Registry/Shell MCP (Dangerous)

Shell MCP (Dangerous)

v1.0.1
Verified

Direct shell command execution. DANGEROUS: No input sanitization, allows arbitrary command execution.

By CommunityISC
typescript
developer tools
340stars
8.5Kdownloads
45forks
Scanned Jun 27, 2026
NPM
C50%
Scanned 2h ago

Fair Security

Vulnerabilities Found
2Crit
0High
0Med
0Low
0Info

Security ScoreC

50
out of 100

Vulnerabilities Found

2
Crit
0
High
0
Medi
0
Low
0
Info
Last scanned: 6/27/2026

Quality ScoreF

25
out of 100
25
Maint.
23
Popular
25
Docs
28
Compat
Maintenance25%
Popularity23%
Documentation25%
Compatibility28%

Maintenance25

Active
3 days ago
Commit Frequency22%
Release Frequency25%
Issue Response25%

Popularity23

340
Stars
8.5K
Downloads
45
Forks
Stars Score51%
Downloads Score54%
Forks Score52%

Documentation25

README Quality78%

Available Documentation

API DocsExamplesChangelog

Compatibility28

MCP Spec Compliance30%
Transport Support50%

Features

TypeScript

Supported Transports

STDIO

Vulnerabilities(2)

2Critical
Filter:

READMEShell MCP (Dangerous)

Shell MCP

EXTREMELY DANGEROUS - USE WITH CAUTION

Warning

This MCP server allows direct shell command execution with NO sanitization.

Risks

  • Full system access
  • Data destruction
  • Malware installation
  • Privilege escalation

Use Case

Only for isolated development environments with no network access.

Recommendation

Use sandboxed alternatives like Docker-based execution environments.

Embed Security Badge

Add this badge to your README or documentation

Shell MCP (Dangerous) MCPSafe Security
[![Shell MCP (Dangerous) MCPSafe Security](https://api.mcpsafe.org
/api/badge/shell-mcp-dangerous.svg)](https://mcpsafe.org/registry/shell-mcp-dangerous)
Need more customization options?Badge Documentation

Server Information

Source
NPM
Package
shell-mcp
Version
1.0.1
Language
typescript
License
ISC
Transport
STDIO
Added
Jan 20, 2026
Updated
Jun 27, 2026