MCPLow riskUnclaimed

kvm-pilot

Smart hands for your AI agents - write-capable KVM+BMC+SSH MCP server: gated, verified, audited.

DustinTrapdustintrap/kvm-pilot★ 7Updated Aug 30, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-09-29/server.schema.json",
  "name": "io.github.DustinTrap/kvm-pilot",
  "description": "Smart hands for your AI agents - write-capable KVM+BMC+SSH MCP server: gated, verified, audited.",
  "repository": {
    "url": "https://github.com/DustinTrap/kvm-pilot",
    "source": "github"
  },
  "version": "0.1.0rc4",
  "packages": [
    {
      "registryType": "pypi",
      "registryBaseUrl": "https://pypi.org",
      "identifier": "kvm-pilot",
      "version": "0.1.0rc4",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Profile name from ~/.config/kvm-pilot/config.toml naming the KVM/BMC to target",
          "name": "KVM_PILOT_PROFILE"
        },
        {
          "description": "Least-privilege posture: only read-only tools are registered; effect gates force-closed. Recommended for first contact (set to 1)",
          "name": "KVM_PILOT_MCP_READ_ONLY"
        },
        {
          "description": "Rehearsal posture: destructive calls are logged, never sent (set to 1)",
          "name": "KVM_PILOT_MCP_DRY_RUN"
        },
        {
          "description": "Operator opt-in enabling power control of the managed host (per-effect gate; see also _ALLOW_HID, _ALLOW_MEDIA, _ALLOW_SSH, _ALLOW_APPLIANCE, _ALLOW_EXTERNAL_WRITE)",
          "name": "KVM_PILOT_MCP_ALLOW_POWER"
        },
        {
          "description": "Device address (KVM/BMC) when not using a config-file profile",
          "name": "KVM_PILOT_HOST"
        },
        {
          "description": "Device username when not using a config-file profile",
          "name": "KVM_PILOT_USER"
        },
        {
          "description": "Device password when not using a config-file profile (KVM_PILOT_HOST / KVM_PILOT_USER accompany it)",
          "isSecret": true,
          "name": "KVM_PILOT_PASSWD"
        },
        {
          "description": "Optional: enables server-side vision for classify_screen / wait_for_state; without it, classification falls back to the calling agent",
          "isSecret": true,
          "name": "ANTHROPIC_API_KEY"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—python
Installs—pypi:kvm-pilot@0.1.0rc4
Runs install scripts—None
NetworkNoneNone
Needs credentialsANTHROPIC_API_KEYKVM_PILOT_PASSWDANTHROPIC_API_KEYKVM_PILOT_PASSWD
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.1.0rc4latestOct 7, 2026