---
title: Linux MCP Daemon Provides Secure Root Access Through Kernel First Tools
url: https://www.dataloco.com/en/linux-mcp-daemon-provides-secure-root-access-through-kernel-first-tools
published: 2026-09-29T13:27:23+00:00
language: en
section: Cloud
source: https://habr.com/ru/articles/1086976/?utm_campaign=1086976&utm_source=habrahabr&utm_medium=rss
organizations: linux, mcp, mcpd, daemon, ssh, sudo
publisher: Dataloco
---

# Linux MCP Daemon Provides Secure Root Access Through Kernel First Tools

The article describes a new Linux MCP daemon that lets an AI agent interact with a server without exposing SSH or sudo. The author wanted the agent to see the operating system as a tree of objects such as processes disks and services and to use commands like get and describe. To achieve this the author built linuxctl and the mcpd daemon. The daemon runs as a single static binary written in Go. It exposes 38 tools named with groups such as processes top disks usage files read and services manage. Each tool has a description and a JSON schema that the agent can read. The daemon does not run commands directly. Instead it launches a short lived worker process for every call.

The worker runs under the same Linux user name as the caller and receives only the arguments that the tool requires. If the caller needs privileged access the configuration file lists the exact tools that may be executed as root and the paths that are allowed. By default mcpd uses TLS and generates a self signed certificate on first start. The client trusts the server by the certificate fingerprint. The author tested existing MCP solutions and found three categories. Some use remote shell over MCP and rely on a whitelist that only checks the first word of a command. Others only allow read access and still require an SSH key for the whole account.

Direct SSH with sudo gives the agent full root rights. None of these met the author's need for fine grained control and auditability. The new daemon solves this by separating each tool call into its own process and by allowing root only for explicitly permitted tools. The author also notes a security issue with stdio based MCP clients that can be tricked into launching arbitrary code. The mcpd daemon avoids that problem by never launching a server from a client config. The project is presented as a way to let an AI agent manage a fleet of servers safely and transparently.

## This story in other languages

- [Français](https://www.dataloco.com/fr/nouveau-demon-mcpd-pour-la-gestion-securisee-des-serveurs-linux)
