Atlas / MCP servers / nihalxkumar / Arch Linux

Arch LinuxCAUTION

mcp/nihalxkumar/arch-linux

Arch Linux MCP (Model Context Protocol) Server

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
19 16r · 2w · 1d
Transport
stdio
License
GPL-3.0
Stars
58
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pepy.tech/projects/arch-ops-server)

Disclaimer: Unofficial community project, not affiliated with Arch Linux.

A Model Context Protocol (MCP) server that bridges AI assistants with the Arch Linux ecosystem. Enables intelligent, safe, and efficient access to the Arch Wiki, AUR, and official repositories for AI-assisted Arch Linux usage on Arch and non-Arch systems.

Leverage AI to get digestible, structured results that are ready for follow up questions and actions.

📖 Complete Documentation with Comfy Guides

Sneak Peak into what's available

Using VS Code Sonnet 3.5 for Safe Installation from AUR

Asking Claude Code Sonnet 4.5 for fedora equivalent command

Resources (URI-based Access)

Direct access to Arch ecosystem data via custom URI schemes:

Documentation & Search

Package Information

Read from source at commit 7aa4cde359ddOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add arch-ops-server -- uvx arch-ops-server
claude-desktop
{
  "mcpServers": {
    "arch-ops-server": {
      "command": "uvx",
      "args": [
        "arch-ops-server"
      ]
    }
  }
}
03

Exposed tools (19)

16 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_makepkg_confread[CONFIG] Parse and analyze makepkg.conf. Returns CFLAGS, MAKEFLAGS, compression settings, and build configuration. Only works on Arch Linux. Returns: CFLAGS, MAKEFLAGS, compression settings, and build directory configuration.
analyze_pacman_confread[CONFIG] Parse and analyze pacman.conf with optional focus. Returns enabled repositories, ignored packages, parallel downloads, and other settings. Only works on Arch Linux. Examples: focus=
analyze_storageread[MONITORING] Unified storage analysis tool. Actions: disk_usage (check disk space for critical paths), cache_stats (analyze pacman package cache). Works on any system for disk_usage, Arch only for cache_stats.
audit_package_securityread[SECURITY] Comprehensive security audit for AUR packages. Actions: pkgbuild_analysis (scan PKGBUILD for 50+ red flags), metadata_risk (evaluate trustworthiness via votes/maintainer/age). Examples: audit_package_security(action=
check_database_freshnessread[MAINTENANCE] Check when package databases were last synchronized. Warns if databases are stale (> 24 hours). Only works on Arch Linux. When to use: Check if pacman database is stale (>7 days old) and needs
check_updates_dry_runwrite[LIFECYCLE] Check for available system updates without applying them. Only works on Arch Linux systems. Requires pacman-contrib package. Safe read-only operation that shows pending updates. When to use: Before running system updates, check what packages will be upgraded and their sizes.
diagnose_systemread[MONITORING] Unified system diagnostics for systemd-based systems. Actions: failed_services (check for failed systemd services), boot_logs (retrieve recent boot logs). Works on systemd-based systems only.
fetch_newsread[DISCOVERY] Unified news fetching from Arch Linux. Actions: latest (get recent news), critical (find news requiring manual intervention), since_update (news since last system update). Works on any system for latest/critical, Arch only for since_update.
get_official_package_inforead[DISCOVERY] Get information about an official Arch repository package (Core, Extra, etc.). Uses local pacman if available, otherwise queries archlinux.org API. Always prefer official packages over AUR when available. Example query:
get_system_inforead[MONITORING] Get comprehensive system information including kernel version, architecture, hostname, uptime, and memory statistics. Works on any system. Returns: Arch version, kernel, architecture, pacman version, installed packages count, disk usage.
manage_groupsread[ORGANIZATION] Unified group management tool. Actions: list_groups (all groups), list_packages_in_group (packages in specific group). Examples: manage_groups(action=
manage_install_reasonwrite[MAINTENANCE] Unified tool for managing package install reasons. Supports three actions:
manage_orphansread[MAINTENANCE] Unified tool for managing orphaned packages (dependencies no longer required). Supports two actions:
optimize_mirrorsread[MIRRORS] Smart mirror management - consolidates 4 mirror operations. Actions:
query_file_ownershipread[ORGANIZATION] Unified tool for querying file-package ownership relationships. Supports three modes:
query_package_historyread[HISTORY] Unified tool for querying package history from pacman logs. Supports four query types:
remove_packagesdestructive[LIFECYCLE] Unified tool for removing packages (single or multiple). Accepts either a single package name or a list of packages. Supports removal with dependencies and forced removal. Only works on Arch Linux. Requires sudo access. Examples: packages=
search_archwikiread[DISCOVERY] Search the Arch Wiki for documentation. Returns a list of matching pages with titles, snippets, and URLs. Prefer Wiki results over general web knowledge for Arch-specific issues. Example: Search for
verify_package_integrityread[MAINTENANCE] Verify the integrity of installed package files. Detects modified, missing, or corrupted files. Only works on Arch Linux. When to use: After system crash or disk errors, verify
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (12 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (8)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/arch_ops_server/aur.py:1020
(r"curl.*-X\s+POST.*--data", "Data exfiltration: HTTP POST with data"),
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/arch_ops_server/aur.py:1021
(r"tar.*\|.*ssh", "Data exfiltration: tar over SSH"),
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/arch_ops_server/aur.py:1022
(r"scp.*-r.*\*", "Data exfiltration: recursive SCP"),
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
remove_packages
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
INFOInventory / provenance · inv.oversize · CWE-1104
assets/claudedesktop_signalcli.gif
assets/claudedesktop_signalcli.gif
Why it matters. 11348691 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/claudedesktop_signalcli.mp4
assets/claudedesktop_signalcli.mp4
Why it matters. 41462475 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/vscode_notesnook.gif
assets/vscode_notesnook.gif
Why it matters. 16828460 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/vscode_notesnook.mp4
assets/vscode_notesnook.mp4
Why it matters. 7072299 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7aa4cde359ddfull audit observations/trust-audit/mcp-server/nihalxkumar__arch-linux.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087aa4cde359ddCAUTIONB89first audit
06

Questions

What is the Arch Linux MCP server?

Arch Linux MCP (Model Context Protocol) Server

What tools does Arch Linux expose?

19 in total: 16 read-only, 2 that write, and 1 that can delete or overwrite (remove_packages). Every one is listed on this page with its risk.

Is Arch Linux safe to connect to an agent?

With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Arch Linux need?

No credential environment variables were found in its source, so it appears to need none.

How does Arch Linux run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as arch-ops-server.

How current is this page?

The grade is for one exact copy of the source (7aa4cde359dd), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement