Linux MCP Server
Enables remote execution of Linux commands via SSH, supporting system monitoring, file operations, and secure authentication with configurable safety controls.
README
Linux MCP Server Setup Guide
This MCP server allows you to execute Linux commands on remote hosts securely via SSH.
Features
- Execute arbitrary Linux commands on remote hosts
- System information gathering (hostname, OS, memory, disk usage, etc.)
- Directory listing with detailed options
- File operations (read, write, append)
- Secure authentication via SSH keys or passwords
- Environment-based configuration for credentials
- Connection management with automatic reconnection
Installation
- Install dependencies:
pip install -r requirements.txt
- Create environment file:
cp .env.example .env
- Edit
.envwith your credentials:
# Required settings
LINUX_HOST=your-server-ip
LINUX_USERNAME=your-username
# Authentication: Use either password OR SSH key (SSH key is recommended)
# Option 1: Password authentication
LINUX_PASSWORD=your_password
# Option 2: SSH key authentication (recommended)
LINUX_SSH_KEY_PATH=/path/to/your/private/key
# Optional: Connection timeout in seconds
LINUX_TIMEOUT=30
# Optional: Logging level (DEBUG, INFO, WARNING, ERROR)
LOG_LEVEL=INFO
# Enable/disable warnings (default: true)
LINUX_ENABLE_WARNINGS=true
# Block critical commands entirely (default: false)
LINUX_BLOCK_CRITICAL=false
# Requires confirmation for high/critical commands (default: true)
# Disables confirmation requirement (only shows warnings) if false
LINUX_REQUIRE_CONFIRMATION=true
Configuration Options
Required Variables
LINUX_HOST: IP address or hostname of the target Linux systemLINUX_USERNAME: Username for SSH connection
Authentication (choose one)
LINUX_SSH_KEY_PATH: Path to your SSH private key file (recommended)LINUX_PASSWORD: SSH password (less secure)
Optional Variables
LINUX_PORT: SSH port (default: 22)LINUX_TIMEOUT: Connection timeout in seconds (default: 30)LOG_LEVEL: Logging level (default: INFO)LINUX_ENABLE_WARNINGS: Enable/disable warnings (default: true)LINUX_BLOCK_CRITICAL: Block critical commands entirely (default: false)LINUX_REQUIRE_CONFIRMATION: Requires confirmation for high/critical commands (default: true). Else, disables confirmation requirement (only shows warnings) - ⚠️⚠️⚠️ DANGEROUS!!! ⚠️⚠️⚠️
Important Configuration Notice
Warning: The Linux MCP server supports configuration changes and potential execution of critial commands, but please ensure you only use this functionality when you want LLM-generated configurations to be loaded and/or potential critical commands executed on your linux server.
Always review the configuration being generated or the commands being executed by the LLM and only allow tool execution if it's the correct configuration/execution for your use case.
SSH Key Setup (Recommended)
- Generate SSH key pair (if you don't have one):
ssh-keygen -t rsa -b 4096 -f ~/.ssh/linux_mcp_key
- Copy public key to target host:
ssh-copy-id -i ~/.ssh/linux_mcp_key.pub username@your-server-ip
- Set the key path in .env:
LINUX_SSH_KEY_PATH=/home/user/.ssh/linux_mcp_key
Running the Server
Directly with your system python:
python linux_mcp_server.py
Directly with your virtual environment python in uv:
uv run python linux_mcp_server.py
Available Tools
1. execute_command
Execute any Linux command on the remote host.
- Parameters:
command(required): The Linux command to executetimeout(optional): Command timeout in seconds
Example:
{
"command": "ps aux | grep python",
"timeout": 60
}
2. get_system_info
Get comprehensive system information including hostname, OS, memory, disk usage, and CPU info.
Example usage: No parameters required.
3. list_directory
List contents of a directory.
- Parameters:
path(optional): Directory path (default: current directory)detailed(optional): Show detailed listing with permissions, sizes, etc.
Example:
{
"path": "/var/log",
"detailed": true
}
4. file_operations
Perform file read/write operations.
- Parameters:
operation(required): "read", "write", or "append"file_path(required): Path to the filecontent(required for write/append): Content to write/append
Example:
{
"operation": "write",
"file_path": "/tmp/test.txt",
"content": "Hello, World!"
}
Security Considerations
- Use SSH keys instead of passwords when possible
- Limit user permissions on the target host
- Use a dedicated user for MCP operations
- Keep your .env file secure and never commit it to version control
- Consider firewall rules to restrict SSH access
- Regular key rotation for enhanced security
Troubleshooting
Connection Issues
- Verify host IP and port are correct
- Check if SSH service is running on target host
- Ensure firewall allows SSH connections
- Verify SSH key permissions (should be 600)
Authentication Issues
- Check username is correct
- For SSH keys: ensure public key is in
~/.ssh/authorized_keyson target host - For passwords: verify password is correct and account is not locked
Permission Issues
- Ensure the user has necessary permissions for the commands you're trying to execute
- Consider using
sudoin commands if needed (configure sudoers appropriately)
Example .env File
# Production server
LINUX_HOST=192.168.1.100
LINUX_PORT=22
LINUX_USERNAME=mcpuser
LINUX_SSH_KEY_PATH=/home/user/.ssh/production_key
LINUX_TIMEOUT=30
LOG_LEVEL=INFO
LINUX_ENABLE_WARNINGS=true
LINUX_BLOCK_CRITICAL=true
LINUX_REQUIRE_CONFIRMATION=true
Integration with MCP Clients
This server follows the MCP (Model Context Protocol) specification and can be integrated with any MCP-compatible client. The server communicates via stdio and provides structured tool definitions that clients can discover and use.
Security
Maximum Safety Configuration Successfully intented. The Linux MCP server is configured with maximum safety settings:
Configuration Applied:
Environment Variables Set:
LINUX_ENABLE_WARNINGS=true # Show all warnings
LINUX_BLOCK_CRITICAL=true # Block critical commands entirely
LINUX_REQUIRE_CONFIRMATION=true # Require confirmation for dangerous commands
Safety Behavior Now Active:
🛡️ Critical Commands (rm -rf /, dd of=/dev/, etc.)**
COMPLETELY BLOCKED - Cannot be executed even with confirmation Will show error message explaining the block
⚠️ High-Risk Commands (shutdown, reboot, kill, etc.)
REQUIRES CONFIRMATION - Must ask user first, then re-run with confirm_dangerous=true Shows detailed warnings about risks
⚡ Medium-Risk Commands (chmod, docker, etc.)
SHOWS WARNINGS - Executes with safety warnings displayed
✅ Safe Commands
Execute normally without warnings
What This Means:
I will ALWAYS ask for confirmation before running dangerous commands like shutdown, reboot, kill, etc. Critical commands will be completely blocked - commands like rm -rf /, dd of=/dev/sda, mkfs cannot be executed at all All warnings are enabled - you'll see detailed risk analysis for any potentially dangerous operation The system is now maximally protected while still being functional for legitimate operations
The Linux MCP server is now configured with the highest level of safety protection possible. When the server restarts, it will load these new settings and enforce maximum safety protocols.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。