MCP Security Kit by Agent Trust Cloud

medium

MCP server launched through a shell

The command is bash, sh, cmd, powershell or similar, with the real server started from a shell string.

Why it matters

A shell makes it easy for arguments or environment values to run extra commands, and hides what actually executes.

How to fix it

Call the server's executable directly with an argument list.

Before

{
  "mcpServers": {
    "db": {
      "command": "bash",
      "args": [
        "-c",
        "cd ~/db && node server.js"
      ]
    }
  }
}

After

{
  "mcpServers": {
    "db": {
      "command": "node",
      "args": [
        "/home/alex/db/server.js"
      ]
    }
  }
}

Illustrative configs. The checker flags the “before” version with this finding and not the “after” version.

Check your own config

Other checks