zspace-cliCAUTION
Agent Skill + zero-config CLI/SDK/MCP for ZSpace (极空间) NAS — no password, no SSH
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English · 简体中文
[](https://pypi.org/project/zspace-cli/) [](https://pypi.org/project/zspace-cli/) [](https://github.com/skyzhao1223/zspace-cli/actions/workflows/ci.yml) [](https://glama.ai/mcp/servers/skyzhao1223/zspace-cli)
Manage your 极空间 (ZSpace) NAS from the terminal or AI agents — no password, no SSH, no DDNS.
mcp-name: io.github.skyzhao1223/zspace-cli
Just keep the ZSpace desktop client logged in on macOS. 📖 How large-file sliced upload was born: 一次 1.4GB 备份引发的逆向 (zh, CSDN) · CLI guide: 极空间 NAS 命令行管理指南 (zh, CSDN)
**Beginner guide** (no coding required) · Skills — incl. 9 cross-NAS organizer skills for AI agents · 中文文档
Install
pip install zspace-cli # base pip install "zspace-cli[mcp]" # optional MCP support zs check # ✓ reads the desktop client login state
Prerequisite: the ZSpace desktop client is running and logged in on macOS.
Quick start
zs ls /sata11/my/data/影视 zs find "权力的游戏" # ful
110e933a5a68OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add zspace-cli -- None zspace-cli==0.1.10
Exposed tools (5)
4 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
zspace_check | read | Check whether the ZSpace NAS is reachable through the local desktop |
zspace_disk_stats | read | Return raw disk statistics reported by the ZSpace NAS. |
zspace_info | read | Return detailed metadata for one file or directory on the ZSpace NAS. |
zspace_pool_info | read | List every storage pool on the ZSpace NAS with its name and capacity. |
zspace_remove | destructive | Permanently delete one or more files/directories from the ZSpace NAS. |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (12)
# - Linux: either use `network_mode: host` (and ZS_BASE_URL=http://127.0.0.1:13579)
zspace_remove
.gitmodules
h = hashlib.sha1()
h = hashlib.sha1()
digest = hashlib.md5()
return hashlib.md5(f"{mtime_ms + size}{target}".encode()).hexdigest()h = hashlib.sha1()
-e ZS_BASE_URL=http://127.0.0.1:13579 \
-e ZS_BASE_URL=http://127.0.0.1:13579 \
PR. The web-client source is reachable: `http://127.0.0.1:13579/home/` serves
-e ZS_BASE_URL=http://127.0.0.1:13579 \
Gates applied: no_behavioural_pass.
110e933a5a68full audit observations/trust-audit/mcp-server/skyzhao1223__zspace-cli.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 110e933a5a68 | CAUTION | B | 87 | first audit |
Questions
What is the zspace-cli MCP server?
Agent Skill + zero-config CLI/SDK/MCP for ZSpace (极空间) NAS — no password, no SSH
What tools does zspace-cli expose?
5 in total: 4 read-only, 0 that write, and 1 that can delete or overwrite (zspace_remove). Every one is listed on this page with its risk.
Is zspace-cli safe to connect to an agent?
With care. The audit graded it B (87/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does zspace-cli need?
No credential environment variables were found in its source, so it appears to need none.
How does zspace-cli run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as zspace-cli.
How current is this page?
The grade is for one exact copy of the source (110e933a5a68), read on 2026-10-08. The repository is watched and re-audited when it changes.