MCP server to monitor and manage remote Linux servers via SSH. 63 tools: health checks, log search, APM, SLOs, anomaly detection, auto-remediation, live dashboard, CIS benchmarks, CVE scanning, database monitoring, compliance reports, team RBAC, PagerDuty/Telegram/OpsGenie.
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"server-guardian-mcp","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# Server Guardian MCP The most comprehensive server management MCP ever built. **63 tools**, **8 connection types**, **16 modules** — log search, access log APM, SLO tracking, anomaly detection, auto-remediation playbooks, CIS benchmarks, CVE scanning, database monitoring, network monitoring, file integrity, live web dashboard, compliance reports, public status pages, team RBAC, PagerDuty/Telegram/OpsGenie — all through Claude. No agents. Just SSH. > **"The AI SRE that lives in your terminal. SSH into any server, diagnose any problem, fix it automatically — all through a conversation with Claude. No agents. No SaaS bills. No PromQL."** ## Live Dashboard ```bash python -m server_guardian_mcp dashboard # start on port 8080 python -m server_guardian_mcp dashboard --port 9090 ``` Real-time web UI with auto-refresh every 30 seconds. Dark theme, Chart.js charts for CPU/memory/disk trends, active alerts feed, incident timeline. ## Why Server Guardian? | What you say to Claude | What happens | |------------------------|-------------| | "Is my server okay?" | SSH in, check CPU/RAM/disk/temp, detect anomalies vs baseline | | "Why is production slow?" | Check processes, disk, logs, access log APM, identify the bottleneck | | "Search logs for OOM errors" | Index logs in SQLite, search with pattern detection, show error rates | | "Show me endpoint latency" | Parse nginx access logs — p50/p95/p99 latency, error rates, slowest endpoints | | "Are we meeting our SLOs?" | Track uptime/latency/error targets, calculate error budget remaining | | "What happened overnight?" | Generate incident narrative from alerts, service events, playbook runs | | "Fix it automatically" | Run playbooks: clear disk, restart services, renew SSL certs | | "Run a security audit" | 61 CIS benchmark checks + CVE scan + rootkit detection + FIM | | "Generate a compliance report" | Branded HTML report with score (A-F) for SOC2/ISO prep | | "How's the database?" | Slow query analysis, connectio…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.