SNAPSHOT_DIR | No | Snapshot slot directory. | ~/.local/share/claude-host-mcp/snapshots |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| host_identityA | Return identity information for the real host running this MCP server. |
| system_summaryA | Get a compact summary of the real host: identity, uptime, disk and memory. |
| run_commandB | Run a shell command on the real host as the current desktop user. Bash ( |
| read_fileC | Read a text file from an allowed host path. Default readable roots are the home directory plus /etc and /var/log on Linux/macOS. Configure HOST_MCP_READ_ROOTS to change them. |
| write_fileA | Write a text file inside an allowed writable host root. Existing files are not replaced unless overwrite=true. Default writable root is the user's home directory. Configure HOST_MCP_WRITE_ROOTS to change it. |
| list_directoryB | List an allowed directory on the real host. |
| file_statA | Return size, modification time and type for a file on the host. |
| file_searchB | Recursively find files whose name matches a glob pattern (e.g. *.log). |
| file_grepB | Recursively search file contents for a regex pattern. Prefers ripgrep, falls back to grep or pure Python. |
| file_copyA | Copy a file or directory. Source must be readable, destination must be writable. |
| file_moveA | Move or rename a file or directory inside writable roots. |
| file_deleteA | Delete a file, or a directory when recursive=true. Never deletes a configured root itself. |
| process_listA | List host processes (ps sorted by CPU on Linux/macOS, tasklist on Windows), optionally filtered by a substring. |
| process_killB | Send a signal to a host process. PID 1 and the MCP server itself are protected. |
| service_statusA | Show status of a user-scope service: systemd --user on Linux, launchctl on macOS, sc query on Windows. |
| disk_usageA | Show filesystem usage (df on Linux/macOS, drive usage on Windows) plus size of one allowed path. |
| git_statusA | Show git status and current branch for a repository on the host. |
| git_logC | Show recent commits for a repository on the host. |
| git_diffA | Show uncommitted changes (or staged changes with staged=true) for a repository. |
| git_branchA | List local and remote branches for a repository on the host. |
| git_commitA | Stage all changes and commit in a repository inside writable roots. Never pushes. |
| http_fetchC | Fetch an http(s) URL from the host and return its text. Response size is capped. |
| network_checkB | Test whether a TCP port on a host is reachable from this machine. |
| download_fileB | Download an http(s) URL to a file inside writable roots. Total size is capped. |
| terminal_createA | Start a persistent shell session (or run a command interactively). Empty command spawns a login shell kept alive across calls. Use terminal_write to send input, terminal_read for incremental output, terminal_wait to block for a pattern/exit instead of polling. |
| terminal_readA | Read new output from a terminal session since cursor. Returns new cursor. |
| terminal_writeA | Send keystrokes/commands to a terminal session's stdin. |
| terminal_resizeB | Store terminal dimensions (metadata; no PTY ioctl yet). |
| terminal_signalB | Send INT/TERM/KILL (HUP on Unix) to a terminal session. |
| terminal_waitA | Block until regex pattern appears in new output, process exits, or timeout. |
| terminal_closeC | Terminate a terminal session and release it. |
| terminal_listA | List live terminal sessions with pid, cwd, age and buffer size. |
| job_startB | Launch a command in background. Returns job_id; page with job_output, block with job_wait. |
| job_statusA | Show state, pid, exit code and buffer sizes for a job. |
| job_outputA | Read new job output since cursor. Returns new cursor. |
| job_waitA | Block until a job exits or timeout. Prefer over polling job_status. |
| job_cancelA | Terminate a running job (TERM, then KILL after 5s). |
| job_listB | List background jobs, optionally only running ones. |
| audit_logA | Return the last N mutating-tool audit records (paths and sizes only, never contents). |
| audit_searchA | Filter audit trail by tool name substring and ok true/false/any. |
| edit_fileC | Replace an exact string in a file. dry_run=true previews a unified diff without writing. |
| apply_patchB | Apply a unified diff to a file ( |
| head_fileA | Return the first N lines of a file. |
| tail_fileA | Return the last N lines of a file. |
| directory_treeB | Render an ASCII tree of a directory (noise dirs hidden). |
| find_files_toolB | Find files by glob, fd preferred with find/pathlib fallback. |
| search_text_toolB | Search contents: literal by default, regex=true for patterns. rg preferred. |
| fuzzy_find_toolA | Subsequence filename search ranked by match compactness. |
| git_showC | Show a commit with stat (oneline). Read-only. |
| git_blameB | Blame line ranges of a tracked file. Read-only. |
| git_tagA | List/create/delete tags. list is read-only; create/delete prompt. |
| git_stashB | Stash list/push/pop/drop. pop/drop are destructive. |
| git_checkoutB | Checkout branch (create with -b). Refuses on dirty tree. |
| git_resetD | Reset modes; --hard requires confirm=true. |
| git_revertB | Revert a commit by creating an inverse commit. |
| git_mergeC | Merge a branch into the current one. |
| git_rebaseC | Rebase onto upstream; abort/continue conflicted rebases. |
| git_cleanA | Preview (dry_run) or execute clean; execution requires confirm=true. |
| git_worktree_createA | Create an isolated worktree under .worktrees/ for agent work. |
| git_worktree_listC | List worktrees of a repository. Read-only. |
| git_worktree_removeC | Remove an agent worktree created by git_worktree_create. |
| system_snapshotA | Point-in-time cpu/memory/disk/load/temps/battery/gpu/network/uptime. |
| journal_queryA | User journal tail, optional service/priority/since filter. |
| port_listA | Listening sockets with owner pid/process (/proc on Linux, ss/lsof fallback). |
| port_checkB | TCP connect to host:port with latency. |
| port_ownerB | Which process owns a listening port (pid, comm, cmdline, cwd). |
| docker_psA | List containers (running by default, all=true for all). |
| docker_logsB | Tail logs of a container. |
| docker_inspectB | State, image, ports and mounts of a container. |
| docker_startC | Start a container. |
| docker_stopA | Stop a container (10s timeout). |
| docker_restartB | Restart a container (10s timeout). |
| docker_rmA | Remove a (stopped) container. |
| docker_execA | Run sh -c inside a container. --privileged blocked. |
| package_searchB | Search native package manager (apt/dnf/pacman/brew/...). |
| package_infoC | Show package metadata from native manager. |
| package_installA | Install a package (apt/dnf/pacman/brew). Developer/full profile only. |
| package_removeA | Remove a package. Developer/full profile only. |
| package_updateA | Refresh package index (apt-get update / brew update / ...). |
| dns_lookupB | Resolve a hostname to addresses. |
| interface_listB | Network interfaces with state and MAC. |
| connection_listB | Active TCP/UDP sockets via ss or netstat. |
| diagnoseA | Layered diagnosis: host:port/http(s):// (DNS/TCP/owner/HTTP/resources) or service:NAME. |
| snapshot_createB | Copy a file/dir into a timestamped slot before risky ops. |
| snapshot_listA | List snapshot slots with source and creation time. |
| snapshot_restoreB | Copy a slot back. Prompts (destructive); overwrite required on clash. |
| file_versionB | One-call pre-edit snapshot of a single file. |
| file_restoreB | Restore the newest snapshot recorded for this path. |
| time_nowA | Current time in an IANA timezone (default local). |
| time_convertB | Convert ISO datetime between IANA timezones. |
| time_zonesB | List IANA zones, optionally filtered. |
| memory_storeB | Store one observation on an entity (persistent knowledge graph). |
| memory_linkC | Link two entities with a typed relation. |
| memory_recallB | Substring recall over entities, observations and relations. |
| memory_forgetB | Delete an observation or whole entity. Prompts. |
| thinkA | Record one reasoning step in a sequential chain. |
| think_listA | Return the current thought chain. |
| think_clearC | Clear the thought chain. Prompts. |
| fetch_textA | Fetch URL, strip boilerplate, return LLM-ready text (<=3 redirects). |
| web_searchA | Keyless-first search: auto fans out to html+wiki+duck; brave when keyed. |
| wiki_searchA | Dedicated Wikipedia search. Keyless, reputable, structured. |
| db_statusB | Keyless DB probe: sqlite files, postgres/redis reachability. |
| browser_fetchA | Render JS page in headless Chrome, return DOM text. Opt-in. |
| browser_shotA | Screenshot page to PNG in writable roots. Opt-in; prompts. |
| github_repoB | Repo metadata (needs GITHUB_TOKEN). |
| github_issueD | List/get/create issues. create prompts. |
| github_prD | List/get/create PRs. create prompts. |
| db_queryC | SELECT-first SQL (postgres psql / sqlite stdlib). Writes need confirm+full. |
| db_tablesB | List tables for a DSN. |
| redis_getC | GET a redis key (needs REDIS_URL or url=). |
| maps_geocodeA | Forward geocode (google with key, else nominatim). |
| maps_directionsB | Directions (google with key, else straight-line km). |
| drive_listC | List rclone remote path (needs RCLONE_REMOTE). |
| drive_getC | Copy remote file into writable roots. Prompts. |
| slack_listA | List channels (needs SLACK_BOT_TOKEN). |
| slack_sendC | Post a message. Prompts. |
| nine_statusA | Gateway health + version. No key needed. |
| nine_modelsB | List routable combos + provider models. |
| nine_combosC | Combos with member models (sina-pro, image, FastImg...). |
| nine_providersB | Provider health, no secrets. |
| nine_usageC | Requests, tokens, cost, provider list. |
| nine_chatB | Ask any combo/model. Single-shot completion with usage. |
| nine_chat_streamC | SSE chat; returns concatenated text. |
| nine_fanoutB | Same prompt to N models in parallel (max 6). Judge/ensemble primitive. |
| nine_imageA | Generate images (b64_json). Default auto-picks FastImg member. |
| nine_ttsC | Text-to-speech. Shape varies by host. |
| nine_sttC | Speech-to-text from base64 audio. |
| nine_embeddingsC | Embed texts. Shape varies by host. |
| nine_searchA | Web search through 9router's connection. Keyless for you. |
| nine_videoC | Video generation. Speculative on this host; kept for others. |
| accountsA | Linked providers with source + live status. Never returns secrets. |
| accounts_connectA | Start linking github|vercel|cloudflare. Returns open-link + request_id (or already:true). |
| accounts_waitB | Block until the user authorizes (link opened) or timeout. Polls 5s. |
| accounts_completeD | Validate a pasted token live, store chmod 600, close request. |
| accounts_removeA | Delete a stored token. Prompts. CLI logins untouched. |
| vercel_projectsA | List Vercel projects. Auto token (env > stored > CLI login). |
| vercel_deploymentsB | List deployments, optional project name/id filter. |
| vercel_inspectB | Deployment detail: aliases, state, regions, creator. |
| vercel_logsB | Build/runtime event tail for a deployment. |
| vercel_redeployC | Rebuild a deployment. Prompts (creates live deploys). |
| cloudflare_zonesA | List zones (id, name, status, plan). Needs token. |
| cloudflare_accountC | First account id/name. Needs Account:Read. |
| cloudflare_dnsB | List DNS records for a zone (name or id). |
| cloudflare_dns_createC | Create a DNS record. Prompts. |
| cloudflare_dns_deleteC | Delete a DNS record by id. Prompts. |
| cloudflare_purgeC | Purge a zone cache. Prompts. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| system-summary | One-line identity, uptime, disk, memory. |
| system-snapshot | Full cpu/memory/disk/load/gpu/net JSON. |
| system-ports | Listening sockets with owners JSON. |
| policy-current | Profile, roots, caps, destructive tools JSON. |
| audit-recent | Last 20 audit records JSON. |
| nine-status | Gateway health + version. |
| nine-models | Routable combos + models. |
TDQS
Scored across 146 tools
Many tools have overlapping purposes: web_search/wiki_search/nine_search, fetch_text/http_fetch/browser_fetch, find_files_tool/file_search/fuzzy_find_tool, search_text_tool/file_grep, and port_check/network_check are near-duplicates. The boundaries are often subtle and depend on backend or mode, which creates real misselection risk for an agent.
The set is mostly snake_case and readable, but conventions are mixed: some names are verb_noun (read_file, edit_file, run_command), some are noun_verb (file_search, terminal_create, web_search), and some are noun_noun (db_status, git_show, docker_ps). Inconsistent prefixes like git_ vs github_ and odd suffixes like find_files_tool or fuzzy_find_tool further break uniformity.
146 tools is an extreme count for a single MCP server, far beyond even a broad host-management scope. Rather than a focused tool set, this is a grab-bag of host operations, git, Docker, databases, AI services, and multiple SaaS integrations that would be better split into several purpose-specific servers.
Core host operations are very well covered: files, processes, git, Docker, terminal, jobs, network, snapshots, and packages all have solid lifecycle support. However, several bundled external domains are incomplete—GitHub issues/PRs lack update/merge operations, Cloudflare DNS has create/delete but no update, Slack only sends and lists channels, and Drive only lists and fetches.