trackmcp
Back to directory

Execute a secure shell in Claude Desktop using the Model Context Protocol.

37 stars JavaScriptAI & Machine Learning Updated Oct 3, 2025
claudefunction-callingshell

Documentation

Shell MCP Server

A Node.js implementation of the Model Context Protocol (MCP) that provides secure shell command execution capabilities. This server allows AI models to execute shell commands in a controlled environment with built-in security measures. Easily integrates with Claude Desktop for connecting Claude with your shell.

Features

  • MCP-compliant server implementation
  • Secure command execution with blacklist protection
  • Command existence validation
  • Standard I/O based transport
  • Error handling and graceful shutdown

Installation

Run `npx mcp-shell`.

To add it to Claude Desktop, run `npx mcp-shell config`. Or add `npx -y mcp-shell` to your config manually.

Start (or restart) Claude Desktop and you should see the MCP tool listed on the landing page.

Security Features

The server implements several security measures:

1. Command Blacklisting

    2. Command Validation

      Available Tools

      The server provides one tool:

      run_command

      Executes a shell command and returns its output.

      Input Schema:

      json
      {
        "type": "object",
        "properties": {
          "command": { "type": "string" }
        }
      }

      Response:

      • Success: Command output as plain text
      • Error: Error message as plain text

      Blacklisted Commands

      The following command categories are blocked for security:

      • File System Destruction Commands (rm, rmdir, del)
      • Disk/Filesystem Commands (format, mkfs, dd)
      • Permission/Ownership Commands (chmod, chown)
      • Privilege Escalation Commands (sudo, su)
      • Code Execution Commands (exec, eval)
      • System Communication Commands (write, wall)
      • System Control Commands (shutdown, reboot, init)

      Error Handling

      The server includes comprehensive error handling:

      • Command not found errors
      • Blacklisted command errors
      • Execution errors
      • MCP protocol errors
      • Graceful shutdown on SIGINT

      Implementation Details

      The server is built using:

      • Model Context Protocol SDK
      • StdioServerTransport for communication
      • execa for command execution
      • command-exists for command validation

      Development

      To modify the security settings, you can:

      1. Edit the `BLACKLISTED_COMMANDS` set to adjust blocked commands

      2. Modify the `validateCommand` function to add additional validation rules

      3. Enhance the command parsing logic in the `CallToolRequestSchema` handler

      Frequently asked questions

      What is mcp-shell?

      mcp-shell is Execute a secure shell in Claude Desktop using the Model Context Protocol.

      How do I install mcp-shell?

      Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

      Is mcp-shell open source?

      Yes — it is hosted on GitHub at https://github.com/hdresearch/mcp-shell and has 37 stars.

      Related MCP tools

      Run your own MCP server? See who uses it and what to fix.

      Measure it with TrackMCP