Skip to content

tumf/mcp-shell-server

MCP Developer Tools

A secure shell command execution server that runs only whitelisted commands over the Model Context Protocol (MCP).

Python Latest v1.1.3 · 2h ago Security brief →

Features

  • Executes only pre‑whitelisted shell commands via argv (no shell string interpretation)
  • Supports stdin input and returns stdout, stderr, exit status, and execution time
  • Enforces timeouts, output size caps, and contained redirection within the working directory
  • Runs child processes with a minimal, allowlisted environment to hide secrets
  • Emits structured audit logs for every invocation

Recent releases

View all 5 releases →
Upgrade now
v1.1.3 Security relevant
RCE / SSRF

Reject sed/GNU find/AWK exec

Upgrade now
v1.1.2 Security relevant
RCE / SSRF

Git config override rejection

Review required
v1.1.1 Security relevant
RCE / SSRF

Security hardening of command arguments

No immediate action
v1.1.0 Breaking risk

Removed asyncio dependency

Upgrade now
v1.0.4 Security relevant
RCE / SSRF Breaking upgrade

Subprocess hardening

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
182
Forks
45
Languages
Python Shell Makefile

Install & Platforms

Install via
pip npm

Beta — feedback welcome: [email protected]