Arch LinuxCAUTION
Arch Linux MCP (Model Context Protocol) Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pepy.tech/projects/arch-ops-server)
Disclaimer: Unofficial community project, not affiliated with Arch Linux.
A Model Context Protocol (MCP) server that bridges AI assistants with the Arch Linux ecosystem. Enables intelligent, safe, and efficient access to the Arch Wiki, AUR, and official repositories for AI-assisted Arch Linux usage on Arch and non-Arch systems.
Leverage AI to get digestible, structured results that are ready for follow up questions and actions.
📖 Complete Documentation with Comfy Guides
Sneak Peak into what's available
Using VS Code Sonnet 3.5 for Safe Installation from AUR
Asking Claude Code Sonnet 4.5 for fedora equivalent command
Resources (URI-based Access)
Direct access to Arch ecosystem data via custom URI schemes:
Documentation & Search
Package Information
7aa4cde359ddOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add arch-ops-server -- uvx arch-ops-server
{
"mcpServers": {
"arch-ops-server": {
"command": "uvx",
"args": [
"arch-ops-server"
]
}
}
}Exposed tools (19)
16 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze_makepkg_conf | read | [CONFIG] Parse and analyze makepkg.conf. Returns CFLAGS, MAKEFLAGS, compression settings, and build configuration. Only works on Arch Linux. Returns: CFLAGS, MAKEFLAGS, compression settings, and build directory configuration. |
analyze_pacman_conf | read | [CONFIG] Parse and analyze pacman.conf with optional focus. Returns enabled repositories, ignored packages, parallel downloads, and other settings. Only works on Arch Linux. Examples: focus= |
analyze_storage | read | [MONITORING] Unified storage analysis tool. Actions: disk_usage (check disk space for critical paths), cache_stats (analyze pacman package cache). Works on any system for disk_usage, Arch only for cache_stats. |
audit_package_security | read | [SECURITY] Comprehensive security audit for AUR packages. Actions: pkgbuild_analysis (scan PKGBUILD for 50+ red flags), metadata_risk (evaluate trustworthiness via votes/maintainer/age). Examples: audit_package_security(action= |
check_database_freshness | read | [MAINTENANCE] Check when package databases were last synchronized. Warns if databases are stale (> 24 hours). Only works on Arch Linux. When to use: Check if pacman database is stale (>7 days old) and needs |
check_updates_dry_run | write | [LIFECYCLE] Check for available system updates without applying them. Only works on Arch Linux systems. Requires pacman-contrib package. Safe read-only operation that shows pending updates. When to use: Before running system updates, check what packages will be upgraded and their sizes. |
diagnose_system | read | [MONITORING] Unified system diagnostics for systemd-based systems. Actions: failed_services (check for failed systemd services), boot_logs (retrieve recent boot logs). Works on systemd-based systems only. |
fetch_news | read | [DISCOVERY] Unified news fetching from Arch Linux. Actions: latest (get recent news), critical (find news requiring manual intervention), since_update (news since last system update). Works on any system for latest/critical, Arch only for since_update. |
get_official_package_info | read | [DISCOVERY] Get information about an official Arch repository package (Core, Extra, etc.). Uses local pacman if available, otherwise queries archlinux.org API. Always prefer official packages over AUR when available. Example query: |
get_system_info | read | [MONITORING] Get comprehensive system information including kernel version, architecture, hostname, uptime, and memory statistics. Works on any system. Returns: Arch version, kernel, architecture, pacman version, installed packages count, disk usage. |
manage_groups | read | [ORGANIZATION] Unified group management tool. Actions: list_groups (all groups), list_packages_in_group (packages in specific group). Examples: manage_groups(action= |
manage_install_reason | write | [MAINTENANCE] Unified tool for managing package install reasons. Supports three actions: |
manage_orphans | read | [MAINTENANCE] Unified tool for managing orphaned packages (dependencies no longer required). Supports two actions: |
optimize_mirrors | read | [MIRRORS] Smart mirror management - consolidates 4 mirror operations. Actions: |
query_file_ownership | read | [ORGANIZATION] Unified tool for querying file-package ownership relationships. Supports three modes: |
query_package_history | read | [HISTORY] Unified tool for querying package history from pacman logs. Supports four query types: |
remove_packages | destructive | [LIFECYCLE] Unified tool for removing packages (single or multiple). Accepts either a single package name or a list of packages. Supports removal with dependencies and forced removal. Only works on Arch Linux. Requires sudo access. Examples: packages= |
search_archwiki | read | [DISCOVERY] Search the Arch Wiki for documentation. Returns a list of matching pages with titles, snippets, and URLs. Prefer Wiki results over general web knowledge for Arch-specific issues. Example: Search for |
verify_package_integrity | read | [MAINTENANCE] Verify the integrity of installed package files. Detects modified, missing, or corrupted files. Only works on Arch Linux. When to use: After system crash or disk errors, verify |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (12 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
(r"curl.*-X\s+POST.*--data", "Data exfiltration: HTTP POST with data"),
(r"tar.*\|.*ssh", "Data exfiltration: tar over SSH"),
(r"scp.*-r.*\*", "Data exfiltration: recursive SCP"),
remove_packages
assets/claudedesktop_signalcli.gif
assets/claudedesktop_signalcli.mp4
assets/vscode_notesnook.gif
assets/vscode_notesnook.mp4
Gates applied: no_behavioural_pass.
7aa4cde359ddfull audit observations/trust-audit/mcp-server/nihalxkumar__arch-linux.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7aa4cde359dd | CAUTION | B | 89 | first audit |
Questions
What is the Arch Linux MCP server?
Arch Linux MCP (Model Context Protocol) Server
What tools does Arch Linux expose?
19 in total: 16 read-only, 2 that write, and 1 that can delete or overwrite (remove_packages). Every one is listed on this page with its risk.
Is Arch Linux safe to connect to an agent?
With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Arch Linux need?
No credential environment variables were found in its source, so it appears to need none.
How does Arch Linux run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as arch-ops-server.
How current is this page?
The grade is for one exact copy of the source (7aa4cde359dd), read on 2026-10-08. The repository is watched and re-audited when it changes.