AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

Remotepower

mcp-tyxak-remotepower · by tyxak

Server management dashboard, CVE-scanner, patch-mangement, SNMP-polling, monitoring, MCP-server, drift-detection, Proxmox. Basically a swiss-knife! AIO.

No reviews yet
0 installs
14 views
0.0% view→install

Install

$ agentstack add mcp-tyxak-remotepower

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-tyxak-remotepower)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Remotepower? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

RemotePower

The all-in-one, Swiss-army-knife control plane for your Linux fleet — and your homelab. Monitoring with alerting, a CMDB, documentation with RAG search, CVE scanning, patching and remote management in one self-hosted place — with AI woven through all of it (optional). Web dashboard, push-based agents, no inbound ports. Set it up in five minutes.

[](LICENSE) [](https://kernel.org) [](docs/install.md#docker-one-liner-alternative) [](https://nginx.org) [](https://python.org) [](https://github.com/tyxak/remotepower/releases) [](https://github.com/tyxak/remotepower/wiki) [](https://github.com/tyxak/remotepower/discussions)

Live demo · [Install](docs/install.md) · [Features](docs/features.md) · Wiki · Discussions · [The story](HISTORY.md)

Click-through gallery — more screenshots

Dashboard Device drawer

Browser SSH terminal Monitoring

Device metrics Logs

CVEs Patches

Custom scripts Software center & policy

Release signing CMDB

IaC generator Settings

AI assistant Claude (AI host integration)

Tickets (helpdesk) WG Access — tunnels

WG Access — client config & QR


What is it?

One tool instead of six. Most teams stitch together a monitor, a CMDB, a wiki, a vulnerability scanner, a patch tool and an SSH jump box. RemotePower is the Swiss-army-knife that does all of it from a single host you control — monitoring & alerting, an asset CMDB, documentation with RAG search over your own fleet, CVE scanning, patching, and remote management — and it's heavily bound to AI as an option: bring your own model (local Ollama/LocalAI or a cloud provider) and ask questions answered from your infrastructure, or leave it off entirely. Everything stays self-hosted.

A web dashboard that manages your Linux machines (and Windows, kind of) without opening firewall ports on them. Each host runs a small Python agent that polls the central server every 60 seconds — outbound HTTPS only. Enrolment is a 6-digit PIN, like pairing a console controller.

Deliberately small and readable: nginx + Python CGI + flat JSON files — around ~67,000 lines of server Python, one HTML file, one CSS file and a handful of vanilla JS files. No external database, no Node.js, no Redis, no Kubernetes, no build step, no bundler, no framework — you can read every line. The whole /var/lib/remotepower/ directory backs up with tar. Tested on real homelabs running 5–50 devices, fine up to a few hundred — and for larger or write-heavy fleets you can switch to an optional embedded SQLite backend, or scale all the way to PostgreSQL (failover + read replicas), load-balanced app nodes and relay satellites for segmented networks. That's an advanced, heavy-fleet track — most installs never touch it. See [docs/scaling.md](docs/scaling.md).

Quick start

Server — one command, HTTPS out of the box:

# Docker (recommended). Self-signed HTTPS on first boot; the one-time admin
# password is printed to `docker logs remotepower`.
docker compose up -d

# Or bare-metal: a single wizard installs nginx + the app + TLS + admin.
# You never edit an nginx file — it writes the vhost and certificate for you.
git clone https://github.com/tyxak/remotepower && cd remotepower
sudo bash install.sh

Open the printed URL and log in. HTTPS is automatic — a self-signed CA by default (agents pin it), or a real Let's Encrypt cert when you give a public domain. No cert wrangling, no nginx editing.

Add a device — one line, nothing to configure:

In the dashboard, Add device → Quick install command, then on the target host:

wget -qO- "https://your-server/install?t=" | sudo sh

It downloads the signed agent, verifies its checksum, enrols with the baked one-time token, and the host appears in the dashboard by its hostname within ~60 seconds. Prefer Docker? Add device → Generate Docker compose. Onboarding many hosts? Push the installer over SSH: install.sh agent push user@h1 user@h2 ….

Uninstall: sudo bash install.sh uninstall (server — keeps your data; --purge to wipe it) · wget -qO- https://your-server/install | sudo sh -s -- --uninstall (agent).

For longer paths (Windows client, demo vhost, Ansible, advanced TLS), see [docs/install.md](docs/install.md).

Try the live demo

A read-only demo deployment runs at ** — seeded with synthetic devices, alerts, CVE findings, and metrics so you can poke around without installing anything. Login: demo / demo** (reset every few hours, so feel free to break things).

What you can do with it

One tool instead of six — the ten things it does best:

| | | |---|---| | Monitor everything | Live 60-second metrics, a CheckMK-style per-host Checks page, active monitors (HTTP / DNS / ICMP / TCP + credential-less DB liveness), and a composable dashboard. Every fired event lands in an Alerts inbox with acknowledge / auto-resolve. | | See every signal | SMART & hardware health, GPU (NVIDIA + AMD, trend sparklines + thermal alerts), power / UPS, disk-fill forecasting, a per-host timeline, and logs with regex search — telemetry the agent already reports, surfaced as first-class views. | | Manage remotely | Shell, multi-line scripts with dry-run lint, batch & scheduled runs, a real browser SSH terminal and VNC over the same tunnel, an opt-in agent file manager (browse / view / edit host files, no SSH), cron & systemd-timer management, Proxmox VM / LXC create, and host user / key / firewall edits — all with zero inbound ports. | | Lock it down | Passkeys / WebAuthn, SAML / OIDC / LDAP, TOTP + recovery codes, per-role MFA enforcement, a tamper-evident (hash-chained) audit log, strict CSP, and SSRF-guarded outbound calls. | | Scan for CVEs | OSV.dev-backed, CVSS-scored, prioritized by CISA KEV + EPSS (exploited-in-the-wild first), with SBOM export (CycloneDX / SPDX, VEX-style vulnerabilities embedded). | | Pentest what you own | Authorized vulnerability scanning of your own hosts & domains — nuclei / nikto / nmap / OWASP ZAP / wapiti / lynis — on a hardened scanner satellite, authorization-gated and schedulable. | | CMDB + RAG search | Asset DB, encrypted credentials vault, Markdown docs per asset, network map — and an AI assistant whose RAG answers from your fleet and docs and cites the source (local or cloud model; off by default). | | Stay compliant | OpenSCAP CIS / STIG / PCI scans with downloadable HTML reports, plus PCI / HIPAA / SOC 2 control mapping and scheduled posture reports. | | Integrate | 26 homelab-app health connectors (Pi-hole, TrueNAS, the *arr suite, …) plus a code-free custom HTTP-probe plugin to turn any endpoint into a signal, Prometheus / Grafana / Uptime-Kuma endpoints, inbound webhooks & syslog, and an MCP server so an AI client can query your fleet. | | Deploy & automate | An app catalog — one-click Docker Compose deploy of curated (or your own custom) self-contained apps to a host — auto-patch policies (cron, per group / tag / site, maintenance-aware), config-drift detection, ACME / Let's Encrypt, backup orchestration, and an IaC generator (Terraform / Ansible / Pulumi / …). |

Full feature inventory → [docs/features.md](docs/features.md).

Recent releases

  • v5.3.0 — ResolveMatters — a built-in, opt-in ticket system (helpdesk) that turns alerts into owned, tracked, resolvable work: tickets typed Incident / Request / Change with P1–P4 priorities and per-priority SLA targets, ownership / teams / groups, master & sub-tickets, alert → ticket → auto-resolve, inbound-mail auto-create + reply threading (dedicated IMAP) and outbound via your SMTP with an HTML signature. Plus an internal Contacts directory, a tickets AI/RAG source + Helpdesk-triage advisor, and a whole-project security / performance / consistency sweep. No breaking changes.
  • v5.2.0 — AccessMattersWG Access, a built-in light WireGuard road-warrior VPN (Admin → WG Access): reach the dashboard and fleet over an encrypted tunnel instead of exposing services. Create tunnels with a reach scope (dashboard-only / entire fleet / site / group / tag), full- or split-tunnel egress and optional auto-expiry, then issue per-client .conf + QR configs whose keys are generated in your browser (the private key never leaves it). Connect/disconnect/stale-handshake are first-class events, and WG Access posture feeds the AI (a new Remote-access review advisor). No breaking changes.
  • v5.1.1 — ClusterMatters — the Proxmox integration now lists guests across the whole cluster (resolving each guest's owning node so every lifecycle action targets the right host), the page you're on is restored from the URL hash on refresh, LocalAI API keys are accepted, and embeddings can run on a different service than chat (a separate provider / base URL / API key). Folds in community contributions from @tbouquet and @loryanstrant. No breaking changes.
  • v5.1.0 — UnityMatters — fail2ban bans become a first-class alert/webhook event (the jail and banned IPs ride the payload, and repeat bans on a host coalesce into one live alert), Arabic gains a full right-to-left layout, and another batch of UI strings are localized — on top of the usual security and correctness finalize sweep. No breaking changes.
  • v5.0.1 — TemperMatters — a stability and polish release that tempers v5.0: it fixes a class of bugs that silently broke features on the SQLite / PostgreSQL backend (SSH-key drift audit, Proxmox snapshot alerts, host-config view), coalesces duplicate alerts into a single entry, makes agent stop / start quiet by default, and adds Edit buttons for API keys and custom checks — on top of a whole-project security and correctness finalize sweep. No breaking changes.

Full release history, newest first → [CHANGELOG.md](CHANGELOG.md).

Security

RemotePower is security-reviewed every few releases and independently pentested clean — the latest full run (Bandit SAST; OWASP ZAP, Nikto, Nuclei, Wapiti, WhatWeb DAST) reported no exploitable findings. Posture in brief: bcrypt (cost 12, PBKDF2-HMAC-SHA256 fallback) behind rate-limited login; TOTP 2FA with recovery codes; passkeys / SAML / OIDC / LDAP; 256-bit header session tokens (CSRF-safe by construction); a strict CSP with no 'unsafe-inline'; an AES-GCM CMDB vault; a tamper-evident audit log; and mandatory TLS verification plus connect-time anti-DNS-rebinding on every outbound call. Full posture, threat model, review history and an operator hardening checklist: [docs/security.md](docs/security.md).

Documentation

Browse the full docs in the Wiki (generated from docs/, organised by topic). Prefer the source? Everything lives in [docs/](docs/) — start with the index there. The essentials:

| Topic | Where | |---|---| | Install (Linux, Docker, demo, Windows) | [docs/install.md](docs/install.md) | | Full feature inventory | [docs/features.md](docs/features.md) | | Architecture + on-disk layout | [docs/architecture.md](docs/architecture.md) | | API reference (endpoints + OpenAPI) | [docs/api.md](docs/api.md) — interactive: /swagger.html | | Security notes | [docs/security.md](docs/security.md) | | Scaling & deployment | [docs/scaling.md](docs/scaling.md) | | Troubleshooting / Upgrading | [docs/troubleshooting.md](docs/troubleshooting.md) · [docs/upgrading.md](docs/upgrading.md) |

TL;DR

A self-hosted Swiss-army knife for your Linux fleet or homelab: monitoring, alerting, CMDB, docs with RAG, CVE scanning, authorized pentesting, patching, compliance, and full remote management (browser SSH, Proxmox, files) — push-based agents, zero inbound ports, optional local or cloud AI that answers from your hosts. One tool instead of six.

Contributing & community

  • Request a feature — open a Feature request; it's labelled enhancement and triaged from there.
  • Report a bug — open a Bug report.
  • Ask a question or float an idea — head to Discussions.
  • Found a security issue? — please report it privately per [SECURITY.md](SECURITY.md); don't open a public issue.
  • Contributing code or docs? — see [CONTRIBUTING.md](CONTRIBUTING.md).

License

MIT — see [LICENSE](LICENSE).

Made with care and vi

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.