mcp-remote-sudo

Narrow, expiring, receipted authority over a remote Linux machine for an AI agent, instead of an open shell. Early design and prototype.

MCPLinuxSSH

The problem

Giving an agent a remote shell gives it everything the account can do. Giving it nothing means it can’t fix anything.

What it does

mcp-remote-sudo is an MCP utility where a human-reviewed manifest defines what one agent session may do on one host: which typed operations, on which resources, with which argument constraints, and for how long. The server exposes only those operations and writes a receipt for every attempt, including denials. Authority is static by default; it can expire, be revoked or be narrowed, but it doesn’t expand because an agent asks.

The README’s example is a Wi-Fi debugging task. It allows network status, scanning, and loading or unloading two named kernel modules for 30 minutes, and denies shell, package installs, reboot and filesystem writes.

Status

Work in progress. The README labels it an early design and prototype, and the first implementation slice is tracked in the repository’s first issue.

Source