Skip to main content
Glama
kaznak

Shell Command MCP Server

by kaznak
README.md
# *OBSOLETE*

I recommend using Claude Code by running `claude mcp serve` instead of this MCP server.
I have created [ai-agent-workspace](https://github.com/kaznak/container-images/tree/main/ai-agent-workspace) as a container to run Claude Code.
Please use it as needed.

# Shell Command MCP Server

This is an MCP (Model Context Protocol) server that allows executing shell commands within a Docker container. It provides a secure and isolated workspace for running commands without giving access to the host Docker daemon.

## Features

- Run shell scripts through a simple MCP interface
  - synchronous execution
  - asynchronous execution with 4 different modes
    - complete: notify when the command is completed
    - line: notify on each line of output
    - chunk: notify on each chunk of output
    - character: notify on each character of output
- Kubernetes tools included: kubectl, helm, kustomize, hemfile
- Isolated Docker container environment with non-root user
  - host-container userid/groupid mapping implemented. this allows the container to run as the same user as the host, ensuring that files created by the container have the same ownership and permissions as those created by the host.
  - mount a host directory to the container /home/mcp directory for persistence. it become the home directory the AI works in.
  - if the host directory is empty, the initial files will be copied form the backup in the container.

## Design Philosophy

This MCP server provides AI with a workspace similar to that of a human.
Authorization is limited not by MCP functions, but by container isolation and external authorization restrictions.

It provides more general tools such as shell script execution, so that they can be used without specialized knowledge of tool use.

The server implementation is kept as simple as possible to facilitate code auditing.

## Getting Started

### Prerequisites

- Docker

### Usage with Claude for Desktop

Add the following configuration to your Claude for Desktop configuration file.

MacOS:

```json
"shell-command": {
  "command": "docker",
  "args": [
    "run",
    "--rm",
    "-i",
    "--mount",
    "type=bind,src=/Users/user-name/MCPHome,dst=/home/mcp",
    "ghcr.io/kaznak/shell-command-mcp:latest"
  ]
}
```

Replace `/Users/user-name/ClaudeWorks` with the directory you want to make available to the container.

Windows:

```json
"shell-command": {
   "command": "docker",
   "args": [
      "run",
      "--rm",
      "-i",
      "--mount",
      "type=bind,src=\\\\wsl.localhost\\Ubuntu\\home\\user-name\\MCPHome,dst=/home/mcp",
      "ghcr.io/kaznak/shell-command-mcp:latest"
   ]
}
```

### Feed some prompts

To Operate the files in the mounted directory.

## Available MCP Tools

- [execute-bash-script-sync](./src/execute-bash-script-sync.ts)
- [execute-bash-script-async](./src/execute-bash-script-async.ts)

## Security Considerations

- The MCP server runs as a non-root user within the container
- The container does not have access to the host Docker daemon
- User workspace is mounted from the host for persistence

## License

MIT

TDQS

A3.7/5.0

Scored across 2 tools

Disambiguation5/5

The two tools are perfectly distinct: one for asynchronous execution and one for synchronous execution. Their names and descriptions clearly differentiate their purposes, with no overlap or ambiguity in functionality.

Naming Consistency5/5

Both tools follow a consistent verb_noun pattern with kebab-case (execute-bash-script-async and execute-bash-script-sync). The naming is predictable and uniform across the set.

Tool Count2/5

With only 2 tools, the server feels thin for a shell command domain. While it covers basic execution modes, it lacks tools for other common operations like file manipulation, process monitoring, or environment inspection, making the scope incomplete.

Completeness2/5

The toolset is severely incomplete for a shell command server. It only provides script execution in two modes, missing essential operations like listing files, checking system status, managing processes, or handling input/output redirection, which are core to shell interactions.

Maintenance

ActivityInactive
ResponsivenessNo issues