MCP Sudo runs on your own machine — the client starts it, so there is no endpoint to ping. 85 installs a week from pypi. Last commit 20 Apr 2026.
Run sudo commands with a Fernet-encrypted password bound to machine-id + user.
We read the source, 22 h ago · rules 3dff92dd89df
A value the model can set ends up inside a file or shell call. That is not a flaw by itself — for a terminal server it is the job — but it is where things go wrong when it is not.
result = subprocess.run(
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
mcp-sudo похож на mcp-suno
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
result = subprocess.run(
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
That is not a flaw by itself — but it is where things go wrong when it is not the job. We re-read this code on every release. Watch it and you hear from us the day another one appears.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add mcp-sudo -- uvx mcp-sudo
{
"mcpServers": {
"mcp-sudo": {
"args": [
"mcp-sudo"
],
"command": "uvx"
}
}
}
[mcp_servers.mcp-sudo]
command = "uvx"
args = ["mcp-sudo"]
{
"mcpServers": {
"mcp-sudo": {
"args": [
"mcp-sudo"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"mcp-sudo": {
"args": [
"mcp-sudo"
],
"command": "uvx"
}
}
}
MCP server to mount and unmount VeraCrypt containers with secure stdin password handling.
Paid token risk and security intelligence for AI agents over MCP with x402 payments.
Send end-to-end encrypted email and files. Encryption happens on your machine, not our server.
An MCP server to run arbitrary commands
Run commands on a machine you cannot SSH into. Air-gapped, bastion-only, change-controlled.
Run commands on a machine you cannot SSH into. Air-gapped, bastion-only, change-controlled.
Hash passwords with bcrypt and issue/verify JWT session tokens over A2A + MCP.
Shared TODO/backlog MCP server with claim tracking, web UI, and encrypted local storage.
Answers built from our own checks of this server.