Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Ā© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. šŸ–„ļø Command Line
  3. Sysknife
Sysknife logo
Health: ActiveRecent health check succeeded.Last checked 9/21/2026, 7:01:13 AM

Sysknife

User RatingsBe the first to rate and review this MCP server!
View Repository12 GitHub StarsTotal stargazers on GitHub for the source repository (12 stars).Visit Website
linuxsystem-administrationsecurityauditcli

Linux administration MCP server using typed actions, approval receipts, signed audit logs, and rollback for atomic-host changes.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.

Add to CursorAdd to VS Code
We couldn’t automatically confirm this listing starts correctly

We ran the install command below but it didn't respond within our test window — this can mean a slow first-time install rather than a real problem.

npx -y sysknife-setup

No response to initialize.

This is an experimental automated check and can have false negatives — missing environment variables, a slow cold install, etc. It doesn’t necessarily mean something’s wrong. Last checked 1mo ago.

Manual Client & Custom JSON ConfigExpand JSON ā–¾

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "lacs-project-sysknife": {
      "command": "npx",
      "args": [
        "-y",
        "sysknife-setup"
      ]
    }
  }
}

šŸ’” Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesšŸ–„ļø More in Command Line

Overview

SysKnife lets AI clients plan and execute Linux administration tasks through typed operations rather than model-generated shell commands. A privileged daemon runs only explicitly approved actions, records them in an Ed25519-signed hash-chain audit log, and provides automatic rollback for failed rpm-ostree changes. Use it when system changes need structured approval, auditing, and reduced shell-injection risk.

Use cases

•Plan Linux administration tasks from chat
•Review and approve typed system changes
•Audit executed actions with signed history
•Verify the integrity of audit records
•Roll back failed rpm-ostree changes

Key features

•189 typed system administration actions
•Risk-rated execution plans
•One-time TTL approval receipts
•Ed25519-signed hash-chain audit log
•Automatic rollback for atomic-host changes
•Live execution output

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Sysknife.

Extracted Tool Capabilities
189 typed system administration actions
Risk-rated execution plans
One-time TTL approval receipts
Ed25519-signed hash-chain audit log
Automatic rollback for atomic-host changes
Live execution output

Documentation Overview

SysKnife

SysKnife

Your sysadmin co-pilot. Plan. Approve. Audit.

CI License Stars Issues Discussions npm version Glama MCP server quality score

DistrosĀ  Ubuntu 20.04 and later supported Ubuntu 22.04, 24.04 and 26.04 VM validated Fedora Atomic 41 and later eligible but not VM validated

Install Ā· How it works Ā· Why not X? Ā· Distro matrix Ā· Roadmap Ā· Contribute Ā· Discuss

SysKnife in Claude Code via MCP on Ubuntu 24.04: UfwAllow, AptInstall and UfwStatus through terminal-issued receipts

A deterministic reproduction of the Claude Code MCP flow on Ubuntu 24.04, rendered offline by ubuntu-flow-mock.sh so it replays identically from a fresh checkout. Every action name, risk level and command shown is the one the catalogue carries. The same flow works in Cursor and Codex CLI.
On an atomic host the plan uses rpm-ostree instead: the Fedora Atomic recording. Looking for the standalone CLI? See the CLI guide.

Describe what you want in plain language. Review a typed plan with risk levels. Approve explicitly. Watch it execute with live output. Atomic-host changes (rpm-ostree) roll back automatically on failure. Every action is Ed25519-signed and audited.

The AI never supplies a command. Every action is a typed operation with a formal risk level, and the daemon builds the command line itself from the action's own definition — some actions do run through sh -c, but the shell fragment is constructed by SysKnife, never by the model. The AI cannot touch your system directly. A privileged daemon executes only what you approve, writes a tamper-evident Ed25519-signed audit chain, and rolls back atomic-host (rpm-ostree) changes automatically on failure.

Why typed actions and not a guarded shell? Red-team research (GuardFall) found that 10 of 11 AI agents bypass raw-string shell guards — an allowlist or regex is filtering a language rich enough to hide intent. SysKnife removes the shell string entirely: the model emits typed actions, and a public-key-verifiable audit chain records every one.


Install

The fastest path is the setup wizard. It installs the daemon and wires SysKnife into your AI IDE — Claude Code, Cursor, or Codex CLI — so you can plan and execute from chat.

Terminal
npx sysknife-setup

Needs Node 22 or newer; older Node releases no longer receive security fixes. On Ubuntu 22.04 apt install nodejs gives Node 12, which is too old; the installer says so and how to get a current Node. No Rust toolchain and no compile: it downloads verified prebuilt binaries.

npm version

What this does:

  1. Downloads the prebuilt sysknife + sysknife-daemon binaries for your architecture (x86_64 / aarch64) from GitHub Releases, SHA-256-verifies each against the release checksum file — a mismatch aborts the install — and places them in ~/.local/bin (no sudo). Pass --no-binary to skip the download and build from source instead.

  2. Asks for your LLM provider, key, and model — OpenAI / Anthropic / Gemini / Ollama / Groq / DeepSeek / Mistral / xAI (Ollama needs no key). The key prompt is skipped when the matching env var is already set.

  3. Asks which AI integration to wire up (or pick --claude / --cursor / --codex / --all) and your daemon target(s) — socket, plus an optional vsock token for a remote VM.

  4. Writes the integration-specific MCP config (merging into any existing file, never clobbering) so the next chat session sees the sysknife_* tools — sysknife_plan, sysknife_execute, sysknife_history, sysknife_doctor, sysknife_audit_verify, and distro-compatible direct read-only queries such as sysknife_get_disk_usage — as first-class tools.

  5. Installs and starts the daemon as a service (last step) — a systemd user service by default (no sudo; kept alive across logout via linger). That service runs as you, so read-only actions work but mutating ones do not: installing packages or restarting services needs the system-level service, whose sudoers grants belong to the sysknife system user. Pick the system service on any host where you intend to change something, and pass --daemon-mode=system|user|skip to choose without a prompt. --daemon-mode=system does not install the system service from the wizard — it needs root-owned sudoers, polkit and helper policy that sudo make install owns — so it prints the exact sequence and reports the daemon as not yet installed.

    To verify the download against a checksum list you trust independently of the release, set SYSKNIFE_PINNED_SHA256SUMS=/path/to/sums; see SECURITY.md.

ClientFiles written
Claude Code.mcp.json + .claude/hookify.*.local.md
Cursor.cursor/mcp.json + .cursor/rules/sysknife.mdc
Codex CLI~/.codex/config.toml (appended) + AGENTS.md

Then in your chat: ask for what you want and review the plan with risk pills. Approve each transaction with sysknife approve <transaction-id> in a terminal, return the one-time receipts, and watch it execute. The daemon, not the prompt, enforces the receipt boundary.

Prefer the standalone CLI? Same engine, no IDE — see the CLI guide for sysknife "...", --dry-run, --json, approval prompts, and audit-log inspection.

Manual install — Ubuntu 20.04+

Needs Rust stable and a C compiler (build-essential): the TLS and SQLite dependencies build native code, so a rustup-only machine stops at error: linker cc not found. cmake is not required. Budget 7 to 12 minutes for the ~400-crate build (6m56s on Ubuntu 24.04, 11m43s on 22.04).

sh
sudo apt-get install -y build-essential
git clone https://github.com/lacs-project/sysknife
cd sysknife
make build                            # builds sysknife (CLI) + sysknife-daemon
sudo make install                     # installs both; daemon runs as a system service
sudo systemctl enable --now sysknife-daemon

# Join the socket group and one role group, or every request is refused with
# "Permission denied" before any role check runs: /run/sysknife is 0750
# sysknife:sysknife, and a sudo admin is not in that group automatically.
# Role groups: sysknife-observer (read-only), sysknife-dev (medium risk),
# sysknife-admin (high risk). Members of wheel are treated as admin.
sudo usermod -aG sysknife,sysknife-admin "$USER"
newgrp sysknife                       # or log out and back in

# Then wire your IDE — --no-binary skips the download since you just built them
# (--daemon-mode=skip: make install already set the service up)
npx sysknife-setup --no-binary --daemon-mode=skip

Uninstall

Whichever way you installed, there is one command for it.

sh
# Removes what the wizard installed: the user service, the binaries in
# ~/.local/bin, and the MCP + agent config in the current directory.
npx sysknife-setup --uninstall

# See exactly what that would touch, without touching it.
npx sysknife-setup --uninstall --dry-run

Read the full README →View source on GitHub →

Related MCP Servers

View all in Command Line View all alternatives
  • Cli MCP Server logoCli MCP Server

    Command line interface with secure execution and customizable security policies

    šŸ–„ļø Command Line3 views
    Compare vs Cli MCP Server →
  • MCP Ssh Manager logoMCP Ssh Manager

    Manage multiple SSH servers from one MCP: command execution, file transfer/rsync, database dump/import/query (MySQL/PostgreSQL/MongoDB), backups & restore, health monitoring, persistent sessions, tunnels, ProxyJump/bastion, and opt-in per-server security modes (readonly/restricted) with audit log. Linux, macOS & Windows OpenSSH.

    šŸ–„ļø Command Line8 views
    Compare vs MCP Ssh Manager →
  • When logoWhen

    Developer toolkit: auto-detect stack for AI context files, catch port conflicts, validate .env schemas, spot docs drift, audit dependency licenses, and time coding tasks — 7 MCP tools, one install.

    šŸ–„ļø Command Line2 views
    Compare vs When →
  • Rootpilot MCP logoRootpilot MCP

    Safe, read-only SSH diagnostics for Linux/Docker servers: a fixed 38-command whitelist (no arbitrary execution), secret redaction, per-command timeouts. Collects evidence; your model does the reasoning. npx @rootpilot/mcp-ssh-diagnose

    šŸ–„ļø Command Line2 views
    Compare vs Rootpilot MCP →

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks — not a rating.

GitHub stars
12
Stargazers on the source repository.
npm downloads
1.1k
Package downloads in the last 30 days.
Last commit
1d ago
Most recent push to the default branch.
Install check
Inconclusive
Didn't respond in our test window — often a slow first install.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet — be the first to share how this listing worked for you.

Frequently Asked Questions about Sysknife

No. The AI emits typed actions, and SysKnife constructs the command line from each action definition.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSysknife AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/lacs-project-sysknife?style=directory)](https://allmcps.com/mcp/lacs-project-sysknife)
HTML Embed
<a href="https://allmcps.com/mcp/lacs-project-sysknife"><img src="https://allmcps.com/api/badge/lacs-project-sysknife?style=directory" alt="Sysknife on AllMCPs" /></a>

Technical Specs & Signals

CategoryšŸ–„ļøCommand Line
PricingFree
More technical detailsExpand ā–¾
TransportSTDIO
RuntimeNode.js
AuthAPI key
ClientsClaude Desktop, Cursor
Last updatedSep 21, 2026
12/12 checks healthy over the last 42d
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars12
GitHub Star CountTotal stargazers on GitHub representing community popularity (12 stars).
Last commit1d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 21, 2026
npm downloads1,127/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
57Quality signal: Good Ā· 57/100How this signal is calculated ā–¾
Server availabilityNot measured

Not scored for repo-hosted servers — we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools24/30
Adoption & activity9/15
Community engagement0/10

A guidance signal from public completeness & health data — not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 3d ago via OSV.dev Ā· sysknife-setup (npm)

ā˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server →

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge — proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it — no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in šŸ–„ļø Command Line →Best MCP servers for Command Line & Terminal →Alternatives to Sysknife →Install in Claude DesktopInstall in CursorInstall in VS Code