UnraidBLOCK
Query, monitor, and manage Unraid servers via GraphQL API through MCP tools. Supports system info, Docker, VMs, array/parity, notifications, plugins, rclone, and live telemetry.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pypi.org/project/unraid-mcp/) [](https://github.com/dinglebear-ai/unraid/pkgs/container/unraid-mcp)
A monorepo of Unraid tooling: two MCP servers (Python and Rust) and three Unraid OS plugins, plus the Claude/Codex agent integrations that surface them.
Repo name. This repo was renamedunraid-mcp→unraidon 2026-07-27, and the former standalonerunraidandincus-unraidrepos were merged in here. Some deployed plugin install/update URLs still depend on the old-name redirect; migrating those runtime URLs requires a deliberate release. The PyPI package, the container image, the Claude plugin, and the Unraid `.plg` are all still namedunraid-mcp— only the repo changed.
Components
fba9703e062fOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add unraid-mcp --env UNRAID_API_KEY=${UNRAID_API_KEY} -- uvx unraid-mcp==2.10.2Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Commands | read | Command execution requires approval when Codex requests it. |
JailAction | read | Jail lifecycle actions |
PackageEcosystem | read | Package catalog to search — apt is Debian/Ubuntu only |
Unraid | read | Unraid control surface |
http-toolkit | read | includes curl support |
Trust audit
BLOCKgrade F · trust 23/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (12 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const TEST_RSA_KEY_PEM: &str = r"-----BEGIN PRIVATE KEY-----
exec($command . ' 2>&1', $out, $code);
exec(RC . ' status 2>/dev/null', $out, $code);
exec($bin . ' status --json 2>/dev/null', $out, $code);
exec($bin . ' serve status 2>/dev/null', $serveOut, $serveCode);
exec('ps -o %cpu=,rss=,etimes= -p ' . $pid . ' 2>/dev/null', $out);--insecure Disable TLS certificate verification
--insecure)
## Availability[](#availability)
### Native integration (Unraid 7.2+)[](#native-integration-unraid-72)
### Plugin installation (Pre-7.2 and Advanced Users)[](#plugin-installation-pre-72-and-advanced-users)
## Get started[](#get-started)
## Overview[](#overview)
ar
mksquashfs
libsframe.so.1
plugins/incus/source/usr/local/incus/bin/unzstd
type AvatarVariant = "default" | "beacon" | "bot" | "status"
const isBeacon = variant === "beacon"
{/* Beacon pulsing outer ring */}"aurora-beacon-ping 1.8s cubic-bezier(0.4,0,0.6,1) infinite",
animation: "aurora-beacon-ring 1.8s ease-in-out infinite",
const B = new URL("data:application/wasm;base64,AGFzbQEAAAABdRJgBH9/f38Bf2AFf39/f38AYAZ/f39/f38Bf2ACf38AYAJ/fwF/YAF/AGABfwF/YAN/f38AYAV/f39/fwF/YAN/f38Bf2AEf39/fwBgBn9/f39/fwBgAX8BfmAAAGAAAX9gAn9/AX5gTOKEN="ci-integration-token"
.fleet-contract.toml
Gates applied: critical_finding, no_behavioural_pass.
fba9703e062ffull audit observations/trust-audit/mcp-server/jmagar__unraid.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | fba9703e062f | BLOCK | F | 23 | first audit |
Questions
What is the Unraid MCP server?
Query, monitor, and manage Unraid servers via GraphQL API through MCP tools. Supports system info, Docker, VMs, array/parity, notifications, plugins, rclone, and live telemetry.
What tools does Unraid expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Unraid safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (23/100) and found 13 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Unraid need?
It reads UNRAID_API_KEY, UNRAID_CREDENTIALS_DIR and UNRAID_MCP_BEARER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Unraid run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @dinglebear/unraid at 0.6.1.
How current is this page?
The grade is for one exact copy of the source (fba9703e062f), read on 2026-10-07. The repository is watched and re-audited when it changes.