mcp-shell-server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ALLOW_COMMANDS | No | Comma-separated list of commands that are allowed to be executed (e.g., 'ls,cat,pwd,grep,wc,touch,find') | |
| ALLOWED_COMMANDS | No | Alias for ALLOW_COMMANDS - comma-separated list of commands that are allowed to be executed |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| shell_executeA | Execute an allowed command as an argv array on the MCP server host. Allowed commands run with the server process's OS authority; the allowlist controls executable names, not what an allowed program does. Allowed commands: cat, pwd, wc, ls, grep Allowed patterns: Default timeout: 30s; maximum timeout: 300s; output cap: 1048576 bytes |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 1 tool
With only one tool, there is no possibility of confusion or overlap. The tool's purpose is clearly defined as executing allowed shell commands.
The single tool uses a clear verb_noun structure with snake_case, which is consistent. While there is no pattern to compare, the name accurately reflects its function.
At one tool, the server is minimal but arguably appropriate for its narrow purpose of executing allowed shell commands. However, according to the calibration, 1-2 tools feels thin and borderline, so this is not well-scoped for a typical server.
For the stated purpose of executing a predefined set of allowed commands, the surface is complete. There are no missing operations for this domain; the allowlist is a configuration parameter, not a missing tool.