Atlas / MCP servers / weidwonder / Terminal

TerminalBLOCK

mcp/weidwonder/terminal-2

Make LLM can control your PC or Server with ssh or terminal.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 0r · 1w · 0d
Transport
stdio
License
—
Stars
28
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@weidwonder/terminal-mcp-server)

Notice 注意事项

Current Project not in maintance anymore. I recommend you guys to use more advanced command tool —— Desktop Commander 当前项目已经不在维护。我建议大家用更先进的终端MCP工具 Desktop Commander

中文文档

Terminal MCP Server is a Model Context Protocol (MCP) server that allows executing commands on local or remote hosts. It provides a simple yet powerful interface for AI models and other applications to execute system commands, either on the local machine or on remote hosts via SSH.

Features

  • Local Command Execution: Execute commands directly on the local machine
  • Remote Command Execution: Execute commands on remote hosts via SSH
  • Session Persistence: Support for persistent sessions that reuse the same terminal environment for a specified time (default 20 minutes)
  • Environment Variables: Set custom environment variables for commands
  • Multiple Connection Methods: Connect via stdio or SSE (Server-Sent Events)

Installation

Installing via Smithery

To install terminal-mcp-server for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @weidwonder/terminal-mcp-server --client claude

Manual Installation

# Clone the repository
git clone https://github.com/weidwonder/terminal-mcp-server.git
cd terminal-mcp-server

# Install dependencies
npm install

# Build the project
npm run build

Usage

Starting the Server

# Start the server using stdio (default mode)
npm start

# Or run the built file directly
node build/index.js

Starting the Server in SSE Mode

The SSE (Server-Sent Events) mode allows you to connect to the server remotely via HTTP.

# Start the server in SSE mod
Read from source at commit d19dd324e536OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add terminal-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "terminal-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
execute_commandwriteExecute commands on remote hosts or locally (This tool can be used for both remote hosts and the current machine)
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/executor.ts:347
exec(command, { env: envVars }, (error, stdout, stderr) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/executor.ts:44
const privateKey = fs.readFileSync(path.join(os.homedir(), '.ssh', 'id_rsa'));
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ssh.ts:21
const privateKey = fs.readFileSync(path.join(os.homedir(), '.ssh', 'id_rsa'));
Why it matters. touches a credential store
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:83
This will start the server and listen for SSE connections at `http://0.0.0.0:3000/mcp`.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_CN.md:66
这将启动服务器并在 `http://0.0.0.0:3000/mcp` 监听 SSE 连接。
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, ssh2, @types/node, @types/ssh2, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha d19dd324e536full audit observations/trust-audit/mcp-server/weidwonder__terminal-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d19dd324e536BLOCKD69first audit
06

Questions

What is the Terminal MCP server?

Make LLM can control your PC or Server with ssh or terminal.

What tools does Terminal expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Terminal safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Terminal need?

No credential environment variables were found in its source, so it appears to need none.

How does Terminal run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as terminal-mcp-server at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (d19dd324e536), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement