{"name":"io.github.kastelldev/kastell","slug":"kastelldev-kastell","title":null,"description":"Server security audit (413 checks), hardening, and fleet management across 4 cloud providers.","url":"https://mcp.market/server/kastelldev-kastell","rating":null,"grade":"B","score":82,"certified":false,"status":"active","category":"security","tags":["security"],"presence":{"score":32,"stars":59,"forks":2,"downloads_week":null,"last_push_at":"2026-09-20T03:52:36.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/kastelldev/kastell","website":null,"version":"1.14.0","remotes":[],"packages":[{"registryType":"npm","identifier":"kastell","version":"1.14.0","transport":{"type":"stdio"},"environmentVariables":[{"description":"Hetzner Cloud API token (optional — only for Hetzner servers)","format":"string","isSecret":true,"name":"HETZNER_TOKEN"},{"description":"DigitalOcean API token (optional — only for DigitalOcean servers)","format":"string","isSecret":true,"name":"DIGITALOCEAN_TOKEN"},{"description":"Vultr API token (optional — only for Vultr servers)","format":"string","isSecret":true,"name":"VULTR_TOKEN"},{"description":"Linode API token (optional — only for Linode servers)","format":"string","isSecret":true,"name":"LINODE_TOKEN"}]}],"tools":[{"name":"server_audit","description":"Run a security audit on a Kastell-managed server. Scans 27 categories (SSH, Firewall, Updates, Auth, Docker, Network, Filesystem, Logging, Kernel, Accounts, Services, Boot, Scheduling, Time, Banners, Crypto, File Integrity, Malware, MAC, Memory, Secrets, Cloud Metadata, Supply Chain, Backup Hygiene, Resource Limits, Incident Readiness, DNS Security) with 413 checks. Returns overall score (0-100), ","write_action":true,"price_micros":0,"input_schema":null},{"name":"server_backup","description":"Backup and snapshot Kastell servers. Backup: 'backup-create' dumps Coolify DB + config via SSH (Coolify servers) or system config files (bare servers), 'backup-list' shows local backups, 'backup-restore' restores from backup — bare servers restore system config, Coolify servers restore DB+config (SAFE_MODE blocks restore). Snapshot: 'snapshot-create'/'snapshot-list'/'snapshot-delete' manage cloud ","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_doctor","description":"Run proactive health analysis on a server. Detects disk trending full, high swap, stale packages, elevated fail2ban bans, audit regression streaks, old backups, and reclaimable Docker space. Uses cached metrics by default — pass fresh=true to fetch live data via SSH. Returns findings grouped by severity (critical/warning/info) with remediation commands. For a full scored security audit across 27 c","write_action":true,"price_micros":0,"input_schema":null},{"name":"server_evidence","description":"Collect forensic evidence package from a server. Gathers firewall rules, auth.log, listening ports, system logs, and optionally Docker info. Writes to ~/.kastell/evidence/{server}/{date}/. Returns manifest with SHA256 checksums per file.","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_fleet","description":"Get fleet-wide health and security posture for all registered servers. Returns server name, IP, provider, health status (ONLINE/DEGRADED/OFFLINE), cached audit score, and SSH response time. Use sort parameter to order results. For per-server cloud status or available server sizes, use server_info instead.","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_guard","description":"Manage autonomous security monitoring daemon on a server. Actions: 'start' installs guard as remote cron (checks disk/RAM/CPU/audit every 5 min), 'stop' removes guard cron entry, 'status' shows whether guard is active with last check time and any threshold breaches. Requires SSH access to target server.","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_info","description":"Get information about Kastell-managed servers. Actions: 'list' all servers, 'status' check cloud provider + Coolify/bare status, 'health' check Coolify reachability or SSH access for bare servers, 'sizes' list available server types with prices for a provider+region. Requires provider API tokens as environment variables (HETZNER_TOKEN, DIGITALOCEAN_TOKEN, VULTR_TOKEN, LINODE_TOKEN) for status/size","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_lock","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_logs","description":"Fetch logs and system metrics from Kastell-managed servers via SSH. Actions: 'logs' retrieves recent log lines from Coolify container (Coolify servers only), Docker service, or system journal. Bare servers: use service 'system' or 'docker' (coolify service not available). 'monitor' fetches CPU, RAM, and disk usage metrics (works for all server modes). Requires SSH access to target server (root@ip)","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_maintain","description":"Maintain Kastell servers. Actions: 'update' runs Coolify update via SSH (Coolify servers only — bare servers are blocked), 'restart' reboots server via cloud provider API (works for both Coolify and bare servers), 'maintain' runs full 5-step maintenance (Coolify servers only — bare servers are blocked). Snapshot not included — use server_backup tool. Requires SSH access for update, provider API to","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_manage","description":"Manage Kastell servers. Actions: 'add' registers an existing Coolify or bare server to local config (validates API token, optionally verifies Coolify via SSH — pass mode:'bare' for servers without Coolify). 'remove' unregisters a server from local config only (cloud server keeps running). 'destroy' PERMANENTLY DELETES the server from the cloud provider and removes from local config. Requires provi","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_provision","description":"Provision a new server on a cloud provider. Default: Coolify auto-install via cloud-init. Pass mode:'bare' for a generic VPS without Coolify (installs UFW and runs system updates only). Requires provider API token as environment variable (HETZNER_TOKEN, DIGITALOCEAN_TOKEN, VULTR_TOKEN, LINODE_TOKEN). WARNING: Creates a billable cloud resource. Blocked when KASTELL_SAFE_MODE=true. Server takes 3-5 ","write_action":false,"price_micros":0,"input_schema":null},{"name":"server_secure","description":"Secure Kastell servers. Secure: 'secure-setup' applies SSH hardening + fail2ban, 'secure-audit' runs security audit with score. Firewall: 'firewall-setup' installs UFW with Coolify ports, 'firewall-add'/'firewall-remove' manage port rules, 'firewall-status' shows current rules. Domain: 'domain-set'/'domain-remove' manage custom domain with optional SSL, 'domain-check' verifies DNS, 'domain-info' s","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":82,"grade":"B","scanned_at":"2026-09-27T23:34:49.344Z","report":{"scannerVersion":"0.1.10","scannedAt":"2026-09-27T23:34:49.270Z","components":{"code":{"score":25,"max":25,"notes":["341 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 8 days ago"]},"identity":{"score":7,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"kastell","version":"1.14.0","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":10,"publishedAt":"2026-03-24T07:33:34.240Z","repositoryUrl":"git+https://github.com/kastelldev/kastell.git"}],"repo":{"found":true,"owner":"kastelldev","repo":"kastell","archived":false,"pushedAt":"2026-09-20T03:52:36Z","stars":59,"forks":2,"openIssues":19,"ownerType":"Organization","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/265485114?v=4","ownerCreatedAt":"2026-03-04T08:51:56Z","license":"Apache-2.0"},"icon":{"url":"https://avatars.githubusercontent.com/u/265485114?v=4&s=128","source":"github"},"presence":{"stars":59,"forks":2,"downloadsWeek":null,"license":"Apache-2.0","lastPushAt":"2026-09-20T03:52:36.000Z","score":32}}}},"grade_history":[],"reviews":[]}