Skip to main content
Glama
murzirius

VPS-Guardian-MCP

by murzirius

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
get_system_healthA

Retrieve a complete system health snapshot of the Linux VPS.

Returns a JSON string containing:

  • CPU: overall percentage, per-core breakdown, core counts, 1/5/15m load averages.

  • RAM & Swap: total, used, available, percentage.

  • Disk: root partition usage, read/write I/O counters.

  • Network: sent/received bytes, packets, and error counts.

  • Uptime: boot timestamp and human-readable duration (e.g. '12d 4h 32m 10s').

get_top_processesA

Retrieve the top resource-consuming processes running on the VPS.

Args: sort_by: Metric to rank processes by ('cpu' or 'memory'). Default: 'cpu'. limit: Number of top processes to return (1 to 50, default: 10).

Returns: JSON string listing process PID, name, user, CPU %, RAM %, RSS memory, and command summary.

check_service_statusA

Check the operational status of a systemd service unit.

Args: service_name: Name of the system service (e.g. 'nginx', 'mysql', 'postgresql', 'ufw', 'docker').

Returns: JSON string with active state ('active', 'inactive', 'failed'), enabled state, and recent status logs.

get_failed_systemd_unitsA

Find all degraded or failed systemd services across the entire system.

Returns: JSON string with list of failed units ('systemctl --failed') and overall health indicator.

read_service_logsA

Safely fetch and optionally filter recent log lines for a service or Docker container.

Args: service_name: Target unit (e.g. 'nginx', 'systemd:cron', 'docker:my_container'). lines_count: Number of recent lines to retrieve (default: 50, maximum: 1000). grep_filter: Optional case-insensitive keyword to filter lines (e.g. 'ERROR', '403', 'denied').

Returns: JSON string containing the extracted log lines and matching statistics.

list_docker_containersA

List Docker containers with their status, image, port bindings, volumes, and health.

Args: all: Set to True to list all containers (running and stopped), False for running only.

Returns: JSON string with list of containers, port forwards, and mount mappings.

get_docker_container_logsA

Safely read stdout/stderr logs from a specific Docker container.

Args: container_name: Container name or container short/full ID. lines_count: Number of recent log lines to retrieve (default: 50, max: 1000).

Returns: JSON string containing the container logs.

get_docker_statsA

Retrieve live resource utilization metrics for all running Docker containers.

Provides real-time CPU %, Memory %, Network I/O, and Block I/O (equivalent to docker stats).

Returns: JSON string listing resource metrics per running container.

get_open_portsA

Discover all listening network ports (TCP and UDP) and identify bound processes.

Returns: JSON string listing open ports, protocols (TCP/UDP), binding addresses (IPv4/IPv6), and process names/PIDs.

get_ufw_statusA

Inspect the status and active filtering rules of the UFW firewall.

Returns: JSON string containing UFW active state, default incoming/outgoing policies, and all active firewall rules.

view_file_contentA

Safely read the content of an authorized configuration or web file.

Permitted directories: /etc/nginx/, /etc/mysql/, /etc/postgresql/, /etc/docker/, /etc/caddy/, /var/www/ Strictly protected against path traversal attacks.

Args: file_path: Canonical path or relative path to the configuration file. max_bytes: Maximum bytes to return (default: 50,000, capped at 200,000).

Returns: JSON string with file content, size, and modification timestamp.

write_file_contentA

Atomically write or update a configuration file within authorized directories.

Creates an automatic timestamped backup (.bak.) before overwriting. Permitted directories: /etc/nginx/, /etc/mysql/, /etc/postgresql/, /etc/docker/, /etc/caddy/, /var/www/

Args: file_path: Path to the target configuration file. content: Text content to write. backup: Create a backup file before writing (default: True).

Returns: JSON string indicating write status and backup location.

list_directoryA

Inspect file and directory structures within authorized administrative paths.

Permitted directories: /etc/nginx/, /etc/mysql/, /etc/postgresql/, /etc/docker/, /etc/caddy/, /var/www/

Args: dir_path: Path to the directory to inspect. max_depth: Exploration depth (1 to 3, default: 1).

Returns: JSON string with item list (names, types, sizes, modification dates).

test_nginx_configA

Test Nginx configuration for syntax errors ('nginx -t') without reloading.

Returns: JSON string indicating syntax validity, exit code, and syntax error messages.

check_ssl_certificatesA

Audit SSL/TLS certificates configured on the host (Let's Encrypt / Certbot).

Returns: JSON string listing domains, expiration dates, days remaining, and warning flags.

list_virtual_hostsA

Inspect active Nginx virtual hosts, listening ports, SSL, and reverse proxy targets.

Returns: JSON string with parsed virtual hosts from /etc/nginx/sites-enabled/ and conf.d/.

check_failed_loginsA

Inspect recent failed SSH login attempts to detect brute-force attackers.

Args: limit: Number of recent failed attempts to inspect (default: 20, max: 100).

Returns: JSON string with recent failed logins and top offending attacker IP addresses.

get_fail2ban_statusA

Check Fail2ban status, active protection jails, and currently banned IP addresses.

Returns: JSON string detailing active jails and banned IP addresses.

audit_ssh_configA

Audit the SSH daemon configuration against security best practices.

Returns: JSON string with detected settings, security score (0-100), and remediation guidance.

analyze_disk_usageA

Analyze disk usage for a directory to discover space bottlenecks and large files.

Safely walks the filesystem without following symlinks and automatically skips virtual pseudo-filesystems (/proc, /sys, /dev, /run).

Args: target_path: Starting path to inspect (defaults to '/var'). max_depth: Depth of directory nesting to inspect (1 to 5, default 2). min_size_mb: Minimum size threshold in megabytes to include (default 50 MB). top_n: Maximum number of largest items to return (1 to 50, default 15).

Returns: JSON string with partition usage, largest directories, and largest files.

list_cron_jobsA

Discover all scheduled cron jobs on the Linux system.

Audits /etc/crontab, /etc/cron.d/, /etc/cron.* periodic scripts, and user crontabs.

Returns: JSON string containing scheduled jobs with user, schedule expression, human-readable timing explanation, and command.

list_systemd_timersA

Audit active and pending systemd timers via 'systemctl list-timers'.

Returns: JSON string with timer unit names, next execution time, countdown, and target services.

check_system_updatesA

Audit available operating system package updates and pending security patches.

Checks reboot requirements (/var/run/reboot-required), total upgradable packages, and security CVE patches. Cached for 5 minutes to minimize CPU and disk usage.

Args: force_refresh: Set to True to bypass the 5-minute cache and query package managers directly.

Returns: JSON string with update counts, security status, reboot flag, and recommended recovery action.

check_guardian_updatesA

Check if a newer version or commit of VPS-Guardian-MCP is available on GitHub.

Provides automated version verification and action guidance for self-updating. Cached for 5 minutes to minimize network and CPU overhead.

Args: force_refresh: Set to True to bypass cache and query GitHub API directly.

Returns: JSON string with current version, latest commit, update availability, and AI warning notice.

check_oom_eventsA

Inspect kernel logs for Linux Out-Of-Memory (OOM) Killer invocations.

Surfaces terminated processes, PIDs, and consumed RSS memory at time of termination.

Args: limit: Maximum number of recent OOM events to return (1 to 50, default 10).

Returns: JSON string with detected OOM incidents and diagnostic summary.

check_kernel_errorsA

Audit kernel logs for hardware failures, storage I/O errors, or application segfaults.

Args: limit: Maximum number of error entries to retrieve (1 to 50, default 20).

Returns: JSON string with categorized kernel errors, root causes, and critical issue counters.

test_network_connectivityA

Benchmark outbound network connectivity and latency using direct Python sockets.

Measures DNS resolution latency, TCP handshake time, and TLS handshake latency without shell ping.

Args: target_host: Destination hostname or IP address (e.g. 'api.github.com' or '8.8.8.8'). port: Destination port (1-65535, default 443). timeout_seconds: Network socket timeout (0.5 to 30.0 seconds, default 5.0).

Returns: JSON string with stage latency breakdown, resolved IP addresses, and TLS session details.

check_dns_healthA

Audit system DNS resolution health, configured nameservers, and query responsiveness.

Args: domains: Optional custom list of domains to probe. Defaults to essential public services.

Returns: JSON string with configured nameservers, individual domain lookup latencies, and health verdict.

get_database_healthA

Discover running databases and verify responsiveness, latency, and socket states.

Detects Redis, PostgreSQL, MySQL/MariaDB, and SQLite databases in application directories.

Returns: JSON string with operational state, socket accessibility, and ping latency for each engine.

execute_recoveryA

Execute an emergency recovery operation from a strictly whitelisted list.

Allowed actions:

  • 'restart_service': Restarts a systemd service (requires target=service_name, e.g. target='nginx').

  • 'clean_docker_cache': Deep prune of unused containers, networks, images, and volumes.

  • 'clean_system_logs': Prunes journal logs older than 3 days and rotated archives in /var/log.

  • 'kill_process': Terminates a runaway process by PID (requires target=PID, e.g. target='12345').

  • 'restart_nginx': Restarts Nginx web server (legacy alias for restart_service target='nginx').

  • 'vacuum_systemd_journal': Truncates journal logs to limit (target defaults to '200M').

  • 'clean_package_cache': Cleans APT archive cache and removes obsolete packages.

  • 'apply_security_updates': Non-interactively applies pending operating system security updates.

  • 'update_guardian': Self-updates VPS-Guardian-MCP from GitHub and refreshes virtual environment.

Args: action_name: The exact recovery action to execute. target: Optional target parameter required by certain actions.

Returns: JSON string with operation outcome, freed resources, or security error.

create_backupA

Create a compressed tar.gz archive of an authorized website or configuration directory.

Archives are saved into an isolated backup repository (/var/backups/vps-guardian/). Permitted source locations: /var/www/, /etc/nginx/, /etc/mysql/, /etc/postgresql/, /etc/docker/, /etc/caddy/

Args: backup_type: Identifier label for the archive (e.g. 'site', 'config', 'data'). source_path: Target directory to archive.

Returns: JSON string with archive file path, size, file count, and duration.

Prompts

Interactive templates invoked by user choice

NameDescription
triage_server_incidentStructured incident triage prompt guiding the AI through systematic diagnosis.
emergency_disk_cleanupGuidance prompt for resolving low disk space emergency on the VPS.
security_and_update_auditComprehensive routine for auditing VPS security, CVE updates, and authentication logs.
troubleshoot_application_crashRunbook for investigating mysterious application, container, or service terminations.

Resources

Contextual data attached and managed by the client

NameDescription
get_system_overview_resourceLive JSON resource providing continuous system snapshot and update alerts for AI context.
get_security_dashboard_resourceLive security dashboard aggregating firewall, failed logins, fail2ban, and open ports.

TDQS

A3.9/5.0

Scored across 31 tools

Disambiguation4/5

Tool names and descriptions generally separate resources and actions well, but a few overlapping boundaries remain: read_service_logs can already fetch Docker logs, duplicating get_docker_container_logs, and list_virtual_hosts/get_open_ports both surface listening-port info. Overall an agent can usually pick the right tool with careful reading.

Naming Consistency5/5

Every tool follows a snake_case verb_noun pattern with semantically appropriate verbs such as list, check, get, audit, test, execute, and create. Even with a large surface, the prefixes map predictably to action types and the resource nouns are clear.

Tool Count2/5

31 tools is a heavy single-server surface and exceeds the 25+ threshold for comfortable agent selection. Several tools could be consolidated, such as Docker logs vs. service logs, or system health vs. separate status/disk tools.

Completeness3/5

The server has strong coverage for monitoring, auditing, Docker, config files, and whitelisted recovery actions, but there are notable dead ends: backups can be created but not restored, SSH config is audited but cannot be edited, and UFW/SSL have no modification or renewal path. These gaps will force agents to stop or go outside the MCP for common VPS remediation tasks.

Maintenance

ActivityMaintained
ResponsivenessNo issues