RustunnelBLOCK
Self-hosted, secure tunnel server in Rust. Expose local HTTP/HTTPS/TCP/UDP services to the public internet via TLS-encrypted WebSocket. Open-source, pay-as-you-go managed option, MCP server for AI agents.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/joaoh82/rustunnel/actions/workflows/ci.yml) [](LICENSE) [](https://www.rust-lang.org) [](https://skillselion.com/mcp/tool/io.github.joaoh82/rustunnel)
The open-source tunnel that scales with you. Don't pay for idle time. Secure, Rust-fast, and Pay-as-you-go.
Expose local services through a public server over encrypted WebSocket connections with TLS termination, HTTP/TCP proxying, a live dashboard, Prometheus metrics, and audit logging.
You can self-host or use our managed service.
Using an AI agent? rustunnel ships an MCP server — one-click setup for Cursor (then add your API token):
[](https://cursor.com/install-mcp?name=rustunnel&config=eyJjb21tYW5kIjoicnVzdHVubmVsLW1jcCIsImFyZ3MiOlsiLS1zZXJ2ZXIiLCJldS5lZGdlLnJ1c3R1bm5lbC5jb206NDA0MCIsIi0tYXBpIiwiaHR0cHM6Ly9ldS5lZGdlLnJ1c3R1bm5lbC5jb206ODQ0MyJdLCJlbnYiOnsiUlVTVFVOTkVMX1RPS0VOIjoiWU9VUl9UT0tFTiJ9fQ==)
For Claude Code, Claude Desktop, Windsurf, and others, see the agent integration guide or the agent manual at rustunnel.com/agents.md.
Table of Contents
- Hosted service
- Architecture overview
- Requirements
- Local development setup
- Build
- Run tests
- Run the server locally
- Run the client locally
- [Git ho
94748dc82682OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add rustunnel-dashboard --env RUSTUNNEL_TOKEN=${RUSTUNNEL_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"rustunnel-dashboard": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"RUSTUNNEL_TOKEN": "${RUSTUNNEL_TOKEN}"
}
}
}
}Trust audit
BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (18 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
!function(){var t="undefined"!=typeof globalThis?globalThis:"undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self?self:{};function e(t){var e={exports:{}};returna.push("--insecure".into());a.push("--insecure".into());assert!(a.contains(&"--insecure".to_string()));
--insecure) INSECURE=1; shift ;;
ARGS_JSON="$ARGS_JSON, \"--insecure\""
TEST_DATABASE_URL=postgres://rustunnel:test@localhost:5432/rustunnel_test cargo test --workspace
@echo " export TEST_DATABASE_URL=postgres://rustunnel:test@localhost:5432/rustunnel_test"
return Some((listener, format!("http://127.0.0.1:{port}")));Ok(listener) => return Some((listener, format!("http://127.0.0.1:{port}"))),assert!(url.starts_with("http://127.0.0.1:"));url: "http://127.0.0.1:4040".into(),
r#"{"event":"inspector_ready","url":"http://127.0.0.1:4040"}"#TEST_DATABASE_URL: postgres://rustunnel:test@localhost:5432/rustunnel_test
TEST_DATABASE_URL=postgres://rustunnel:test@localhost:5432/rustunnel_test cargo test --workspace
TEST_DATABASE_URL=postgres://rustunnel:test@localhost:5432/rustunnel_test \
curl -fsSL https://raw.githubusercontent.com/joaoh82/rustunnel/main/integrations/install.sh | bash
curl -fsSL https://raw.githubusercontent.com/joaoh82/rustunnel/main/integrations/install.sh | bash
[](https://cursor.com/install-mcp?name=rustunnel&config=eyJjb21tYW5kIjoicnVzdHVubmVsLW1jcCIsImFyZ3MiOlsiLS1zZXJ2ZXIiLCJldS5lZGdlLnJ1c3
next, react, react-dom, @types/node, @types/react, @types/react-dom, typescript
| Admin token | Value of `auth.admin_token` in `server.toml` | Full access — sees every tunnel and group across every tenant |
The skill instructs the agent to read credentials from `~/.rustunnel/config.yml`
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
curl -fsSL https://raw.githubusercontent.com/joaoh82/rustunnel/main/integrations/install.sh | bash
curl -s -X POST https://your-server:8443/api/tokens \
Gates applied: no_behavioural_pass.
94748dc82682full audit observations/trust-audit/mcp-server/joaoh82__rustunnel.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 94748dc82682 | BLOCK | F | 47 | first audit |
Questions
What is the Rustunnel MCP server?
Self-hosted, secure tunnel server in Rust. Expose local HTTP/HTTPS/TCP/UDP services to the public internet via TLS-encrypted WebSocket. Open-source, pay-as-you-go managed option, MCP server for AI agents.
Is Rustunnel safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (47/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Rustunnel need?
It reads RUSTUNNEL_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Rustunnel run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as rustunnel-dashboard at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (94748dc82682), read on 2026-09-28. The repository is watched and re-audited when it changes.