MCP shell server for controlled local and SSH argv execution with sudo password support and strict local WORK_DIR filesystem confinement on Linux.
Three tools with comprehensive descriptions (194 - 350 chars, well above baseline 194 avg) and detailed parameter documentation. All parameters have types and descriptions. Input schemas are complete with proper JSON Schema. Error handling is documented (status 126 for policy rejection, timeout/output-limit flags). However, no output schema is explicitly documented in the visible code, and tool annotations (destructiveHint, readOnlyHint) are absent from the MCP registration. Naming is clear and verb-based (shell_execute, ssh_execute, shell_config). Risk levels are declared but not via MCP annotations.
Inspect the effective non-secret shell and SSH execution policy. Use this tool before shell_execute or ssh_execute when you need to know whether sudo password injection is configured, SSH is available, WORK_DIR confinement is active, or command allowlisting applies. This operation is read-only and never exposes either sudo password.
Execute one local Linux process using an explicit argv array. Use this tool when a local command must actually run. The command executes with the server process's permissions and may cause filesystem, process, service, network, or other system side effects. Commands prefixed with "sudo" may run with elevated privileges when sudo is enabled. Shell operators such as pipes, redirects, &&, ||, and variable expansion are not interpreted. For remote execution prefer ssh_execute. For compatibility, the simple argv form ["ssh", "host", "sudo", "command", ...] is detected and the configured remote sudo password is supplied through stdin. Complex SSH option sets should use ssh_execute instead. Use shell_config first when execution restrictions such as sudo, SSH, WORK_DIR confinement, or command allowlisting are relevant. Policy or configuration rejections return status 126; timeout and output-limit conditions are reported in the result.
Execute one command on a remote host through the local OpenSSH client. Prefer this tool over shell_execute when the target command runs on another machine. SSH login authentication itself must already work non-interactively through the user's SSH config, key, or agent. This tool does not inject an SSH login password. When sudo=true, the remote command is sent as `sudo -S -p '' -- ...`. PASSWORD_SUDO_SSH is used when configured; otherwise PASSWORD_SUDO is reused. The password is sent only through SSH stdin and is never placed in process argv. If neither password is configured, remote sudo uses `sudo -n` so it fails instead of waiting for an interactive password prompt. Remote argv elements are quoted with shlex semantics before OpenSSH passes the command to the remote login shell. Set tty=true only when the remote sudo policy requires a TTY. WORK_DIR and SSH execution are intentionally incompatible because local bubblewrap confinement cannot restrict filesystem changes made on a remote host. When ALLOW_COMMANDS is configured, both `ssh` and the remote target executable must be present in the allowlist.
Output schema not documented in tool definitions. Descriptions mention 'stdout, stderr, exit status, execution time, timeout flag, and output-limit flag' but no formal schema is visible in the @mcp.tool() registration.
Tool annotations missing. Risk levels (DESTRUCTIVE, READ_ONLY) are declared in comments but not registered via MCP destructiveHint/readOnlyHint/idempotentHint annotations, preventing clients from enforcing safety policies.
Error responses return generic dict with error message but no structured error classification (retryable vs fatal). LLM cannot determine whether to retry, ask user, or abort.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 73 | <=2025-11-25 | v2 |
No pagination or result limits documented for shell_execute/ssh_execute output. If stdout/stderr are very large, response could exhaust context window.
Parameter 'directory' accepts any path without validation hints. With WORK_DIR configured, path must resolve inside WORK_DIR, but this constraint is not formally expressed in the schema (no pattern, no enum).