TTerminatorA lightweight Model Context Protocol (MCP) server written in Go that enables secure terminal command execution on macOS and Linux. Supports persistent shell sessions, configurable timeouts, and both HTTP (StreamableHTTP) and STDIO transports. Designed for AI integrations and automation use cases with flexible session management and platform-aware execution.

mcp-so:terminator_iris-networks

View source
B
85/100

First Seen

Feb 18, 2026

Last Scanned

Feb 20, 2026

Findings

1

Score

85/100

HIGH 1

Findings (1)

HIGH
Inline code execution in MCP command
L61

Detects MCP servers using inline code execution via -e, -c, or eval flags

"args": [
        "run",
        "-i",
        "--rm",
        "-p",
        "8080:8080",
        "-e",
        "MCP_COMMAND_TIMEOUT=30",
        "-e",
        "MCP_SHELL=/bin/bash"
FIX

Restrict MCP server permissions to the minimum required. Remove broad filesystem, network, or execution permissions and use scoped access controls (specific directories, specific tools).

FP?

Likely FP if the broad permissions are in a development/testing configuration that is clearly not intended for production use.