Skip to main content
Glama
tumf

mcp-shell-server

by tumf

MCP シェル サーバー

コードコフ 鍛冶屋のバッジ

モデルコンテキストプロトコル(MCP)を実装したセキュアシェルコマンド実行サーバー。このサーバーは、標準入力をサポートし、ホワイトリストに登録されたシェルコマンドのリモート実行を可能にします。

特徴

  • 安全なコマンド実行:ホワイトリストに登録されたコマンドのみ実行可能

  • 標準入力サポート: stdin経由でコマンドに入力を渡す

  • 包括的な出力: stdout、stderr、終了ステータス、実行時間を返します。

  • シェル演算子の安全性: シェル演算子 (;、&&、||、|) の後のコマンドを検証します。

  • タイムアウト制御: コマンドの最大実行時間を設定する

Related MCP server: Shell MCP Server

Claude.app の MCP クライアント設定

公開版

code ~/Library/Application\ Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "shell": {
      "command": "uvx",
      "args": [
        "mcp-shell-server"
      ],
      "env": {
        "ALLOW_COMMANDS": "ls,cat,pwd,grep,wc,touch,find"
      }
    },
  }
}

ローカルバージョン

構成

code ~/Library/Application\ Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "shell": {
      "command": "uv",
      "args": [
        "--directory",
        ".",
        "run",
        "mcp-shell-server"
      ],
      "env": {
        "ALLOW_COMMANDS": "ls,cat,pwd,grep,wc,touch,find"
      }
    },
  }
}

インストール

Smithery経由でインストール

Smithery経由で Claude Desktop の Shell Server を自動的にインストールするには:

npx -y @smithery/cli install mcp-shell-server --client claude

手動インストール

pip install mcp-shell-server

Smithery経由でインストール

Smithery経由で Claude Desktop の Shell Server を自動的にインストールするには:

npx -y @smithery/cli install mcp-shell-server --client claude

使用法

サーバーの起動

ALLOW_COMMANDS="ls,cat,echo" uvx mcp-shell-server
# Or using the alias
ALLOWED_COMMANDS="ls,cat,echo" uvx mcp-shell-server

ALLOW_COMMANDS (またはそのエイリアスであるALLOWED_COMMANDS )環境変数は、実行を許可するコマンドを指定します。コマンドはカンマで区切ることができ、前後にスペースを入れることもできます。

ALLOW_COMMANDS または ALLOWED_COMMANDS の有効な形式:

ALLOW_COMMANDS="ls,cat,echo"          # Basic format
ALLOWED_COMMANDS="ls ,echo, cat"      # With spaces (using alias)
ALLOW_COMMANDS="ls,  cat  , echo"     # Multiple spaces

リクエスト形式

# Basic command execution
{
    "command": ["ls", "-l", "/tmp"]
}

# Command with stdin input
{
    "command": ["cat"],
    "stdin": "Hello, World!"
}

# Command with timeout
{
    "command": ["long-running-process"],
    "timeout": 30  # Maximum execution time in seconds
}

# Command with working directory and timeout
{
    "command": ["grep", "-r", "pattern"],
    "directory": "/path/to/search",
    "timeout": 60
}

応答フォーマット

成功した応答:

{
    "stdout": "command output",
    "stderr": "",
    "status": 0,
    "execution_time": 0.123
}

エラー応答:

{
    "error": "Command not allowed: rm",
    "status": 1,
    "stdout": "",
    "stderr": "Command not allowed: rm",
    "execution_time": 0
}

安全

サーバーはいくつかのセキュリティ対策を実装しています。

  1. コマンドホワイトリスト: 明示的に許可されたコマンドのみ実行可能

  2. シェル演算子の検証: シェル演算子 (;、&&、||、|) の後のコマンドもホワイトリストに対して検証されます。

  3. シェルインジェクションなし: コマンドはシェル解釈なしで直接実行されます

発達

開発環境の設定

  1. リポジトリをクローンする

git clone https://github.com/yourusername/mcp-shell-server.git
cd mcp-shell-server
  1. テスト要件を含む依存関係をインストールする

pip install -e ".[test]"

テストの実行

pytest

APIリファレンス

リクエスト引数

分野

タイプ

必須

説明

指示

[]

はい

コマンドとその引数を配列要素として

標準入力

いいえ

コマンドに渡される入力

ディレクトリ

いいえ

コマンド実行のための作業ディレクトリ

タイムアウト

整数

いいえ

最大実行時間(秒)

応答フィールド

分野

タイプ

説明

標準出力

コマンドからの標準出力

標準エラー出力

コマンドからの標準エラー出力

状態

整数

終了ステータスコード

実行時間

フロート

実行にかかった時間(秒)

エラー

エラー メッセージ (失敗した場合のみ表示)

要件

  • Python 3.11以上

  • mcp>=1.1.0

ライセンス

MITライセンス - 詳細はLICENSEファイルを参照

Available Tools

1 tool
shell_executeA

Execute a shell command Allowed commands: pwd, grep, cat, ls, wc Allowed patterns: Default timeout: 30s; maximum timeout: 300s; output cap: 1048576 bytes

ParametersJSON Schema
NameRequiredDescriptionDefault
stdinNoInput to be passed to the command via stdin
commandYesCommand and its arguments as array
timeoutNoMaximum execution time in seconds; clamped to server maximum
directoryNoOptional working directory. Omit to use the MCP server process current working directory; relative paths are resolved from that same server process CWD.

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the transparency burden. It discloses the allowed commands, default/maximum timeout, and output cap, providing useful behavioral context. However, it omits details about stderr handling, output truncation behavior, or the fact that all allowed commands are read-only, preventing a perfect score.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is brief and front-loaded with the primary action, followed by key constraints. However, the 'Allowed patterns: ' line is empty and incomplete, which introduces a minor structural flaw and reduces clarity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description captures the essential constraints (allowed commands, timeout, output cap) and parameter semantics are handled by the schema. Yet it does not describe the return format, stderr handling, or exit code behavior, and the incomplete 'Allowed patterns' field leaves a gap in coverage for a shell execution tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already provides complete descriptions for all four parameters (100% coverage), so the baseline is 3. The description adds marginal value by mentioning the default timeout (30s) and maximum timeout (300s), which aligns with the 'timeout' parameter but does not elaborate on other parameters beyond what the schema already states.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description explicitly states 'Execute a shell command' and lists the allowed commands (pwd, grep, cat, ls, wc), making the tool's purpose specific and unambiguous. Even without siblings, the allowed-command list defines scope clearly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description communicates constraints via 'Allowed commands' and 'Allowed patterns', indicating when the tool is appropriate. However, it does not explicitly state when to use this tool versus alternatives (there are none listed) or provide a 'when not to use' guideline, leaving usage context somewhat implicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 1 tool updatev1.1.0
    • Changedshell_execute4 fields changed
      • changedInput schema / properties / directory / description
        Previous value: -"Absolute path to a working directory where the command will be executed"New value: +"Optional working directory. Omit to use the MCP server process current working directory; relative paths are resolved from that same server process CWD."
      • changedInput schema / properties / timeout / description
        Previous value: -"Maximum execution time in seconds"New value: +"Maximum execution time in seconds; clamped to server maximum"
      • changedInput schema / properties / timeout / minimum
        Previous value: -0New value: +1
      • changedInput schema / required
        Previous value: -[
        -  "command",
        -  "directory"
        -]New value: +[
        +  "command"
        +]
  2. 1 tool update
    • First observedshell_execute

TDQS

A3.9/5.0
Disambiguation5/5

Only one tool exists, so there is no possibility of confusion or overlap. Every action goes through the single shell_execute tool.

Naming Consistency5/5

The tool name shell_execute follows a clear verb_noun pattern, consistent with common MCP naming conventions. Even with a single tool, the name is predictable and descriptive.

Tool Count3/5

With only one tool, the set feels thin, but for a restricted shell executor it could be acceptable. The scope is narrow, making the tool count borderline rather than clearly excessive or insufficient.

Completeness3/5

The tool covers the allowed commands (pwd, grep, cat, ls, wc), but the restricted set excludes many typical shell operations like file writing or process control. This suggests notable gaps for a server named 'shell', though the explicit allowlist mitigates some issues.

Maintenance

ActivityMaintained
ResponsivenessWithin a week

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    D
    maintenance
    A secure MCP server for executing whitelisted shell commands with resource and timeout controls, designed for integration with Claude and other MCP-compatible LLMs.
    20
    389
    7
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol server that allows LLMs to execute shell commands and receive their output in a controlled manner.
    7
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/tumf/mcp-shell-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server