$npx skillfedfor your agent

cli-mcp-server

Command line interface for MCP clients with secure execution and customizable security policies

With conditionsPyPI UtilitiesReleased Jul 202582.1K downloads / moPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — cli_mcp_server-0.2.5-py3-none-any.whl
v0.2.5 · released 2025-07-04 · Python >=3.10 · 1 runtime deps: mcp

Yes, with conditions. Install if you need to safely expose CLI access to an LLM application and are comfortable configuring environment variables and managing a whitelist. The low install friction and clear security model make it straightforward to set up. However, verify the actual license in the repository first (metadata is unclear), and be aware that maintenance is aging—last release was 406 days ago. No known vulnerabilities are recorded, but the security features (injection protection, path validation) should be reviewed for your threat model before use in production.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Requires mcp runtime dependency.
  • Must set ALLOWED_DIR environment variable before the server will start.

License · maintenance · safety

(unclear) — License treatment is unclear: no SPDX identifier or raw license string is recorded in the package metadata, despite the description mentioning MIT licensing. Verify the actual license terms in the repository before use in proprietary or restricted contexts.

last release 2025-07-04 (406 days) · last repo commit 2025-07-04 · 177 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 82,121 downloads/mo, #14,182 on PyPI

Verify before relying

pip install cli-mcp-server

# Add to Claude Desktop config (~/Library/Application\ Support/Claude/claude_desktop_config.json):
# {
#   "mcpServers": {
#     "cli-mcp-server": {
#       "command": "uvx",
#       "args": ["cli-mcp-server"],
#       "env": {
#         "ALLOWED_DIR": "/your/safe/dir",
#         "ALLOWED_COMMANDS": "ls,cat,pwd"
#       }
#     }
#   }
# }
  • Whether the MIT license mentioned in the description is actually applied to the package on PyPI, given the unclear metadata.
  • Current maintenance cadence and whether 406 days since last release indicates active development or dormancy.
  • Whether shell operator injection protection and path traversal prevention have been independently audited for security.
Same gist for agents: .md · .json

What it is and what it does

CLI MCP Server is a Python package that implements the Model Context Protocol (MCP) as a secure server for command-line execution. It bridges LLM applications (like Claude Desktop) and the shell by exposing two tools: run_command (to execute whitelisted CLI commands) and show_security_rules (to display current restrictions). The server enforces security through command and flag whitelisting, path validation to prevent traversal attacks, shell operator blocking, execution timeouts, and working directory restrictions—all configured via environment variables.

You use it by installing the package, configuring it with allowed commands and a base directory, and registering it as an MCP server in your LLM client (typically Claude Desktop). Once running, the LLM can invoke commands only within the whitelist and the allowed directory, making it safe to grant controlled shell access to AI agents without exposing the full system.

Use it for

  • Give Claude Desktop controlled access to run file operations (ls, cat, pwd) on a specific project directory without exposing the entire filesystem.
  • Allow an LLM agent to execute build or test commands (e.g., pytest, make) within a sandbox directory as part of a development workflow.
  • Provide a secure interface for an AI application to query system information (e.g., echo, uname) without allowing arbitrary command execution.
  • Integrate with MCP-compatible LLM clients to enable auditable, whitelisted CLI automation while maintaining security boundaries.
  • Debug and test MCP server behavior using the MCP Inspector for local development and integration testing.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

Install if you need to safely expose CLI access to an LLM application and are comfortable configuring environment variables and managing a whitelist. The low install friction and clear security model make it straightforward to set up. However, verify the actual license in the repository first (metadata is unclear), and be aware that maintenance is aging—last release was 406 days ago. No known vulnerabilities are recorded, but the security features (injection protection, path validation) should be reviewed for your threat model before use in production.

Install

cli-mcp-server on PyPI

Before you install

Low install friction with a single runtime dependency (mcp). Maintenance status is aging—last release was 406 days ago, though the repository remains active with 177 stars and no archived status. Suitable for projects that can tolerate infrequent updates.

Requires Python 3.10 or later. Requires mcp runtime dependency. Must set ALLOWED_DIR environment variable before the server will start.

License in practice

License treatment is unclear: no SPDX identifier or raw license string is recorded in the package metadata, despite the description mentioning MIT licensing. Verify the actual license terms in the repository before use in proprietary or restricted contexts.

Quickstart

pip install cli-mcp-server

# Add to Claude Desktop config (~/Library/Application\ Support/Claude/claude_desktop_config.json):
# {
#   "mcpServers": {
#     "cli-mcp-server": {
#       "command": "uvx",
#       "args": ["cli-mcp-server"],
#       "env": {
#         "ALLOWED_DIR": "/your/safe/dir",
#         "ALLOWED_COMMANDS": "ls,cat,pwd"
#       }
#     }
#   }
# }

Verify before relying

  • Whether the MIT license mentioned in the description is actually applied to the package on PyPI, given the unclear metadata.
  • Current maintenance cadence and whether 406 days since last release indicates active development or dormancy.
  • Whether shell operator injection protection and path traversal prevention have been independently audited for security.

Package facts

LicenseNot declared unclear
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
mcp
MaintenanceAging 406 days since the last release
Last repo commit
First released
Downloads82,121 / month, #14,182 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: cli_mcp_server-0.2.5-py3-none-any.whl

Tags

Capabilities
mcp server command executionsecure cli for llmcommand whitelist validationmcp protocol implementationcontrolled shell accessclaude desktop integrationcommand security sandbox
Topics
mcp-protocolllm-integrationsecurity-sandbox

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “mcp server command execution”

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also mcp-server-git · mcp · wikipedia-mcp · mcp-server-time · mcp-server-fetch · tilt-mcp · opensearch-mcp-server-py · blender-mcp · cisco-ai-mcp-scanner · fastapi-mcp

Further reading