Community System

Shell

Run arbitrary shell commands — full control of the host with configurable allow/deny lists.

197 stars 50 forks Last commit 3d ago Language TypeScript License MIT
Sign in to like, install, or save to a bundle → View on GitHub →

Install

npm install -g mcp-shell-server

Maintain this server? Add the badge

Show your README readers it's in a curated directory — and give them a one-click path to install docs and config.

Listed on Prismix ← links back here

Markdown

[![Listed on Prismix](https://prismix.dev/api/badge/mcp/shell.svg)](https://prismix.dev/mcp/shell)
Theme-aware version (auto dark/light on GitHub) →
<a href="https://prismix.dev/mcp/shell"><picture><source media="(prefers-color-scheme: dark)" srcset="https://prismix.dev/api/badge/mcp/shell.svg?theme=dark"><img alt="Listed on Prismix" src="https://prismix.dev/api/badge/mcp/shell.svg"></picture></a>

Claude Desktop / Cursor config

Drop into your claude_desktop_config.json or Cursor MCP settings. Replace the ${…} placeholders with your own values.

{
  "mcpServers": {
    "shell": {
      "command": "npx",
      "args": ["-y", "mcp-shell-server"],
      "env": { "ALLOWED_COMMANDS": "ls,cat,grep,git,npm,node" }
    }
  }
}

About

Shell execution server. Two safety layers: configurable command allow-list (only run commands you whitelist) and a sandboxed working directory. Strong power, strong footgun — use with restricted scope only.

Recent releases (5)

All releases →
  • v1.1.12 Latest Sep 19, 2026
    Security release: reject persistent `git config` invocations prefixed by the value-taking `--attr-source` or `--shallow-file` global options. These parser mismatches could bypass the existing policy and persist an executable Git alias.
    
    Affected versions: `<= 1.1.11`. Upgrade to `1.1.12` or later.
    
    Advisory: https://github.com/tumf/mcp-shell-server/security/advisories/GHSA-7v25-vcp6-4hcr
    View on GitHub ↗
  • v1.1.11 Sep 18, 2026
    ## Security
    
    - Reject GNU awk `@nsinclude` external program-source directives.
    - Complete the AWK hardening tracked in [GHSA-8wm7-jvxq-2r3m](https://github.com/tumf/mcp-shell-server/security/advisories/GHSA-8wm7-jvxq-2r3m).
    - Preserve option-parser state for `--`, inline program boundaries, and values consumed by safe options.
    
    Versions `<=1.1.10` are affected. Upgrade to `1.1.11` or later.
    
    View on GitHub ↗
  • v1.1.10 Sep 18, 2026
    ## Security
    
    - Reject AWK program-source and extension-loading options that bypass argv program inspection, including GNU long options, accepted abbreviations, short forms and clusters, `-W` aliases, and `@include`/`@load` directives.
    - Fixes [GHSA-8wm7-jvxq-2r3m](https://github.com/tumf/mcp-shell-server/security/advisories/GHSA-8wm7-jvxq-2r3m).
    
    Versions `<=1.1.9` are affected. Upgrade to `1.1.10` or later.
    
    View on GitHub ↗
  • v1.1.9 Aug 15, 2026
    ## Security
    
    - Harden allowlisted GNU `sort` and `gsort` arguments against external program execution and path escape.
    - Reject `--compress-program`, `-o`/`--output`, `--files0-from`, and `-T`/`--temporary-directory`, including GNU abbreviations, attached values, clustered forms, and options after operands.
    - Preserve ordinary sorting and option-like filenames after a discrete `--`.
    
    Versions `<=1.1.8` are affected. Upgrade to `1.1.9` or later.
    
    Fixes GHSA-74g6-ch7r-v7jr.
    
    PyPI: https://pypi.org/project/mcp-shell-server/1.1.9/
    View on GitHub ↗
  • v1.1.8 Aug 8, 2026
    ## Security
    
    - Preserve literal pipe characters inside argv arguments. Pipeline syntax is now recognized only from a discrete `|` argv element.
    - Prevent attached pipe arguments from creating unintended pipeline stages or bypassing command-specific argument policies such as the `awk` external-access check.
    - Attached pipes are no longer implicit pipeline syntax. Use `["cmd1", "|", "cmd2"]`.
    
    Fixes GHSA-q8pm-q3r2-q7cg and GHSA-7wg7-jj87-qp4c.
    
    PyPI: https://pypi.org/project/mcp-shell-server/1.1.8/
    
    View on GitHub ↗

Discussion (0)

Sign in to comment →

No comments yet. Sign in to start the discussion.

More System servers