Atlas / MCP servers / gongrzhe / Terminal Controller

Terminal ControllerSAFE

mcp/gongrzhe/terminal-controller

A Model Context Protocol (MCP) server that enables secure terminal command execution, directory navigation, and file system operations through a standardized interface.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
10 5r · 4w · 1d
Transport
stdio
License
MIT
Stars
95
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that enables secure terminal command execution, directory navigation, and file system operations through a standardized interface.

[](https://smithery.ai/server/@GongRzhe/terminal-controller-mcp)

Features

  • Command Execution: Run terminal commands with timeout controls and comprehensive output capture
  • Directory Management: Navigate and list directory contents with intuitive formatting
  • Security Measures: Built-in safeguards against dangerous commands and operations
  • Command History: Track and display recent command executions
  • Cross-Platform Support: Works on both Windows and UNIX-based systems
  • File Operations: Read, write, update, insert, and delete file content with row-level precision

Installation

Installing via Smithery

To install Terminal Controller for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @GongRzhe/terminal-controller-mcp --client claude

Prerequisites

  • Python 3.11+
  • An MCP-compatible client (such as Claude Desktop)
  • UV/UVX installed (optional, for UVX method)

Method 1: PyPI Installation (Recommended)

Install the package directly from PyPI:

pip install terminal-controller

Or if you prefer to use UV:

uv pip install terminal-controller

Method 2: From Source

If you prefer to install from source:

  1. Clone this repository:
git clone https://github.com/GongRzhe/terminal-controller-mcp.git
cd terminal-controller-mcp
  1. Run the setup script:
python setup_mcp.py

Client Configuration

Claude Desktop

There are two ways to configure Claude Desktop to use Terminal Controller:

Option 1: Using UVX (Recommended)

Add

Read from source at commit 49aa192985b2OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add terminal-controller -- uvx terminal-controller
claude-desktop
{
  "mcpServers": {
    "terminal-controller": {
      "command": "uvx",
      "args": [
        "terminal-controller"
      ]
    }
  }
}
03

Exposed tools (10)

5 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
change_directoryread
delete_file_contentdestructive
execute_commandwrite
get_command_historyread
get_current_directoryread
insert_file_contentwrite
list_directoryread
read_fileread
update_file_contentwrite
write_filewrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_file_content
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, httpx
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 49aa192985b2full audit observations/trust-audit/mcp-server/gongrzhe__terminal-controller.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0749aa192985b2SAFEB89first audit
06

Questions

What is the Terminal Controller MCP server?

A Model Context Protocol (MCP) server that enables secure terminal command execution, directory navigation, and file system operations through a standardized interface.

What tools does Terminal Controller expose?

10 in total: 5 read-only, 4 that write, and 1 that can delete or overwrite (delete_file_content). Every one is listed on this page with its risk.

Is Terminal Controller safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Terminal Controller need?

No credential environment variables were found in its source, so it appears to need none.

How does Terminal Controller run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as terminal-controller.

How current is this page?

The grade is for one exact copy of the source (49aa192985b2), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement