Atlas / MCP servers / jmagar / Unraid

UnraidBLOCK

mcp/jmagar/unraid

Query, monitor, and manage Unraid servers via GraphQL API through MCP tools. Supports system info, Docker, VMs, array/parity, notifications, plugins, rclone, and live telemetry.

Verdict
BLOCK
Grade
F
Trust score
23 /100
Exposed tools
5 5r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
135
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/unraid-mcp/) [](https://github.com/dinglebear-ai/unraid/pkgs/container/unraid-mcp)

A monorepo of Unraid tooling: two MCP servers (Python and Rust) and three Unraid OS plugins, plus the Claude/Codex agent integrations that surface them.

Repo name. This repo was renamed unraid-mcp → unraid on 2026-07-27, and the former standalone runraid and incus-unraid repos were merged in here. Some deployed plugin install/update URLs still depend on the old-name redirect; migrating those runtime URLs requires a deliberate release. The PyPI package, the container image, the Claude plugin, and the Unraid `.plg` are all still named unraid-mcp — only the repo changed.

Components

Read from source at commit fba9703e062fOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add unraid-mcp --env UNRAID_API_KEY=${UNRAID_API_KEY} -- uvx unraid-mcp==2.10.2
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
CommandsreadCommand execution requires approval when Codex requests it.
JailActionreadJail lifecycle actions
PackageEcosystemreadPackage catalog to search — apt is Debian/Ubuntu only
UnraidreadUnraid control surface
http-toolkitreadincludes curl support
04

Trust audit

BLOCKgrade F · trust 23/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (12 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
unraid-rs/crates/lab-auth/src/authorize.rs:1415
const TEST_RSA_KEY_PEM: &str = r"-----BEGIN PRIVATE KEY-----
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
plugins/mcp/source/usr/local/emhttp/plugins/unraid-mcp/include/config.php:176
exec($command . ' 2>&1', $out, $code);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
plugins/mcp/source/usr/local/emhttp/plugins/unraid-mcp/include/config.php:431
exec(RC . ' status 2>/dev/null', $out, $code);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
plugins/mcp/source/usr/local/emhttp/plugins/unraid-mcp/include/config.php:441
exec($bin . ' status --json 2>/dev/null', $out, $code);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
plugins/mcp/source/usr/local/emhttp/plugins/unraid-mcp/include/config.php:449
exec($bin . ' serve status 2>/dev/null', $serveOut, $serveCode);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
plugins/mcp/source/usr/local/emhttp/plugins/unraid-mcp/include/config.php:465
exec('ps -o %cpu=,rss=,etimes= -p ' . $pid . ' 2>/dev/null', $out);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
agents/unraid-py/skills/unraid/scripts/unraid-query.sh:29
--insecure             Disable TLS certificate verification
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
agents/unraid-py/skills/unraid/scripts/unraid-query.sh:82
--insecure)
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
plugins/incus/docs/unraid/API.md:6
## Availability[](#availability)
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
plugins/incus/docs/unraid/API.md:7
### Native integration (Unraid 7.2+)[](#native-integration-unraid-72)
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
plugins/incus/docs/unraid/API.md:13
### Plugin installation (Pre-7.2 and Advanced Users)[](#plugin-installation-pre-72-and-advanced-users)
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
plugins/incus/docs/unraid/API.md:19
## Get started[](#get-started)
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
plugins/incus/docs/unraid/API/api-key-app-developer-authorization-flow.md:5
## Overview[](#overview)
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.binary · CWE-1104
plugins/incus/source/usr/local/incus/bin/ar
ar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
plugins/incus/source/usr/local/incus/bin/mksquashfs
mksquashfs
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
plugins/incus/source/usr/local/incus/lib/libsframe.so.1
libsframe.so.1
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugins/incus/source/usr/local/incus/bin/unzstd
plugins/incus/source/usr/local/incus/bin/unzstd
Why it matters. link not followed
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
plugins/codex/web-src/src/components/ui/aurora/avatar.tsx:15
type AvatarVariant = "default" | "beacon" | "bot" | "status"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
plugins/codex/web-src/src/components/ui/aurora/avatar.tsx:95
const isBeacon = variant === "beacon"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
plugins/codex/web-src/src/components/ui/aurora/avatar.tsx:149
{/* Beacon pulsing outer ring */}
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
plugins/codex/web-src/src/components/ui/aurora/avatar.tsx:160
"aurora-beacon-ping 1.8s cubic-bezier(0.4,0,0.6,1) infinite",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
plugins/codex/web-src/src/components/ui/aurora/avatar.tsx:172
animation: "aurora-beacon-ring 1.8s ease-in-out infinite",
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
plugins/incus/source/usr/local/emhttp/plugins/incus/web/incus-settings-Terminal-DDk6hy6k.js:18
const B = new URL("data:application/wasm;base64,AGFzbQEAAAABdRJgBH9/f38Bf2AFf39/f38AYAZ/f39/f38Bf2ACf38AYAJ/fwF/YAF/AGABfwF/YAN/f38AYAV/f39/fwF/YAN/f38Bf2AEf39/fwBgBn9/f39/fwBgAX8BfmAAAGAAAX9gAn9/AX5g
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
unraid-py/tests/test_live.sh:610
TOKEN="ci-integration-token"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.fleet-contract.toml
.fleet-contract.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fba9703e062ffull audit observations/trust-audit/mcp-server/jmagar__unraid.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fba9703e062fBLOCKF23first audit
06

Questions

What is the Unraid MCP server?

Query, monitor, and manage Unraid servers via GraphQL API through MCP tools. Supports system info, Docker, VMs, array/parity, notifications, plugins, rclone, and live telemetry.

What tools does Unraid expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Unraid safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (23/100) and found 13 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Unraid need?

It reads UNRAID_API_KEY, UNRAID_CREDENTIALS_DIR and UNRAID_MCP_BEARER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Unraid run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @dinglebear/unraid at 0.6.1.

How current is this page?

The grade is for one exact copy of the source (fba9703e062f), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement