CLI toolkit for provisioning, securing, and managing self-hosted servers via MCP. Supports Coolify, Dokploy, and bare VPS deployment on Hetzner, DigitalOcean, Vultr, and Linode with security audits, backups, and maintenance.
Kastell demonstrates strong overall definition quality with 17 well-named tools, comprehensive descriptions for each tool, and explicit parameter schemas with types and descriptions. Most tools follow verb-noun naming conventions and include actionable context. However, several tools lack explicit output schema documentation visible in the source, and some parameter descriptions could be more prescriptive about constraints and formats. Tool compositions are well-designed with clear purpose separation. The security-focused tools (server_secure, server_audit, server_lock) are particularly well-described with detailed action enumerations and context about prerequisites. Plugin tools are registered with proper annotations but lack visibility into plugin-specific schemas.
Run security audit on servers and track compliance. Actions: full security audit with category breakdown, optional compliance framework check (CIS, PCI-DSS, HIPAA), snapshot creation/comparison, regression detection, and quick-win recommendations. Supports filtering by category, severity, or profile (web-server, database, mail-server). Compare mode compares two snapshots: format 'before:after' (e.g. 'pre-upgrade:latest'). Threshold check fails if score below specified minimum.
Backup and snapshot Kastell servers. Backup: 'backup-create' dumps Coolify DB + config via SSH (Coolify servers) or system config files (bare servers), 'backup-list' shows local backups, 'backup-restore' restores from backup — bare servers restore system config, Coolify servers restore DB+config (SAFE_MODE blocks restore). Snapshot: 'snapshot-create'/'snapshot-list'/'snapshot-delete' manage cloud provider snapshots (requires provider API token). Snapshots not available for manually added servers.
Compare security posture between two servers. Shows category-by-category score deltas and check-level differences (passed/failed/skipped). Supports fresh live audits or snapshot comparison. Useful for identifying divergent configurations.
Diagnose server health issues. Analyzes cached metrics (memory, CPU, disk, Docker, Coolify health, SSH key validity, expiring certificates). Actions: 'diagnose' reads cached diagnostics (fast), autoFix applies fixes. Requires active probe for fresh metrics (see server_guard). Supports dry-run and force options for CI/automation. Returns grouped findings with severity counts and fix commands.
Output schemas not documented in tool descriptions. While input parameters are well-defined, LLMs cannot predict what fields will be returned (e.g., server_info 'list' action returns what structure? server_audit returns score in what format?). This forces agents to make assumptions about downstream chaining.
server_plugin tool lacks visibility into plugin-specific parameter schemas. The tool registration uses a generic defaultSchema with only 'server' parameter, but plugins declare their own parameters. LLMs cannot see plugin parameter types/descriptions at discovery time, forcing blind parameter passing.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 74 | 2025-06-18+ | v2 |
| 2026-03-09 | D | 52 | 1.27.1+ | v1 |
Export compliance evidence for external auditors. Generates audit snapshots as point-in-time evidence for compliance frameworks (CIS, PCI-DSS, HIPAA). Requires prior server_audit run to have evidence available.
Explain security audit checks: detailed descriptions, why each check matters, and step-by-step remediation instructions. Useful for understanding audit failures before running server_fix.
Auto-remediate security findings. Analyzes audit results, identifies quick-win fixes (failed checks with available fixes), and applies SSH commands. Supports dry-run (preview without executing) and force mode (skip prompts). Blocked in SAFE_MODE unless dry-run. Returns before/after scores and detailed remediation log.
View fleet-wide health and security summary across all Kastell-managed servers. Aggregates health status (SSH/Coolify reachability), latest audit scores, and key metrics. Supports sorting by health score or provider. Useful for multi-server dashboards and compliance monitoring.
Active Probe: continuous SSH session monitoring for servers. Actions: 'start' initiates active probe session for a server, 'stop' terminates the session, 'status' reports active probes and recent diagnostics. Used by server_doctor for fresh diagnostics. Active sessions consume SSH connections — use sparingly.
Get information about Kastell-managed servers. Actions: 'list' all servers, 'status' check cloud provider + Coolify/bare status, 'health' check Coolify reachability or SSH access for bare servers, 'sizes' list available server types with prices for a provider+region. Requires provider API tokens as environment variables (HETZNER_TOKEN, DIGITALOCEAN_TOKEN, VULTR_TOKEN, LINODE_TOKEN) for status/sizes checks. Avoid calling repeatedly in short intervals to prevent provider API rate limiting. For fleet-wide health and audit scores across all servers, use server_fleet instead.
Comprehensive server hardening: one-shot command applies SSH hardening + fail2ban + UFW + sysctl + unattended-upgrades. Idempotent (safe to run multiple times). Requires SSH access. Locked servers achieve >90 audit score baseline.
Fetch logs and system metrics from Kastell-managed servers via SSH. Actions: 'logs' retrieves recent log lines from Coolify container (Coolify servers only), Docker service, or system journal. Bare servers: use service 'system' or 'docker' (coolify service not available). 'monitor' fetches CPU, RAM, and disk usage metrics (works for all server modes). Requires SSH access to target server (root@ip). Note: live streaming (--follow) is not available via MCP — use the CLI for live log tailing.
Maintain Kastell servers. Actions: 'update' runs Coolify update via SSH (Coolify servers only — bare servers are blocked), 'restart' reboots server via cloud provider API (works for both Coolify and bare servers), 'maintain' runs full 5-step maintenance (Coolify servers only — bare servers are blocked). Snapshot not included — use server_backup tool. Requires SSH access for update, provider API tokens for restart/status. Manual servers: restart not available.
Manage Kastell servers. Actions: 'add' registers an existing Coolify or bare server to local config (validates API token, optionally verifies Coolify via SSH — pass mode:'bare' for servers without Coolify). 'remove' unregisters a server from local config only (cloud server keeps running). 'destroy' PERMANENTLY DELETES the server from the cloud provider and removes from local config. Requires provider API tokens as environment variables. Destroy is blocked when KASTELL_SAFE_MODE=true. Server mode for 'add' action: 'coolify', 'dokploy', or 'bare'. Default: coolify
Execute custom plugin tools (extensibility system). Plugins provide domain-specific actions registered under 'kastell/' prefix. Each plugin declares tools with handlers, parameters, and output schemas. Requires plugin to be installed in kastell-plugin/ directory.
Provision a new server on a cloud provider. Default: Coolify auto-install via cloud-init. Pass mode:'bare' for a generic VPS without Coolify (installs UFW and runs system updates only). Requires provider API token as environment variable (HETZNER_TOKEN, DIGITALOCEAN_TOKEN, VULTR_TOKEN, LINODE_TOKEN). WARNING: Creates a billable cloud resource. Blocked when KASTELL_SAFE_MODE=true. Server takes 3-5 minutes to fully initialize after provisioning.
Secure Kastell servers. Secure: 'secure-setup' applies SSH hardening + fail2ban, 'secure-audit' runs security audit with score. Firewall: 'firewall-setup' installs UFW with Coolify ports, 'firewall-add'/'firewall-remove' manage port rules, 'firewall-status' shows current rules. Domain: 'domain-set'/'domain-remove' manage custom domain with optional SSL, 'domain-check' verifies DNS, 'domain-info' shows current FQDN. All require SSH access to server. For full one-shot hardening (SSH + fail2ban + UFW + sysctl + unattended-upgrades), use server_lock instead.
Several tools accept optional 'server' parameter with fallback to 'Auto-selected if only one server exists.' This creates ambiguity: does the tool error when multiple servers exist and server param is omitted? Or silently picks the first? LLMs cannot predict behavior without explicit handling rules.
Numeric parameters lack explicit range constraints. 'limit' in server_logs accepts a number but does not specify min/max (e.g., is 0 allowed? Is 10000 allowed?). server_audit 'threshold' accepts 1-100 per description, but schema does not enforce bounds.
Some parameter descriptions include example values (e.g., 'e.g. nbg1, sfo1' in server_provision 'region'). LLMs tend to reuse example values literally rather than adapting to context. Use enum or formal regex patterns instead.