Files
unraid-mcp/.claude-plugin
Jacob Magar 2b777be927 fix(security): path traversal, timing-safe auth, stale credential bindings
Security:
- Remove /mnt/ from _ALLOWED_LOG_PREFIXES to prevent Unraid share exposure
- Add early .. detection for disk/logs and live/log_tail path validation
- Add /boot/ prefix restriction for flash_backup source_path
- Use hmac.compare_digest for timing-safe API key verification in server.py
- Gate include_traceback on DEBUG log level (no tracebacks in production)

Correctness:
- Re-raise CredentialsNotConfiguredError in health check instead of swallowing
- Fix ups_device query (remove non-existent nominalPower/currentPower fields)

Best practices (BP-01, BP-05, BP-06):
- Add # noqa: ASYNC109 to timeout params in _handle_live and unraid()
- Fix start_array* → start_array in docstring (not in ARRAY_DESTRUCTIVE)
- Remove from __future__ import annotations from snapshot.py
- Replace import-time UNRAID_API_KEY/URL bindings with _settings.ATTR pattern
  in manager.py, snapshot.py, utils.py, diagnostics.py — fixes stale binding
  after apply_runtime_config() post-elicitation (BP-05)

CI/CD:
- Add .github/workflows/ci.yml (5-job pipeline: lint, typecheck, test, version-sync, audit)
- Add fail_under = 80 to [tool.coverage.report]
- Add version sync check to scripts/validate-marketplace.sh

Documentation:
- Sync plugin.json version 1.1.1 → 1.1.2 with pyproject.toml
- Update CLAUDE.md: 3 tools, system domain count 18, scripts comment fix
- Update README.md: 3 tools, security notes
- Update docs/AUTHENTICATION.md: H1 title fix
- Add UNRAID_CREDENTIALS_DIR to .env.example

Bump: 1.1.1 → 1.1.2

Co-Authored-By: Claude <noreply@anthropic.com>
2026-03-23 11:37:05 -04:00
..

Unraid MCP Marketplace

This directory contains the Claude Code marketplace configuration for the Unraid MCP server and skills.

Installation

# Add the marketplace
/plugin marketplace add jmagar/unraid-mcp

# Install the Unraid skill
/plugin install unraid @unraid-mcp

From Local Path (Development)

# Add local marketplace
/plugin marketplace add /path/to/unraid-mcp

# Install the plugin
/plugin install unraid @unraid-mcp

Available Plugins

unraid

Query and monitor Unraid servers via GraphQL API - array status, disk health, containers, VMs, system monitoring.

Features:

  • 1 consolidated unraid tool with ~108 actions across 15 domains
  • Real-time live subscriptions (CPU, memory, logs, array state, UPS)
  • Disk health and temperature monitoring
  • Docker container management
  • VM status and control
  • Log file access
  • Network share information
  • Notification management
  • Plugin, rclone, API key, and OIDC management

Version: 1.0.0 Category: Infrastructure Tags: unraid, monitoring, homelab, graphql, docker, virtualization

Configuration

After installation, run setup to configure credentials interactively:

unraid(action="health", subaction="setup")

Credentials are stored at ~/.unraid-mcp/.env automatically.

Getting an API Key:

  1. Open Unraid WebUI
  2. Go to Settings → Management Access → API Keys
  3. Click "Create" and select "Viewer" role (or appropriate roles for mutations)
  4. Copy the generated API key

Documentation

  • Plugin Documentation: See skills/unraid/README.md
  • MCP Server Documentation: See root README.md
  • API Reference: See skills/unraid/references/

Support