Manage Apt Packages Securely
An MCP server that installs, removes, updates, and queries apt/dpkg packages on Linux via passwordless sudo.
Why it matters
Empower AI agents to securely manage Linux apt packages. This asset enables automated installation, removal, updates, and queries of packages via sudo operations.
Outcomes
What it gets done
Install, remove, and upgrade apt packages.
Query the status of apt packages.
Update the apt package list.
Securely execute package management tasks using passwordless sudo.
Install
Add it to your toolbox
Run in your project directory:
curl -fsSL https://spark.entire.vc/get/vb-apt-mcp | bash Capabilities
Tools your agent gets
Install one or more apt packages on the system
Remove one or more apt packages from the system
Check if a package is installed, available, or can be upgraded
Update the apt package list and upgrade all packages
List all packages available for upgrade
Upgrade a specific apt package to the latest version
Overview
APT MCP Server
An MCP server exposing six apt/dpkg tools for AI agents on Linux: install, remove, query status, update-all, list upgradable, and upgrade a specific package. Use it when an AI agent needs to manage Linux system packages directly - requires passwordless sudo and is not sandboxed.
What it does
This MCP server controls the apt package manager on Linux for AI agents. It exposes six tools built on the system's native apt and dpkg binaries: installAptPackage and removeAptPackage (operate on an array of package names), queryAptPackageStatus (reports installed/upgradable/available status for a package), updateAptPackages (runs apt update and upgrade for the whole system), listUpgradableAptPackages, and upgradeSpecificAptPackage. Every tool returns a consistent plain-text response with a result status, a summary line, and stdout/stderr/log detail. It assumes passwordless sudo is configured for all apt/dpkg operations, and runs over stdio transport by default for local AI agent integration (Cursor, Claude Desktop, Windsurf). Errors follow the same consistent format (Result: ERROR plus a summary) - common causes include an invalid package name, a package that doesn't exist in configured repositories, permission denied when passwordless sudo isn't set up, and an apt lock held by another process, which the server retries once automatically before surfacing the error.
When to use - and when NOT to
Use it when an AI agent needs to install, remove, update, or check the status of Linux system packages as part of an automated dev-environment or system-administration workflow. Because it requires passwordless sudo and executes real package-manager operations against the host system, only use it in environments where you accept that an agent can modify installed system packages - it is not sandboxed, and package removal/upgrade actions can affect other running software. The server ships configured for stdio transport (recommended for local agent use), though it can be adapted to HTTP/SSE transport for remote use; new tools are added by following the existing server.addTool pattern in src/index.ts.
Inputs and outputs
Inputs: a package name or array of package names (for install/remove/query/upgrade tools), or no parameters (for update-all and list-upgradable tools).
Outputs: a plain-text result with Result: SUCCESS or Result: ERROR, a one-line summary, and the underlying stdout/stderr from the apt/dpkg command.
const { Client } = require("@modelcontextprotocol/sdk/client");
const { StdioClientTransport } = require("@modelcontextprotocol/sdk/client/stdio");
const client = new Client({ name: "test-client", version: "1.0.0" });
const transport = new StdioClientTransport();
(async () => {
await client.connect(transport);
const result = await client.callTool("installAptPackage", { packages: ["curl"] });
console.log(result);
})();
How to install
git clone <your-repo-url>
cd popos-control-mcp
npm install
npm run build
npm run dev
Who it's for
Developers and AI-agent workflows on Linux (e.g. Cursor, Claude Desktop, Windsurf users) who want an agent to manage apt packages directly - installing dependencies, checking upgrade status, or keeping a dev machine's packages current - with passwordless sudo already configured. The project is released under the MIT License.
Source README
Apt MCP Server
A TypeScript-based Model Context Protocol (MCP) server for controlling the apt package manager on Linux. Designed for integration with AI agents (e.g., Cursor, Claude Desktop, Windsurf) and developer tools, it exposes tools for installing, removing, updating, and querying apt packages using the system's native apt and dpkg binaries with sudo privileges.
Features
- Install, remove, update, and query apt packages via MCP tools
- Secure, passwordless
sudoassumed for all operations - Input validation and robust error handling
- Consistent, human-readable output for all tools
- Designed for stdio transport (default for local AI agent integration)
Setup & Installation
- Clone the repository:
git clone <your-repo-url> cd popos-control-mcp - Install dependencies:
npm install - Build the project:
npm run build - Run the server (stdio transport):
npm run dev # or npm start
Note: The server assumes the user has passwordless
sudofor apt operations.
Tools & API Endpoints
All tools are exposed via MCP and can be called by AI agents or clients. Each tool returns a plain text response with a summary, stdout, stderr, and logs (if any).
1. installAptPackage
- Description: Install one or more apt packages.
- Parameters:
packages: array of package names (e.g.,["curl", "git"])
- Example Input:
{ "packages": ["curl"] } - Example Output:
Result: SUCCESS Summary: Apt install succeeded for: curl [stdout] ... [stderr] ...
2. removeAptPackage
- Description: Remove one or more apt packages.
- Parameters:
packages: array of package names
- Example Input:
{ "packages": ["curl"] } - Example Output:
Result: SUCCESS Summary: Apt remove succeeded for: curl [stdout] ... [stderr] ...
3. queryAptPackageStatus
- Description: Query if a package is installed, available, or upgradable.
- Parameters:
package: package name (string)
- Example Input:
{ "package": "curl" } - Example Output:
Result: SUCCESS Summary: Status for package curl: Installed=installed, Upgradable=false, Available=available [stdout] Package: curl Installed: installed Upgradable: no Available: available
4. updateAptPackages
- Description: Update the apt package list and upgrade all packages.
- Parameters: none
- Example Input:
{} - Example Output:
Result: SUCCESS Summary: Apt update and upgrade completed successfully. [stdout] apt update stdout: ... apt upgrade stdout: ... [stderr] ...
5. listUpgradableAptPackages
- Description: List all upgradable apt packages.
- Parameters: none
- Example Input:
{} - Example Output:
Result: SUCCESS Summary: Listed upgradable packages successfully. [stdout] ... [stderr] ...
6. upgradeSpecificAptPackage
- Description: Upgrade a specific apt package.
- Parameters:
package: package name (string)
- Example Input:
{ "package": "curl" } - Example Output:
Result: SUCCESS Summary: Apt only-upgrade succeeded for: curl [stdout] ... [stderr] ...
Example Usage
CLI (stdio transport)
You can test the server using the MCP CLI or by connecting with an AI agent (e.g., Cursor, Claude Desktop).
Node.js Example
const { Client } = require("@modelcontextprotocol/sdk/client");
const { StdioClientTransport } = require("@modelcontextprotocol/sdk/client/stdio");
const client = new Client({ name: "test-client", version: "1.0.0" });
const transport = new StdioClientTransport();
(async () => {
await client.connect(transport);
const result = await client.callTool("installAptPackage", { packages: ["curl"] });
console.log(result);
})();
Error Handling & Troubleshooting
- All errors are returned in a consistent format with
Result: ERRORand a summary. - Common error causes:
- Invalid package name: check spelling and allowed characters
- Package not found: ensure the package exists in your repositories
- Permission denied: ensure passwordless sudo is configured
- Apt lock: the server retries once automatically, but if the error persists, wait and try again
- Example error output:
Result: ERROR Summary: Apt install failed: E: Unable to locate package notarealpackage [stdout] ... [stderr] E: Unable to locate package notarealpackage
FAQ
Q: Does the server require passwordless sudo?
A: Yes, all apt/dpkg commands are run with sudo and assume no password prompt.
Q: What transport does the server use?
A: Stdio by default, for easy integration with local AI agents and tools.
Q: Can I use this server remotely?
A: You can adapt it to use HTTP/SSE transport, but stdio is recommended for local/agent use.
Q: How do I add new tools?
A: Add a new server.addTool block in src/index.ts following the existing pattern.
FAQ
Common questions
Discussion
Questions & comments · 0
Sign In Sign in to leave a comment.