Run commands and read/write files on your servers over Termalin's keyless tunnels (hosted MCP).
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://termal.in/api/v1/mcp8 tools · 569mshosts_listList the servers reachable through Termalin (your tunnel agents). Returns id, name, whether the server is online, and the default login user. Use the id with ssh_exec.List the servers reachable through Termalin (your tunnel agents). Returns id, name, whether the server is online, and the default login user. Use the id with ssh_exec.
No input schema was published for this tool.
generate_passwordGenerate a strong random password — handy when creating a user or setting a password on a server. Returns the password only; nothing is stored.Generate a strong random password — handy when creating a user or setting a password on a server. Returns the password only; nothing is stored.
| Parameter | Type | Description |
|---|---|---|
| length | integer | length (default 20, 8-128) |
ssh_execprivilegedRun a single shell command on one of your servers and return its combined output. Runs keyless over Termalin's tunnel — no SSH key, and the server needs no open inbound port.Run a single shell command on one of your servers and return its combined output. Runs keyless over Termalin's tunnel — no SSH key, and the server needs no open inbound port.
| Parameter | Type | Description |
|---|---|---|
| host* | string | Server id from hosts_list |
| command* | string | Shell command to execute |
| username | string | Login user (defaults to the tunnel's user, else root) |
| timeoutSeconds | number | Max seconds to wait (default 60, up to 300) |
sftp_listList a directory on one of your servers over SFTP. Returns each entry's name, whether it's a directory, size and modified time. Runs keyless over Termalin's tunnel, like ssh_exec.List a directory on one of your servers over SFTP. Returns each entry's name, whether it's a directory, size and modified time. Runs keyless over Termalin's tunnel, like ssh_exec.
| Parameter | Type | Description |
|---|---|---|
| host* | string | Server id from hosts_list |
| path | string | Directory to list (default the login home, ".") |
| username | string | Login user (defaults to the tunnel's user, else root) |
sftp_readRead a text file from one of your servers over SFTP and return its contents. Files over 512 KB or non-text (binary) files are refused — use ssh_exec (e.g. sed/tail) for those.Read a text file from one of your servers over SFTP and return its contents. Files over 512 KB or non-text (binary) files are refused — use ssh_exec (e.g. sed/tail) for those.
| Parameter | Type | Description |
|---|---|---|
| host* | string | Server id from hosts_list |
| path* | string | Absolute or home-relative file path |
| username | string | Login user (defaults to the tunnel's user, else root) |
sftp_writeprivilegedCreate or overwrite a text file on one of your servers over SFTP. 'content' is written as UTF-8. Capped at 512 KB; for binary uploads use a terminal/scp instead.Create or overwrite a text file on one of your servers over SFTP. 'content' is written as UTF-8. Capped at 512 KB; for binary uploads use a terminal/scp instead.
| Parameter | Type | Description |
|---|---|---|
| host* | string | Server id from hosts_list |
| path* | string | Destination file path (created or overwritten) |
| content* | string | UTF-8 text to write |
| username | string | Login user (defaults to the tunnel's user, else root) |
data_queryRun a database query on one of your servers — passwordless. It executes the engine's own client on the host over Termalin's keyless tunnel, using the database's local trust (Postgres peer auth via `sudo -u postgres`, MySQL/MariaDB unix-socket via `sudo mysql`, redis-cli, mongosh, sqlite3) — so no d…Run a database query on one of your servers — passwordless. It executes the engine's own client on the host over Termalin's keyless tunnel, using the database's local trust (Postgres peer auth via `sudo -u postgres`, MySQL/MariaDB unix-socket via `sudo mysql`, redis-cli, mongosh, sqlite3) — so no d…
| Parameter | Type | Description |
|---|---|---|
| host* | string | Server id from hosts_list |
| engine | string | Database engine on that server (default postgres) |
| query* | string | The statement / command / expression to run |
| database | string | Database name (for sqlite: the .db file path) |
| username | string | SSH login user (defaults to the tunnel's user, else root) |
| allowWrites | boolean | Allow a non-read statement (full-access keys only; default false) |
| timeoutSeconds | number | Max seconds to wait (default 60, up to 300) |
data_tablesList the tables / collections / keys of a database on one of your servers — passwordless, over the same local-client path as data_query.List the tables / collections / keys of a database on one of your servers — passwordless, over the same local-client path as data_query.
| Parameter | Type | Description |
|---|---|---|
| host* | string | Server id from hosts_list |
| engine | string | Database engine on that server (default postgres) |
| database | string | Database name (for sqlite: the .db file path) |
| username | string | SSH login user (defaults to the tunnel's user, else root) |
8 of 8 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Run commands and read/write files on your servers over Termalin's keyless tunnels (hosted MCP).
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.