Secure Host MCP (Razewang/secure-host-mcp) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 29 tools. No publisher has claimed this listing.
Exposes a Windows or Linux host terminal to remote MCP clients via Streamable HTTP, enabling command execution, tunnel management, and privileged operations with security features like OAuth and audit logging.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
Razewang
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
system_infoRead host system and privilege information
execute_commandExecute one command as the MCP service account
start_jobStart a tracked background command
job_statusRead tracked background job status
read_job_outputRead background job output from an offset
write_job_inputWrite UTF-8 input to a running background job and optionally close stdin
cancel_jobCancel a tracked background job
execute_elevatedExecute a command through administrator mode or the privileged helper
set_admin_modeRestart the whole MCP as root/SYSTEM through the privileged helper, or request local service-account restoration.
tunnel_inspectInspect cloudflared and frpc installation/configuration with secrets redacted
tunnel_startStart a configured tunnel client
tunnel_stopStop a tunnel client started by this service
create_terminalCreate a persistent interactive PTY terminal session
read_terminalRead bounded PTY output from a monotonic byte offset
write_terminalWrite UTF-8 input to a running PTY terminal
resize_terminalResize a running PTY terminal
interrupt_terminalSend Ctrl+C to a running PTY terminal
close_terminalClose a PTY terminal session
workspace_infoShow the configured coding workspace and its limits
read_fileRead a bounded UTF-8 file range inside the coding workspace
list_directoryList entries inside the coding workspace without following symbolic links
list_filesRecursively list coding-workspace files with an optional glob
search_textSearch UTF-8 files in the coding workspace using literal text or a regular expression
apply_patchAtomically create, uniquely replace, or delete files inside the coding workspace
git_statusRead Git working-tree status for the coding workspace
git_diffRead a bounded staged or unstaged Git diff
git_logRead bounded Git commit history for the coding workspace
git_showShow a bounded Git revision and patch
git_blameRead bounded Git line attribution for one workspace file
SECURE_HOST_MCP_HOME(by default ~/.secure-host-mcp). The status commandAll four hints declared on every tool
28/29 tools missing one or more hints — system_info (missing: destructiveHint, idempotentHint); execute_command (missing: idempotentHint); start_job (missing: idempotentHint), +25 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 6/29 tools referenced in tests (21%)
Write tests that reference each tool by name so every tool has at least one test.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/razewang/secure-host-mcp)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check