Self-hosted MCP for controlled AI development and staging without a general-purpose remote shell.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Let an AI run tests and controlled staging operations on your own server without giving it a general-purpose remote shell.
Runner MCP is a security-first, self-hosted Model Context Protocol service. You configure the projects and operations that exist; the AI selects from those bounded capabilities instead of supplying arbitrary shell commands, executables, filesystem paths or service names.
An AIfordable project — secure software. Built with AI. Fairly priced.
Runner MCP is currently alpha. The canonical public distribution is available on PyPI, the official MCP Registry and GitHub Releases. The first fully aligned cross-registry release is v0.1.2.
Start here: 5-minute demo · Quickstart · Security model · Threat model
| Approach | AI can inspect/run configured work | Arbitrary shell is the normal interface | Explicit audit/safety boundary |
|---|---|---|---|
| SSH / broad remote-control tool | Yes | Yes | Depends on the surrounding setup |
| Runner MCP | Yes | No | Yes — allow-lists, bounded output, emergency stop and approval gates |
Runner MCP is intentionally not a sandbox for untrusted code and does not claim to replace every operator maintenance tool. Its goal is narrower: routine AI-assisted development and staging operations should not require handing the AI an unrestricted shell.
AI-assisted development becomes much more useful when the assistant can verify changes against real projects. But routine tasks such as reading a safe file, running a known test suite or checking a staging service do not require the authority of a general-purpose remote shell.
Runner MCP turns those routine operations into explicit capabilities. The operator configures projects and named actions locally; the AI client selects from those capabilities instead of supplying arbitrary commands, executable paths or private infrastructure values.
The original motivation was practical: reduce the day-to-day dependency on broad remote-control tooling while keeping useful development and staging automation.
Runner MCP is the local safety boundary. GitHub can be used for source collaboration and, optionally, as a bounded mailbox transport; it is not turned into a mechanism for sending arbitrary shell commands.
The normal authority model is deliberately asymmetric: read-only inspection is easier, mutating staging actions are narrower, higher-risk actions require short-lived local approval, and production mutations remain disabled.
Runner Fabric remains a separate product and orchestration/control-plane owner. When both products run on the same host, Runner MCP can optionally expose a loopback-only transport bridge with three coarse tools — run, inspect and cancel a bounded Fabric work-unit. This lets an AI hand off a whole repository-change workflow without receiving generic GitHub/Git/shell primitives.
The bridge is disabled by default and does not change Runner MCP's authority model. See Optional Runner Fabric bridge.
You do not need to understand the Python source code for the basic workflow.
Starting with v0.1.1, the shortest persistent install is:
uvx aifordable-runner-mcp ... is also suitable for package discovery and short-lived evaluation, but a persistent tool install is the clearer choice for a self-hosted service with private configuration and autostart.
To install directly from source instead:
Start with QUICKSTART.md for the guided installation.
Connectivity remains loopback-first. runner-mcp setup in public mode records an external HTTPS resource/auth identity only; it does not expose a bind address, install TLS, edit DNS/firewalls, configure a reverse proxy or create a tunnel. runner-mcp guide reports only a generic connectivity category without printing the configured hostname or private URL. For supported OpenAI products, private access can use Secure MCP Tunnel; an external HTTPS reverse proxy remains an operator-managed alternative.
If Runner MCP runs under a dedicated service account while you log in with a separate operator account, install a local operator wrapper. Skip this step when Runner MCP runs under the same account you use interactively:
The wrapper keeps the private configuration with the service account and delegates through sudo; it does not copy credentials into the operator account.
For a user-to-developer path, see docs/USING_AND_EXTENDING.md. Contributors can start with CONTRIBUTING.md.
For the zero-additional-service-cost GitHub mailbox pattern, see docs/GITHUB_MAILBOX_BRIDGE.md. The public package now includes both a transport-neutral processor and a fixed-host GitHub transport; completion feedback and watcher resilience are documented in docs/COMPLETION_FEEDBACK.md and docs/WATCHER_RESILIENCE.md. Bounded multi-project scheduling and capacity controls are documented in docs/CONCURRENCY.md.
Dependency/build/interpreter contract changes are deliberately refused by self-update and require a local bootstrap/manual upgrade; see self-update compatibility.
Runner MCP is developed as an AIfordable project. Public launch readiness is tracked in docs/LAUNCH_READINESS.md. See also the changelog, release checklist and prepared launch copy.
Useful commands:
The emergency stop is intentionally easy to activate and harder to clear.
Current implemented foundations include:
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/runner-mcp)<a href="https://allmcps.com/mcp/runner-mcp"><img src="https://allmcps.com/api/badge/runner-mcp?style=directory" alt="Runner MCP on AllMCPs" /></a>