cli-mcp-server

MCP.Pizza Chef: MladenSU

Your assistant gets two tools: run a command inside one folder you nominate, and show the rules currently in force. Out of the box only ls, cat, and pwd are permitted, plus a few flags, so it can look around but change nothing. Setting the allowed-commands option to 'all' removes that fence completely and hands over unrestricted command access. No key or account is involved anywhere. Turning on shell operators sends your whole command line through a shell, which widens the risk, and the project has had no code changes since July 2025.

Unmaintained · no code changes since July 2025, no successor named
Coding
Files/PDF

Use This MCP server To

List and read the files in one folder from chat Check what a script produced without opening a terminal Let my assistant run one specific command I approved See exactly which commands my assistant is allowed to run Give an assistant safe read-only access to a project folder

README

CLI MCP Server


A secure Model Context Protocol (MCP) server implementation for executing controlled command-line operations with comprehensive security features.

License Python Version MCP Protocol smithery badge Python Tests


Table of Contents

  1. Overview
  2. Features
  3. Configuration
  4. Available Tools
  5. Usage with Claude Desktop
  6. Security Features
  7. Error Handling
  8. Development
  9. License

Overview

This MCP server enables secure command-line execution with robust security measures including command whitelisting, path validation, and execution controls. Perfect for providing controlled CLI access to LLM applications while maintaining security.

cli-mcp-server FAQ

Do I need a key or an account?
No. Despite what some listings claim, there is no key of any kind. Nothing talks to an outside service — the only setup is a folder path and a list of allowed commands.
Is it actually safe to let an assistant run commands?
The defaults are cautious: three read-only commands, a few flags, a length cap, a thirty-second timeout, and path checks that follow symlinks so nothing outside your chosen folder is reachable.
Can it delete or overwrite my files?
Not with the default list of ls, cat and pwd. It can only do that if you add something like rm or mv to the allowed list yourself.
What do the 'all' settings do?
They switch the safety off. Allowing all commands and all flags gives the assistant unrestricted use of your command line inside that folder, so treat those options as a deliberate choice rather than a convenience.
Can I use this to search through a folder of documents?
Yes — add grep or find to the allowed commands, point the folder setting at your documents, and then ask in plain language.
Is this project still maintained?
It works and is not archived, but the code has had no changes since July 2025 and no replacement project is named by the author.
How hard is it to set up?
You paste a config block listing your folder, allowed commands and allowed flags. The uv tool needs to be installed on your computer first.