MCP-Exec (bensons/mcp-exec) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 43 tools. No publisher has claimed this listing.
A secure, context-aware MCP server for shell command execution with comprehensive logging and AI optimizations, enabling interactive sessions and safe system administration via Claude Desktop.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
bensons
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
ws: Memory exhaustion DoS from tiny fragments and data chunks
ws: Uninitialized memory disclosure
COMSPECMCP_EXEC_ALERT_RETENTIONMCP_EXEC_ALLOWED_DIRECTORIES"cwd,/tmp" # Comma-separated allowed directoriesMCP_EXEC_AUDIT_ENABLEDtrue # Enable audit loggingMCP_EXEC_AUDIT_LOGMCP_EXEC_AUDIT_LOG_LEVELdebug # emergencyalertcriticalerrorwarningnoticeinfodebugMCP_EXEC_AUDIT_RETENTION30 # Days to retain logsMCP_EXEC_BLOCKED_COMMANDS"rm -rf /,format" # Comma-separated blocked commandsMCP_EXEC_COLORIZE_OUTPUTMCP_EXEC_CONFIRM_DANGEROUS"": "true",MCP_EXEC_DESKTOP_NOTIFICATIONS_ENABLEDMCP_EXEC_ENABLE_AI_OPTIMIZATIONStrue # Enable AI-powered optimizationsMCP_EXEC_ENABLE_HEARTBEATtrue # Enable connection monitoringMCP_EXEC_FILESYSTEM_ACCESSfull # read-onlyrestrictedfullMCP_EXEC_FORMAT_CODE_BLOCKSMCP_EXEC_FORMAT_STRUCTUREDtrue # Format output in structured formatMCP_EXEC_INACTIVITY_TIMEOUT0 # Inactivity timeout in ms (0 = disabled, recommended for MCP)MCP_EXEC_INCLUDE_METADATAMCP_EXEC_INCLUDE_SUGGESTIONSMCP_EXEC_LOG_DIRMCP_EXEC_MAX_ALERTS_PER_HOURMCP_EXEC_MAX_FILE_SIZE100 # Maximum file size in MBMCP_EXEC_MAX_HISTORY_SIZEMCP_EXEC_MAX_MEMORY1024 # Maximum memory usage in MBMCP_EXEC_MAX_OUTPUT_LENGTH10000 # Maximum output length in bytesMCP_EXEC_MAX_PROCESSES10 # Maximum number of processesMCP_EXEC_MAX_SESSIONS10 # Maximum concurrent sessionsMCP_EXEC_MCP_INCLUDE_CONTEXTtrue # Include context dataMCP_EXEC_MCP_LOGGING_ENABLEDtrue # Enable MCP client notificationsMCP_EXEC_MCP_LOG_LEVEL"": "warning"MCP_EXEC_MCP_QUEUE_SIZE100 # Max queued messagesMCP_EXEC_MCP_RATE_LIMIT60 # Max messages per minuteMCP_EXEC_MONITORING_ENABLEDMCP_EXEC_NETWORK_ACCESStrue # Allow network accessMCP_EXEC_PRESERVE_WORKING_DIRMCP_EXEC_SANDBOXING_ENABLEDfalse # Enable sandboxingMCP_EXEC_SECURITY_LEVEL"": "strict",MCP_EXEC_SESSION_BUFFER_SIZE1000 # Session output buffer sizeMCP_EXEC_SESSION_PERSISTENCEMCP_EXEC_SESSION_TIMEOUT1800000 # Session timeout (30 minutes)MCP_EXEC_SHOW_COMMAND_HEADERMCP_EXEC_SHOW_EXECUTION_TIMEMCP_EXEC_SHOW_EXIT_CODEMCP_EXEC_SHUTDOWN_TIMEOUT5000 # Graceful shutdown timeout (5 seconds)MCP_EXEC_STRIP_ANSItrue # Strip ANSI escape codesMCP_EXEC_SUMMARIZE_VERBOSEtrue # Summarize verbose outputMCP_EXEC_TERMINAL_VIEWER_AUTH_TOKENMCP_EXEC_TERMINAL_VIEWER_BUFFER_SIZEMCP_EXEC_TERMINAL_VIEWER_ENABLEDMCP_EXEC_TERMINAL_VIEWER_ENABLE_AUTHMCP_EXEC_TERMINAL_VIEWER_HOSTMCP_EXEC_TERMINAL_VIEWER_MAX_SESSIONSMCP_EXEC_TERMINAL_VIEWER_PORTMCP_EXEC_TERMINAL_VIEWER_SESSION_TIMEOUTMCP_EXEC_TIMEOUT300000 # Command timeout in millisecondsMCP_EXEC_USE_MARKDOWNtrue # Use Markdown formattingSHELLTests exist
No test files found
Add tests that exercise each declared tool.
Shell command execution
5 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 1 high severity in production deps — ws@8.18.3 (high), ws@8.18.3 (low)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/bensons/mcp-exec)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check