Atlas / MCP servers / g0t4 / Server Commands

Server CommandsSAFE

mcp/g0t4/server-commands

Model Context Protocol server to run commands (tool: `runProcess`)

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 0r · 1w · 0d
Transport
stdio
License
MIT
Stars
234
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

runProcess tool

The runProcess tool runs processes on the host machine. There are two mutually exclusive ways to invoke it:

  1. `command_line` (string) — Executed via the system's default shell (just like typing into bash/fish/pwsh/etc). Shell features like pipes, redirects, and variable expansion all work.
  2. `argv` (string array) — Direct executable invocation. argv[0] is the executable, the rest are arguments. No shell interpretation.

You cannot pass both. The tool infers whether to use a shell from which parameter you provide.

If you want your model to use specific shell(s) on a system, I would list them in your system prompt. Or, maybe in your tool instructions, though models tend to pay better attention to examples in a system prompt.

Let me know if you encounter problems!

Tools

Tools are for LLMs to request. Claude Sonnet 3.5 intelligently uses run_process. And, initial testing shows promising results with Groq Desktop with MCP and llama4 models.

Currently, just one command to rule them all!

  • run_process - run a command, i.e. hostname or ls -al or echo "hello world" etc
  • Returns STDOUT and STDERR as text
  • Optional stdin parameter means your LLM can
  • pass scripts over STDIN to commands like fish, bash, zsh, python
  • create files with cat >> foo/bar.txt from the text in stdin
[!WARNING] Be careful what you ask this server to run! In Claude Desktop app, use Approve Once (not Allow for This Chat) so you can review each command, use Deny if you don't trust the command. Permissions are dictated by the user that runs the server. DO NOT run with sudo.

Video walkthrough

Prompts

Prompts are for users to include in chat history, i.e. via Zed's slash commands (in its AI

Read from source at commit 88c0f5f84124OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-server-commands -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server-commands": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
run_processwriteInclude command output in the prompt.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.config.fish
.config.fish
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.githooks.setup.fish
.githooks.setup.fish
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.rag.yaml
.rag.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/integration/fish_workaround.ts:37
exec(command, options, (error, stdout, stderr) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/manual/test-without-error-handler.cjs:6
const { stdout, stderr } = await exec(argv[2]);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/run_process.test.ts:1
import { runProcess } from "../../src/run_process.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/shells.test.ts:1
import { runProcess } from "../../src/run_process.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/typical-commands.test.ts:1
import { runProcess } from "../../src/run_process.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/jest, @types/node, chalk, jest, ts-jest, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 88c0f5f84124full audit observations/trust-audit/mcp-server/g0t4__server-commands.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0688c0f5f84124SAFEB89first audit
06

Questions

What is the Server Commands MCP server?

Model Context Protocol server to run commands (tool: `runProcess`)

What tools does Server Commands expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Server Commands safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Server Commands need?

No credential environment variables were found in its source, so it appears to need none.

How does Server Commands run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-server-commands at 0.8.2.

How current is this page?

The grade is for one exact copy of the source (88c0f5f84124), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement