Server CommandsSAFE
Model Context Protocol server to run commands (tool: `runProcess`)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
runProcess tool
The runProcess tool runs processes on the host machine. There are two mutually exclusive ways to invoke it:
- `command_line` (string) — Executed via the system's default shell (just like typing into
bash/fish/pwsh/etc). Shell features like pipes, redirects, and variable expansion all work. - `argv` (string array) — Direct executable invocation.
argv[0]is the executable, the rest are arguments. No shell interpretation.
You cannot pass both. The tool infers whether to use a shell from which parameter you provide.
If you want your model to use specific shell(s) on a system, I would list them in your system prompt. Or, maybe in your tool instructions, though models tend to pay better attention to examples in a system prompt.
Let me know if you encounter problems!
Tools
Tools are for LLMs to request. Claude Sonnet 3.5 intelligently uses run_process. And, initial testing shows promising results with Groq Desktop with MCP and llama4 models.
Currently, just one command to rule them all!
run_process- run a command, i.e.hostnameorls -alorecho "hello world"etc- Returns
STDOUTandSTDERRas text - Optional
stdinparameter means your LLM can - pass scripts over
STDINto commands likefish,bash,zsh,python - create files with
cat >> foo/bar.txtfrom the text instdin
[!WARNING] Be careful what you ask this server to run! In Claude Desktop app, useApprove Once(notAllow for This Chat) so you can review each command, useDenyif you don't trust the command. Permissions are dictated by the user that runs the server. DO NOT run withsudo.
Video walkthrough
Prompts
Prompts are for users to include in chat history, i.e. via Zed's slash commands (in its AI
88c0f5f84124OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-server-commands -- npx -y [email protected]
{
"mcpServers": {
"mcp-server-commands": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
run_process | write | Include command output in the prompt. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
.config.fish
.githooks.setup.fish
.rag.yaml
exec(command, options, (error, stdout, stderr) => {const { stdout, stderr } = await exec(argv[2]);import { runProcess } from "../../src/run_process.js";import { runProcess } from "../../src/run_process.js";import { runProcess } from "../../src/run_process.js";@types/jest, @types/node, chalk, jest, ts-jest, typescript
Gates applied: no_behavioural_pass.
88c0f5f84124full audit observations/trust-audit/mcp-server/g0t4__server-commands.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 88c0f5f84124 | SAFE | B | 89 | first audit |
Questions
What is the Server Commands MCP server?
Model Context Protocol server to run commands (tool: `runProcess`)
What tools does Server Commands expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Server Commands safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Server Commands need?
No credential environment variables were found in its source, so it appears to need none.
How does Server Commands run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-server-commands at 0.8.2.
How current is this page?
The grade is for one exact copy of the source (88c0f5f84124), read on 2026-10-06. The repository is watched and re-audited when it changes.