MCP Shell Server
MCP Shell 服务器
使用模型上下文协议 (MCP) 执行 Shell 命令的服务器。它充当桥梁,使 AI 代理能够安全地执行 Shell 命令。
特征
执行shell命令(单行和多行支持)
支持各种shell(bash、zsh、fish、powershell、cmd等)
详细的错误处理和日志记录
兼容 MCP Inspector
Related MCP server: Command Executor MCP Server
安装
从 npm(作为用户)
# Using npm
npm install -g @mkusaka/mcp-shell-server
# Using yarn
yarn global add @mkusaka/mcp-shell-server
# Using pnpm
pnpm add -g @mkusaka/mcp-shell-server从源头(用于开发)
# Clone the repository
git clone https://github.com/mkusaka/mcp-shell-server.git
cd mcp-shell-server
# Install dependencies
pnpm install
# Build the project
pnpm buildMCP 配置
游标配置
将以下内容添加到您的 Cursor 配置文件( ~/.cursor/config.json ):
{
"mcpServers": {
"shell": {
"command": "npx",
"args": ["-y", "@mkusaka/mcp-shell-server"]
}
}
}克莱恩积分
Cline是一个 VS Code 扩展,允许您将 MCP 服务器与 Claude AI 结合使用。要使用 Cline 设置此 MCP shell 服务器,请执行以下操作:
打开您的 Cline MCP 设置文件:
macOS:
~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.jsonWindows:
%APPDATA%/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.jsonLinux:
~/.config/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json
添加shell服务器MCP配置:
{ "mcpServers": { "shell": { "command": "npx", "args": ["-y", "@mkusaka/mcp-shell-server"], "disabled": false, "autoApprove": [] } } }或者,如果您想使用本地安装的包:
{ "mcpServers": { "shell": { "command": "node", "args": ["/path/to/mcp-shell-server/dist/index.js"], "disabled": false, "autoApprove": [] } } }
规则配置
将以下内容添加到您的 AI 助手的规则或提示中:
You have MCP Shell tools at your disposal. Follow these rules regarding Shell tool usage:
1. ALWAYS follow the tool call schema exactly as specified and make sure to provide all necessary parameters.
2. **NEVER refer to tool names when speaking to me.** For example, instead of saying 'I need to use the shell_exec tool to run this command', just say 'I'll run that command for you'.
3. Only use Shell tools when they are necessary. If my task is general or you already know the answer, just respond without calling tools.
4. When I ask you to execute shell commands, use the appropriate tool to:
- Run single-line commands
- Run multi-line commands (using heredoc syntax when appropriate)
- Execute file operations, git commands, or system utilities
- Provide system information when relevant
5. Always be careful with shell commands that might modify the system, and explain what the command will do before executing it.
6. If a shell command produces an error, explain what went wrong in simple terms and suggest ways to fix it.用法
直接执行
node dist/index.js
# or as an executable
./dist/index.js开发模式
pnpm dev使用 MCP Inspector 进行测试
pnpm inspect命令行参数
-s, --shell <shell> Specify the path to the shell to use
-w, --working-dir <directory> Specify the working directory for command execution
-h, --help Display help message
-V, --version Display version information工具参考
shell_exec
在指定的 shell 中执行命令。
参数:
command(字符串,必需):要执行的 shell 命令workingDir(字符串,可选):执行命令的工作目录。必须在 $HOME 下。
资源参考
服务器提供以下系统信息作为资源:
主机名
返回系统的主机名。
URI: hostname://
平台
返回操作系统平台。
URI: platform://
壳
返回服务器正在使用的 shell 路径。
URI: shell://
用户名
返回当前用户名。
URI: username://
系统信息
以 JSON 格式返回全面的系统信息,包括:
主机名
平台
壳
用户名
CPU 数量
总内存
释放内存
系统正常运行时间
使用示例
基本命令执行
{
"name": "shell_exec",
"parameters": {
"command": "echo Hello, World!"
}
}多行命令(Heredoc)执行
{
"name": "shell_exec",
"parameters": {
"command": "cat << EOF | grep 'example'\nThis is an example text.\nAnother line without the keyword.\nEOF"
}
}发展
项目结构
src/
├── index.ts # Main entry point
└── shell-server/
├── index.ts # Shell server implementation
└── lib/
└── logger.ts # Logging configuration日志记录
日志写入mcp-shell.log文件。
执照
麻省理工学院
Available Tools
1 toolshell_execC
Executes commands in the specified shell with detailed error handling and output capture
| Name | Required | Description | Default |
|---|---|---|---|
| command | Yes | The shell command to execute in the configured shell environment | |
| workingDir | No | Optional working directory to execute the command in (must be under $HOME for security) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions 'detailed error handling and output capture' which adds some context beyond basic execution, but fails to address critical aspects like security implications, permission requirements, rate limits, or what happens when commands fail. For a shell execution tool with zero annotation coverage, this leaves significant gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that front-loads the core purpose ('Executes commands in the specified shell') and adds value with secondary capabilities ('with detailed error handling and output capture'). Every word earns its place with zero waste.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity of shell execution (security risks, variable outputs) and the absence of both annotations and an output schema, the description is insufficient. It doesn't explain return values, error formats, or security constraints beyond the schema's workingDir note. For a potentially dangerous tool with no structured safety indicators, more descriptive context is needed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents both parameters thoroughly. The description adds no additional parameter semantics beyond what's in the schema (e.g., no examples of command syntax, working directory constraints beyond security). The baseline score of 3 reflects adequate schema coverage without description enhancement.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Executes commands in the specified shell' with additional capabilities for 'detailed error handling and output capture'. It uses specific verbs ('executes', 'capture') and identifies the resource ('shell commands'). However, there are no sibling tools mentioned, so differentiation from alternatives cannot be evaluated.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives, prerequisites, or security considerations. It mentions 'detailed error handling and output capture' which implies some context, but offers no explicit when/when-not instructions or named alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v1.0.0- First observed
shell_exec
TDQS
Scored across 1 tool
With only one tool, there is no possibility of ambiguity or overlap between tools. The tool's purpose is clearly defined and distinct by default.
A single tool inherently has perfect naming consistency, as there are no other tools to compare against. The name 'shell_exec' follows a clear verb_noun pattern.
A single tool is generally too few for a server's purpose, as it limits functionality and may indicate an incomplete surface. However, for a simple shell execution server, it could be minimally viable but lacks breadth.
The tool provides basic shell command execution, but there are obvious gaps such as no tools for listing available commands, managing shell sessions, or handling file operations, making the surface severely incomplete for typical shell-related tasks.
Maintenance
Related MCP Connectors
MCP server for building and testing AI agents with multi-model experimentation and insights.
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
- ArcjetOAuthcom.arcjet
An MCP server for Arcjet - the runtime security platform that ships with your AI code.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that allows LLMs to execute shell commands and receive their output in a controlled manner.7MIT
- AlicenseBqualityDmaintenanceA Model Context Protocol server that allows secure execution of pre-approved commands, enabling AI assistants to safely interact with the user's system.12 npm22ISC
- AlicenseCqualityCmaintenanceA server that enables AI assistants to execute terminal commands and retrieve outputs via the Model Context Protocol (MCP).326MIT
- AlicenseCqualityCmaintenanceA secure server that implements the Model Context Protocol (MCP) to enable controlled execution of authorized shell commands with stdin support.1MIT