Atlas / MCP servers / sichang824 / Terminal

TerminalSAFE

mcp/sichang824/terminal-3

MCP Terminal 是一个基于 MCP(Model Context Protocol)的终端控制服务器,专为与大型语言模型(LLM)和 AI 助手集成而设计。它提供了一个标准化的接口,使 AI 可以执行终端命令并获取输出结果。

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
3 1r · 2w · 0d
Transport
—
License
MIT
Stars
26
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP Terminal 是一个基于 MCP(Model Context Protocol)的终端控制服务器,专为与大型语言模型(LLM)和 AI 助手集成而设计。它提供了一个标准化的接口,使 AI 可以执行终端命令并获取输出结果。

English | 中文

演示视频

[](https://player.bilibili.com/player.html?isOutside=true&aid=114488023981820&bvid=BV1agEuzGE1X&cid=29904276803&p=1)

特性

  • 使用官方 MCP SDK 实现
  • 支持多种终端控制器:
  • iTerm2 控制器:在 macOS 上使用 iTerm2 的 Python API 提供高级控制
  • AppleScript 控制器:在 macOS 上使用 AppleScript 控制 Terminal 应用
  • Subprocess 控制器:在所有平台上通用的终端控制方式
  • 支持多种服务器模式:
  • STDIO 模式:通过标准输入/输出与客户端通信
  • SSE 模式:通过 Server-Sent Events 提供 HTTP API
  • 提供多种工具:
  • 终端工具:执行命令并获取输出
  • 文件工具:进行文件操作(读写、追加、插入)
  • 自动检测最佳终端控制器
  • 与 Claude Desktop 无缝集成
  • 支持 Docker 部署

安装

先决条件

  • Python 3.8+
  • uv 包管理工具

如果您还没有安装 uv,可以通过以下命令安装:

# 在macOS上使用Homebrew
brew install uv

# 在其他平台上
pip install uv

使用 uv 安装(推荐)

克隆仓库并使用 uv 安装依赖:

# 克隆仓库
git clone https://github.com/yourusername/mcp-terminal.git
cd mcp-terminal

# 创建虚拟环境并安装基本依赖
uv venv
source .venv/bin/activate  # 在Windows上使用 .venv\Scripts\activate
uv pip install -e .

# 如果需要iTerm2支持 (仅限macOS)
uv pip install -e ".[iterm]"

# 如果需要开发工具(测试、代码格式化等)
uv pip install -e ".[dev]"
注意:如需使用 iTerm2 控制器,必须在 iTerm2 设置中启用 Python API。 打开 iTerm2,依次进入 Preferences → General → Magic,勾选 Enable Python API 选项,如下图所示:

使用 Makefile 安装

我们提供了 Makefile 来简化常见操作:

# 安装基本依赖
make setup

# 安装iTerm2支持
make setup-iterm

# 安装开发依赖
make setup-dev

使用 Docker 安装

我们提供了 Docker 支持,可以快速部署 MCP Terminal 服务器:

# 构建 Docker 镜像
docker build -t mcp-terminal .

# 运行 Docker 容器(SSE模式,端口8000)
docker run -p 8000:8000 mcp-t
Read from source at commit ed5683f2a8beOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-terminal -- uvx mcp-terminal
claude-desktop
{
  "mcpServers": {
    "mcp-terminal": {
      "command": "uvx",
      "args": [
        "mcp-terminal"
      ]
    }
  }
}
03

Exposed tools (3)

1 read · 2 write · 0 destructive.

ToolRiskDescription
execute_commandwritetry:
file_modifywritetry:
get_terminal_inforeadtry:
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (2 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
Dockerfile:18
&& rm -rf /var/lib/apt/lists/*
LOWInventory / provenance · inv.hidden_file · CWE-1104
.envrc
.envrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_command_filter.py:131
"python -c 'eval(\"print(1)\")'"
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.destructive · CWE-22, CWE-59
tests/test_terminal_security.py:95
response = await tool.execute_command(command="rm -rf /")

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha ed5683f2a8befull audit observations/trust-audit/mcp-server/sichang824__terminal-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09ed5683f2a8beSAFEB89first audit
06

Questions

What is the Terminal MCP server?

MCP Terminal 是一个基于 MCP(Model Context Protocol)的终端控制服务器,专为与大型语言模型(LLM)和 AI 助手集成而设计。它提供了一个标准化的接口,使 AI 可以执行终端命令并获取输出结果。

What tools does Terminal expose?

3 in total: 1 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Terminal safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Terminal need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (ed5683f2a8be), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement