mirror of
https://github.com/punkpeye/awesome-mcp-servers.git
synced 2026-10-03 11:12:57 +00:00
Add cmdxray (shell-command safety gate + explainer for AI agents) to Security
This commit is contained in:
@@ -3948,6 +3948,7 @@ Tools for conducting research, surveys, interviews, and data collection.
|
||||
- [CTRLRun/ctrlrun](https://github.com/CTRLRun/ctrlrun) [](https://glama.ai/mcp/servers/CTRLRun/ctrlrun) 🐍 🏠 - Execution safety for AI agent actions. `ctrlrun mcp-operator` exposes the approval queue as tools (`list_pending_approvals`, `approve`, `deny`, `resolve`, plus `receipts`, `effects`, `stats` and `inspect_action`), so the human who has to answer a held action answers it from the assistant they are already in; read tools answer without a credential and write tools refuse without one that names a person. Separately, the gateway proxies any MCP server so every tool call is checked against a YAML policy before it runs: allow, hold for a human, or deny. Approvals are single-use and bound to the hash of the exact action, one logical effect runs at most once across processes and hosts, and an unknown outcome is recorded AMBIGUOUS rather than FAILED so a blind retry is refused. Every attempt leaves a hash-chained JSON receipt. Apache-2.0. `pip install ctrlrun`
|
||||
|
||||
- [Drumworks/ssid-mcp](https://github.com/Drumworks/ssid-mcp) [](https://glama.ai/mcp/servers/Drumworks/ssid-mcp) 📇 ☁️ - MAC-address (OUI) vendor lookup and router default-login directory for AI agents. Identify a device manufacturer from its MAC address, detect randomized/private (locally-administered) addresses instead of reporting "unknown", or fetch a router's default login IP and admin credentials — every router field cited to the manufacturer's own documentation. Free tier, no signup. `npx -y ssid-mcp`
|
||||
- [aurelio-nakamura/cmdxray](https://github.com/aurelio-nakamura/cmdxray) [](https://glama.ai/mcp/servers/aurelio-nakamura/cmdxray) 📇 🏠 🍎 🪟 🐧 - A safety gate and explainer for AI coding agents that run shell commands. `check_command_safety` returns a danger/caution/none verdict for a proposed command — catching `rm -rf /`, `curl | sudo bash`, `dd`/`mkfs`/`shred` to a device, `chmod -R 777 /`, fork bombs, `git push --force` and CI `${{ }}` script-injection — so an agent can guard a command before executing it. `explain_command` gives a token-by-token breakdown of every flag, pipe, redirect and subshell. Fully offline, zero dependencies, nothing leaves the machine. `npx -y cmdxray-mcp`.
|
||||
|
||||
### 🌐 <a name="social-media"></a>Social Media
|
||||
|
||||
|
||||
Reference in New Issue
Block a user