Atlas / MCP servers / pazuzu1w / Ubuntu System Controller

Ubuntu System ControllerSAFE

mcp/pazuzu1w/ubuntu-system-controller

an mcp server built to give claude config limited control over ubuntu os operations

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
7 4r · 3w · 0d
Transport
—
License
MIT
Stars
42
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🔒 Security-First Model Context Protocol server for safe Ubuntu system operations

A hardened, production-ready Model Context Protocol (MCP) server that provides AI assistants with secure, controlled access to Ubuntu system operations. Built with comprehensive security controls, audit logging, and defense-in-depth principles.

[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](#security-features) [](https://modelcontextprotocol.io/)

✨ Key Features

🛡️ Security-First Architecture

  • Path traversal protection - Symlink resolution with allowlist/denylist controls
  • Command sanitization - Shell injection prevention with safe argument parsing
  • Resource limits - File size, execution timeouts, and output size controls
  • Comprehensive audit logging - All operations logged with user attribution
  • Defense in depth - Multiple security layers with fail-safe defaults

🎯 Core Capabilities

  • File Operations - Read, write, and list directories with permission validation
  • Command Execution - Safe shell command execution with whitelist/blacklist filtering
  • System Information - OS details, memory, and disk usage monitoring
  • Package Management - APT package search and listing (installation requires explicit config)

🏗️ Production Ready

  • Modular design with clear separation of concerns
  • Comprehensive error handling with meaningful error messages
  • Extensive test suite including security validation tests
  • Configurable policies for different use cases and environments
  • Zero-dependency security - Core security doesn't rely on external p
Read from source at commit 38234cf194aaOBSERVED · 2026-10-08
02

Exposed tools (7)

4 read · 3 write · 0 destructive.

ToolRiskDescription
execute_commandwriteExecutes a shell command on the Ubuntu system.
get_system_inforeadGets basic system information.
install_packagewrite
list_directoryreadLists the contents of a directory.
read_filereadReads the contents of a file.
search_packagesread
write_filewriteWrites content to a file, creating backups of existing files.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
main.py:875
await run_test("Path Traversal", controller.read_file, "/tmp/../../etc/passwd")
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, psutil
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 38234cf194aafull audit observations/trust-audit/mcp-server/pazuzu1w__ubuntu-system-controller.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0838234cf194aaSAFEB89first audit
05

Questions

What is the Ubuntu System Controller MCP server?

an mcp server built to give claude config limited control over ubuntu os operations

What tools does Ubuntu System Controller expose?

7 in total: 4 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Ubuntu System Controller safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Ubuntu System Controller need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (38234cf194aa), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement