cmdshellmcp: an allowlisted shell MCP server with Docker sandbox for AI agents

ag789 · reddit · 2026-10-04

A new open-source project, cmdshellmcp, gives AI agents limited local shell access safely: it exposes a small allowlisted set of Unix commands, safe file operations, patch application and URL fetching instead of unrestricted shell. Built in Python with fastmcp, listening on 127.0.0.1:8003 (streamable HTTP, optional --sse), it ships full Docker Debian sandbox setup — Dockerfile, setup scripts, DOCKER.md guide and a systemd service unit. Inspired by an earlier r/LocalLLaMA discussion on unsafe shell MCP servers.

Original post →

More from coding & agent

coding & agent channel →