{"name":"io.github.murzirius/vps-guardian-mcp","slug":"murzirius-vps-guardian-mcp","title":"VPS Guardian","description":"Secure SSH bridge for AI agents to observe and safely administer Linux VPSs.","url":"https://mcp.market/server/murzirius-vps-guardian-mcp","rating":null,"grade":"A","score":89,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":29,"stars":0,"forks":0,"downloads_week":674,"last_push_at":"2026-09-17T18:02:58.000Z","license":"MIT"},"uptime":null,"claimed":false,"transport":"mixed","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/murzirius/VPS-Guardian-MCP","website":null,"version":"0.21.0","remotes":[],"packages":[{"registryType":"npm","identifier":"@murzirius/vps-guardian-mcp","version":"0.21.0","runtimeHint":"npx","transport":{"type":"stdio"}},{"registryType":"pypi","identifier":"vps-guardian-mcp","version":"0.21.0","runtimeHint":"uvx","transport":{"type":"stdio"}}],"tools":[{"name":"analyze_disk_usage","description":"Analyze disk usage for a directory to discover space bottlenecks and large files.","write_action":false,"price_micros":0,"input_schema":null},{"name":"apply_change_set","description":"Apply, validate, reload, health-check, and automatically roll back one ChangeSet.","write_action":false,"price_micros":0,"input_schema":null},{"name":"apply_project_patch","description":"Apply a confirmed bounded source patch with backups; it never executes project code.","write_action":true,"price_micros":0,"input_schema":null},{"name":"audit_ssh_config","description":"Audit the SSH daemon configuration against security best practices.","write_action":false,"price_micros":0,"input_schema":null},{"name":"begin_change_set","description":"Open a short-lived, bounded, reversible Nginx configuration ChangeSet.","write_action":false,"price_micros":0,"input_schema":null},{"name":"begin_project_patch","description":"Open a short-lived, bounded source patch; no project code runs.","write_action":true,"price_micros":0,"input_schema":null},{"name":"check_dns_health","description":"Audit system DNS resolution health, configured nameservers, and query responsiveness.","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_failed_logins","description":"Inspect recent failed SSH login attempts to detect brute-force attackers.","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_guardian_updates","description":"Check if a newer version or commit of VPS-Guardian-MCP is available on GitHub.","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_http_endpoint","description":"Check a public HTTP(S) URL: response status, redirects, TLS, latency, and optional text.","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_http_endpoints","description":"Check up to 20 public HTTP(S) endpoints in one compact deployment health report.","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_kernel_errors","description":"Audit kernel logs for hardware failures, storage I/O errors, or application segfaults.","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_oom_events","description":"Inspect kernel logs for Linux Out-Of-Memory (OOM) Killer invocations.","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_service_status","description":"Check the operational status of a systemd service unit.","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_ssl_certificates","description":"Audit SSL/TLS certificates configured on the host (Let's Encrypt / Certbot).","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_system_limits","description":"Audit system-wide and user limits: file descriptors, max PIDs, virtual memory, socket backlogs.","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_system_updates","description":"Audit available operating system package updates and pending security patches.","write_action":false,"price_micros":0,"input_schema":null},{"name":"clean_docker_garbage","description":"Safely reclaim disk space by pruning dangling images, stopped containers, unused volumes, and networks.","write_action":false,"price_micros":0,"input_schema":null},{"name":"close_agent_session","description":"Close a session with an outcome; historical records remain secret-redacted.","write_action":false,"price_micros":0,"input_schema":null},{"name":"close_maintenance_window","description":"Close a maintenance window with a secret-redacted outcome note.","write_action":false,"price_micros":0,"input_schema":null},{"name":"compare_system_snapshots","description":"Compare two snapshots and rank configuration or infrastructure drift by risk.","write_action":false,"price_micros":0,"input_schema":null},{"name":"compare_workload_baseline","description":"Compare a saved workload baseline with the current workload state.","write_action":false,"price_micros":0,"input_schema":null},{"name":"compose_project_action","description":"Token-confirmed Docker Compose up, restart, or stop for selected project services.","write_action":false,"price_micros":0,"input_schema":null},{"name":"create_backup","description":"Create a compressed tar.gz archive of an authorized website or configuration directory.","write_action":true,"price_micros":0,"input_schema":null},{"name":"create_maintenance_window","description":"Create an expiring maintenance window for agent coordination.","write_action":true,"price_micros":0,"input_schema":null},{"name":"create_system_snapshot","description":"Save a privacy-preserving, read-only VPS state baseline.","write_action":true,"price_micros":0,"input_schema":null},{"name":"create_workload_baseline","description":"Save a secret-free known-good workload baseline for later drift comparison.","write_action":true,"price_micros":0,"input_schema":null},{"name":"deploy_config_change","description":"Commit a validated configuration plan, reload its service, and auto-rollback on failure.","write_action":true,"price_micros":0,"input_schema":null},{"name":"detect_zombie_processes","description":"Scan system process table for defunct/zombie processes and identify non-reaping parents.","write_action":false,"price_micros":0,"input_schema":null},{"name":"diagnose_workload","description":"Gather bounded read-only logs, OOM, kernel, and health evidence for a workload.","write_action":false,"price_micros":0,"input_schema":null},{"name":"discover_projects","description":"Find bounded Git/application projects in configured VPS project roots.","write_action":false,"price_micros":0,"input_schema":null},{"name":"docker_container_action","description":"Safely execute lifecycle operations (start, stop, restart, pause, unpause) on a container.","write_action":false,"price_micros":0,"input_schema":null},{"name":"execute_recovery","description":"Execute an emergency recovery operation from a strictly whitelisted list.","write_action":true,"price_micros":0,"input_schema":null},{"name":"find_workload","description":"Find an application by domain, container, Compose service, port, or path fragment.","write_action":false,"price_micros":0,"input_schema":null},{"name":"generate_incident_report","description":"Generate one prioritized, read-only VPS incident report.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_agent_session","description":"Read a session's objective, findings, handoff note, and expiry state.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_audit_events","description":"Return recent redacted audit events for state-changing operations.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_backup_status","description":"List isolated Guardian backups with sizes and creation times, without reading contents.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_change_impact","description":"Show what a prospective restart, stop, config deployment, or update may affect.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_database_health","description":"Discover running databases and verify responsiveness, latency, and socket states.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_docker_container_logs","description":"Safely read stdout/stderr logs from a specific Docker container.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_docker_stats","description":"Retrieve live resource utilization metrics for all running Docker containers.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_event_watch","description":"Retrieve events seen since an active event watch was opened; this does not push notifications.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_fail2ban_status","description":"Check Fail2ban status, active protection jails, and currently banned IP addresses.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_failed_systemd_units","description":"Find all degraded or failed systemd services across the entire system.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_firewall_status","description":"Return normalized UFW, firewalld, or nftables firewall state and rules.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_open_ports","description":"Discover all listening network ports (TCP and UDP) and identify bound processes.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_package_updates","description":"List available updates via APT, DNF, YUM, Pacman, or Zypper without changing state.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_platform_capabilities","description":"Detect package, firewall, service-manager, and Docker Compose backends on this host.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_process_details","description":"In-depth diagnostics for a specific PID: hierarchy, threads, memory, open files, sockets, I/O.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_project_changes","description":"Read Git working-tree changes and diff statistics without modifying the project.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_recent_server_events","description":"Return a compact timeline of Guardian actions and important journal events.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_resource_alerts","description":"Evaluate active resource watches once and return current threshold alerts.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_runtime_budget","description":"Show the active low-resource profile and limits VPS-Guardian applies on this host.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_safety_status","description":"Return the active safety mode, confirmation policy, TTL, and audit destination.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_system_health","description":"Retrieve a complete system health snapshot of the Linux VPS.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_top_processes","description":"Retrieve the top resource-consuming processes running on the VPS.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_ufw_status","description":"Inspect the status and active filtering rules of the UFW firewall.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_vps_topology","description":"Map websites, reverse proxies, Compose projects, containers, ports, and databases.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_web_deployment_status","description":"Verify one website end to end: public HTTPS response, local Nginx host, and certificate.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_workload_health","description":"Return concise health, resource, container, and matching SSL state for one workload.","write_action":false,"price_micros":0,"input_schema":null},{"name":"handoff_agent_session","description":"Leave a concise handoff note so another agent can continue without rediscovery.","write_action":false,"price_micros":0,"input_schema":null},{"name":"inspect_compose_project","description":"Return Docker Compose service topology, images, ports, dependencies, and healthchecks.","write_action":false,"price_micros":0,"input_schema":null},{"name":"inspect_docker_container","description":"Deep inspection of container networks, volume mounts, restart policy, healthcheck, and masked env vars.","write_action":false,"price_micros":0,"input_schema":null},{"name":"inspect_project","description":"Inspect an approved project: stack markers, Git branch/commit, and dirty state.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_agent_sessions","description":"List active shared agent sessions; expired sessions are marked automatically.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_compose_projects","description":"Discover conventional Docker Compose files in an authorized directory tree.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_cron_jobs","description":"Discover all scheduled cron jobs on the Linux system.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_directory","description":"Inspect file and directory structures within authorized administrative paths.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_docker_containers","description":"List Docker containers with their status, image, port bindings, volumes, and health.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_maintenance_windows","description":"List active maintenance windows, or include closed and expired history.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_runbook_templates","description":"List command-free agent runbooks built from existing guarded MCP tools.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_runbooks","description":"List active agent runbooks, with optional completed history.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_system_snapshots","description":"List stored VPS state snapshots without exposing their collected content.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_systemd_timers","description":"Audit active and pending systemd timers via 'systemctl list-timers'.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_virtual_hosts","description":"Inspect active Nginx virtual hosts, listening ports, SSL, and reverse proxy targets.","write_action":false,"price_micros":0,"input_schema":null},{"name":"lock_workload","description":"Reserve a workload briefly so concurrent agents do not make conflicting changes.","write_action":false,"price_micros":0,"input_schema":null},{"name":"open_event_watch","description":"Open an expiring workload watch. Use get_event_watch later to retrieve new events.","write_action":false,"price_micros":0,"input_schema":null},{"name":"plan_config_deployment","description":"Validate and preview an Nginx config or Caddyfile deployment.","write_action":false,"price_micros":0,"input_schema":null},{"name":"prepare_repair_plan","description":"Create an evidence-backed repair plan without changing the VPS.","write_action":true,"price_micros":0,"input_schema":null},{"name":"preview_change_set","description":"Show secret-redacted diffs and request one confirmation for a ChangeSet.","write_action":false,"price_micros":0,"input_schema":null},{"name":"preview_project_patch","description":"Show secret-redacted source diff and obtain one confirmation token for a patch.","write_action":true,"price_micros":0,"input_schema":null},{"name":"read_project_file","description":"Read one non-binary project file without following symlinks; redact common secrets.","write_action":false,"price_micros":0,"input_schema":null},{"name":"read_service_logs","description":"Safely fetch and optionally filter recent log lines for a service or Docker container.","write_action":false,"price_micros":0,"input_schema":null},{"name":"record_session_finding","description":"Save one bounded, secret-redacted finding or decision to an active agent session.","write_action":false,"price_micros":0,"input_schema":null},{"name":"run_project_checks","description":"Run only fixed safe checks: Git whitespace validation or bounded Python syntax parsing.","write_action":true,"price_micros":0,"input_schema":null},{"name":"search_project_code","description":"Bounded literal code search with ignored dependency folders and redacted output.","write_action":false,"price_micros":0,"input_schema":null},{"name":"set_web_file_mode","description":"Set a safe web-readable mode (0644 or 0640) for a static file under /var/www.","write_action":false,"price_micros":0,"input_schema":null},{"name":"stage_file_change","description":"Stage one Nginx configuration change; content is not applied yet.","write_action":false,"price_micros":0,"input_schema":null},{"name":"stage_project_file_change","description":"Stage one source-file replacement in an active project patch without applying it.","write_action":false,"price_micros":0,"input_schema":null},{"name":"start_agent_session","description":"Create an expiring, secret-safe shared task context for agents working on this VPS.","write_action":true,"price_micros":0,"input_schema":null},{"name":"start_runbook","description":"Open a bounded agent runbook; it never runs commands or bypasses confirmation.","write_action":false,"price_micros":0,"input_schema":null},{"name":"test_network_connectivity","description":"Benchmark outbound network connectivity and latency using direct Python sockets.","write_action":false,"price_micros":0,"input_schema":null},{"name":"test_nginx_config","description":"Test Nginx configuration for syntax errors ('nginx -t') without reloading.","write_action":false,"price_micros":0,"input_schema":null},{"name":"update_runbook_step","description":"Record the outcome of one runbook step after its separate guarded tool call.","write_action":true,"price_micros":0,"input_schema":null},{"name":"verify_backup","description":"Verify a Guardian tar.gz archive without extracting it.","write_action":false,"price_micros":0,"input_schema":null},{"name":"view_file_content","description":"Safely read the content of an authorized configuration or web file.","write_action":false,"price_micros":0,"input_schema":null},{"name":"watch_resource_threshold","description":"Create an expiring CPU, memory, swap, or disk threshold watch.","write_action":true,"price_micros":0,"input_schema":null},{"name":"write_file_content","description":"Atomically write or update a configuration file within authorized directories.","write_action":true,"price_micros":0,"input_schema":null}],"scan":{"score":89,"grade":"A","scanned_at":"2026-09-19T21:08:28.104Z","report":{"scannerVersion":"0.1.8","scannedAt":"2026-09-19T21:08:27.964Z","components":{"code":{"score":25,"max":25,"notes":["2 source files scanned","29 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 2 days ago"]},"identity":{"score":6,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"@murzirius/vps-guardian-mcp","version":"0.21.0","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":0,"publishedAt":"2026-09-17T18:04:15.940Z","repositoryUrl":"git+https://github.com/murzirius/VPS-Guardian-MCP.git"},{"registryType":"pypi","identifier":"vps-guardian-mcp","version":"0.21.0","found":true,"license":"MIT","dependencyCount":7,"publishedAt":"2026-09-17T18:03:33.116984Z","repositoryUrl":"https://github.com/murzirius/VPS-Guardian-MCP"}],"repo":{"found":true,"owner":"murzirius","repo":"VPS-Guardian-MCP","archived":false,"pushedAt":"2026-09-17T18:02:58Z","stars":0,"forks":0,"openIssues":0,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/267067278?v=4","ownerCreatedAt":"2026-03-10T14:34:59Z","license":"MIT"},"icon":{"url":"https://avatars.githubusercontent.com/u/267067278?v=4&s=128","source":"registry"},"presence":{"stars":0,"forks":0,"downloadsWeek":674,"license":"MIT","lastPushAt":"2026-09-17T18:02:58.000Z","score":29}}}},"grade_history":[{"kind":"restore","fromGrade":"B","toGrade":"A","reason":"score 89","createdAt":"2026-09-19T21:08:28.848Z"},{"kind":"restore","fromGrade":"C","toGrade":"B","reason":"score 76: Whole environment serialized (possible credential exfil)","createdAt":"2026-09-18T00:15:57.069Z"}],"reviews":[]}