sully-termux-mcp
A secure MCP gateway for Termux that exposes filesystem, shell, and Termux:API tools over a local HTTP endpoint with admin controls, job management, and upstream support.
README
sully-termux-mcp
sully-termux-mcp is a Node.js 20+ TypeScript ESM gateway for running MCP tools in Termux. The production default is deliberately small: it listens on a loopback address only, requires a 32-byte Bearer token, and exposes a separate authenticated admin API.
Quick start
npm ci
npm run build
node dist/cli.js setup
node dist/cli.js start
node dist/cli.js status
node dist/cli.js pair # explicit user action; prints both tokens
The generated configuration is ~/.config/sully-mcp/config.json with mode 0600; data, job output, and the redacted audit log are under ~/.local/share/sully-mcp with mode 0700. Never paste pairing JSON into a log or issue.
For phone controls, install the Termux:API command package (pkg install termux-api) and install the Termux:API companion Android app from the same signing source (for example, both from F-Droid, or both from GitHub). Android will not deliver API calls when the two packages come from different signing sources. Restart the gateway after installing or updating Termux:API so its command inventory is rebuilt.
The MCP endpoint is http://127.0.0.1:8765/mcp. This release supports the stable 2025-11-25 and 2025-06-18 session-based protocols using initialize, notifications/initialized, tools/list, and tools/call. The 2026-07-28 transport is intentionally not advertised until its required routing headers and response envelope are implemented. DELETE /mcp closes a 2025 session.
Administration
POST /admin/v1 uses the admin Bearer token and accepts { "action": "status", "params": {} }. Actions include status, doctor, permissions, capabilities, jobs.list, jobs.output, jobs.cancel, jobs.cleanup, profiles.list, profiles.upsert, profiles.remove, upstreams.list, upstreams.import, upstreams.update, upstreams.remove, gateway.stop, tokens.rotate, and pair.revoke. All responses have {ok:true,result} or {ok:false,error}. Secrets are only returned for an explicit tokens.rotate response or the explicit pair CLI command.
permissions and doctor include a centralized Termux:API checklist grouped by device, communication, media, interaction, and automation. Command availability is detected at startup; Android runtime permission state is reported as unknown, and the same-signature-source requirement for Termux:API is explicit.
Tools and limits
Built-ins include bounded echo_safe, fs_read, fs_write, fs_list, fs_metadata, fs_find, fs_copy, fs_move, command profiles, shell jobs, job status/output/cancel/cleanup, and detected Termux:API commands (including typed location, camera, notification, toast, clipboard, SMS, TTS, volume, and torch inputs). Less common API commands expose bounded raw args with a usage/help hint; consult the installed command's --help for exact options. shell_exec always spawns bash -lc with shell:false; command profiles and stdio upstreams use an executable plus argument array with shell:false. Jobs survive restarts as interrupted, capture at most 8 MiB, and return at most 64 KiB per output request. Requests are limited to 1 MiB and responses to 4 MiB; tool concurrency defaults to four.
HTTP upstreams must use HTTPS, or HTTP on the exact literal loopback host 127.0.0.1/::1 (no DNS aliases or whitespace). HTTPS destinations resolving to private, link-local, or metadata ranges are rejected. Redirects, URL credentials, fragments, and non-allowlisted tools are rejected. HTTP and stdio upstream tools are prefixed (id__tool) and can be restricted with allowedTools, readOnly, and prefix.
Termux lifecycle
The normal sully-mcp start/restart lifecycle acquires termux-wake-lock when available and stop releases it. Install termux-boot/sully-termux-mcp as ~/.termux/boot/sully-termux-mcp and make it executable to start after reboot. Android battery optimisation can still stop Termux; the application should treat an unavailable gateway as recoverable.
Supported CLI commands: setup, start, stop, restart, status, logs, doctor, permissions, pair, update, and uninstall --yes.
Release integrity
npm run release -- --version 0.2.0 requires MCP_RELEASE_ED25519_PRIVATE_KEY and runs a build before writing sully-termux-mcp-0.2.0.tar.gz, its SHA-256, manifest, and Ed25519 signature. The App command in scripts/install-command.txt downloads the fixed GitHub Release archive, hash, manifest, and signature into a temporary directory, compares the archive to its pinned expected hash, verifies the Ed25519 signature with its inline public key, and only then runs the verified archive's scripts/install-local.sh. The local installer checks Node 20+, runs npm ci --omit=dev and the build, and swaps an atomic versions/<version>/current symlink while preserving the previous current target on failure. It also creates a real sully-mcp wrapper in Termux's $PREFIX/bin (or ~/.local/bin) and never uses an unverified curl | sh pipeline. The private signing key is supplied transiently through MCP_RELEASE_ED25519_PRIVATE_KEY by the release operator and is never committed.
Security model
Only loopback hosts are accepted for the local listener. MCP and admin credentials are independent 64-hex random values and compared with a constant-time comparison. Configuration is written as UTF-8 with restrictive permissions. The server does not return tokens from /health, tool lists, normal errors, audit records, or job metadata. Audit entries are redacted and bounded. Side-effect tools are never automatically retried. Destructive upstream tools must be explicitly allowlisted by the caller.
This repository is licensed under the PolyForm Noncommercial License 1.0.0 carried over from SULLYTEST2.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。