TerminalBLOCK
Make LLM can control your PC or Server with ssh or terminal.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@weidwonder/terminal-mcp-server)
Notice 注意事项
Current Project not in maintance anymore. I recommend you guys to use more advanced command tool —— Desktop Commander 当前项目已经不在维护。我建议大家用更先进的终端MCP工具 Desktop Commander
中文文档
Terminal MCP Server is a Model Context Protocol (MCP) server that allows executing commands on local or remote hosts. It provides a simple yet powerful interface for AI models and other applications to execute system commands, either on the local machine or on remote hosts via SSH.
Features
- Local Command Execution: Execute commands directly on the local machine
- Remote Command Execution: Execute commands on remote hosts via SSH
- Session Persistence: Support for persistent sessions that reuse the same terminal environment for a specified time (default 20 minutes)
- Environment Variables: Set custom environment variables for commands
- Multiple Connection Methods: Connect via stdio or SSE (Server-Sent Events)
Installation
Installing via Smithery
To install terminal-mcp-server for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install @weidwonder/terminal-mcp-server --client claude
Manual Installation
# Clone the repository git clone https://github.com/weidwonder/terminal-mcp-server.git cd terminal-mcp-server # Install dependencies npm install # Build the project npm run build
Usage
Starting the Server
# Start the server using stdio (default mode) npm start # Or run the built file directly node build/index.js
Starting the Server in SSE Mode
The SSE (Server-Sent Events) mode allows you to connect to the server remotely via HTTP.
# Start the server in SSE mod
d19dd324e536OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add terminal-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"terminal-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
execute_command | write | Execute commands on remote hosts or locally (This tool can be used for both remote hosts and the current machine) |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
exec(command, { env: envVars }, (error, stdout, stderr) => {const privateKey = fs.readFileSync(path.join(os.homedir(), '.ssh', 'id_rsa'));
const privateKey = fs.readFileSync(path.join(os.homedir(), '.ssh', 'id_rsa'));
This will start the server and listen for SSE connections at `http://0.0.0.0:3000/mcp`.
这将启动服务器并在 `http://0.0.0.0:3000/mcp` 监听 SSE 连接。
@modelcontextprotocol/sdk, ssh2, @types/node, @types/ssh2, typescript
Gates applied: no_behavioural_pass, no_license.
d19dd324e536full audit observations/trust-audit/mcp-server/weidwonder__terminal-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d19dd324e536 | BLOCK | D | 69 | first audit |
Questions
What is the Terminal MCP server?
Make LLM can control your PC or Server with ssh or terminal.
What tools does Terminal expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Terminal safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Terminal need?
No credential environment variables were found in its source, so it appears to need none.
How does Terminal run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as terminal-mcp-server at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (d19dd324e536), read on 2026-10-08. The repository is watched and re-audited when it changes.