mcp-shell-server

MCP.Pizza Chef: tumf

Everything hinges on one setting: the list of allowed command names you write into the config. Nothing outside that list will run, and if you leave it empty the assistant is told plainly that no commands are permitted. There is a single tool here, shell_execute, which takes a command, optional typed-in input, a folder and a time limit. No account or paid key is involved. Whatever you do allow runs without a confirmation step, so putting a deleting command on the list means deletes happen unprompted.

Coding
Files/PDF

Use This MCP server To

Count the files in a folder without opening a terminal Search a folder for every file mentioning a client name Check how much free space is left on my disk Show me the first lines of a log file Limit my assistant to a few harmless read-only commands

README

MCP Shell Server

codecov smithery badge

MseeP.ai Security Assessment Badge

A secure shell command execution server implementing the Model Context Protocol (MCP). This server allows remote execution of whitelisted shell commands with support for stdin input.

mcp-shell-server MCP server

Features

  • Argv-based Command Execution: Allowed commands run via subprocess argv without shell-string interpretation
  • Standard Input Support: Pass input to commands via stdin
  • Comprehensive Output: Returns stdout, stderr, exit status, and execution time
  • Safe Pipeline Support: Pipelines preserve and validate argv segments instead of invoking a shell
  • Execution Limits: Server-side default timeout, maximum timeout, and output byte caps are enforced
  • Contained Redirection: <, >, and >> targets must stay inside the requested working directory
  • Minimal Child Environment: Child processes receive a small allowlisted environment instead of inheriting all server secrets
  • Structured Audit Logging: Success, rejection, timeout, output-cap, and process-error outcomes are logged with redaction

MCP client setting in your Claude.app

Published version

code ~/Library/Application\ Support/Claude/claude_desktop_config.json

mcp-shell-server FAQ

Do I need an account or a paid key?
No. There is nothing to sign up for. The only required setting is the list of command names you are willing to allow.
How many things can it actually do?
Exactly one, a tool called shell_execute. It runs a command you allowed and hands back the output, any error text and the exit status.
Can I use this to delete or overwrite my files?
Only if you put a deleting or overwriting command on your allow list, and then it will happen with no confirmation prompt. Leave those off the list and it cannot.
What happens if I do not set anything up?
The assistant is refused every command and told that no commands are allowed, so an unconfigured install is harmless but useless.
Which apps does it work in?
It is documented for Claude Desktop, and it works in any assistant that starts a local helper from the same kind of config file.
Is it genuinely safe to hand my computer over?
The author is explicit that the protections are best-effort rather than a real sandbox, and recommends running it inside a container if you allow a broad list.
How hard is the setup?
You paste a short block into a config file and type your command list. Python 3.11 or newer needs to be on the machine first.