Shell Executor is an MCP server that provides controlled command-line execution capabilities to Model Context Protocol clients like VS Code Copilot and other AI agents. It connects development environments directly to system command utilities while enforcing safety constraints to prevent destructive behavior. Developers and automated coding assistants use it to inspect files, query version control, build code, and inspect operating system state. By using an explicit whitelist of supported commands, Shell Executor restricts agent operations to standard non-destructive tools across filesystem navigation, text transformation, and runtime environments. It enables automated agents to execute commands such as git, python, cargo, grep, and curl without exposing underlying systems to dangerous commands such as rm, mv, or privilege escalation binaries like sudo. The server operates over standard I/O via a JSON-RPC interface and limits execution times with built-in timeouts, making it suitable for sandboxed agent tasks and development workflows.
Category: Cloud & Infrastructure
Tags: bash, cli, linux, remote-execution, shell
Follow these steps to install and configure Shell Executor: 1. Clone the repository and install the dependencies locally: bash git clone https://github.com/yourusername/shell-executor-mcp.git cd shell-executor-mcp pip install -e . Or install via PyPI once published: pip install shell-executor-mcp. 2. Add the server configuration to your VS Code settings.json or .vscode/mcp_servers.json: json { "mcpServers": { "shell-executor": { "command": "python", "args": ["/path/to/shell-executor-mcp/src/mcp_server.py"], "env": { "MCP_API_TOKEN": "your-secret-token" } } } } 3. Restart your MCP client to enable the execute_command tool.
Part of MCP Servers
Shell Executor allows AI agents to run whitelisted shell commands over an MCP interface. It supports file navigation tools, text filters, archive tools, network utilities like curl, and build tools like git, cargo, and python, while enforcing strict execution timeouts.
The server applies a strict command whitelist and rejects harmful operations. Commands for file deletion or moving, such as rm and mv, are barred. Privilege escalation through sudo or su is blocked, and executions are limited by a 30-second timeout.
Shell Executor works with any client supporting the standard Model Context Protocol over stdio. It includes explicit configuration support for VS Code Copilot and workspace settings files, as well as general JSON-RPC testing interfaces.
Yes, Shell Executor is open source software distributed under the terms of the MIT License. The code and configuration files are available for inspection and modification on GitHub.