No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by thuanpham582002 · MCP Server · ★ 85
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is tabby-mcp-server safe to install? View the security audit →
Tabby MCP Server A Tabby Terminal plugin that exposes your active terminal sessions through the Model Context Protocol (MCP). It lets MCP-compatible AI clients discover terminal tabs, execute commands, read terminal buffers, and retrieve long command output. Tabby stays the terminal UI. Your AI client connects to Tabby through MCP. Highlights MCP server inside Tabby — exposes an SSE endpoint at Terminal session discovery — list local and SSH-backed Tabby terminal sessions Command execution — run commands in a selected Tabby terminal tab Robust output capture — simple marker protocol with exit-code parsing Terminal buffer access — read visible/history buffer ranges from a tab Long output pagination — retrieve full command output by Pair programming mode — optional confirmation dialogs and user feedback
| Stars | 85 |
| Forks | 12 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 76.8791779979667/100 |
| Open Issues | 1 |
| Last Updated | 2026-08-18 |
| Created | 2025-04-08 |
| Platforms | mcp, node |
| Est. Tokens | ~15k |
These tools work well together with tabby-mcp-server for enhanced workflows:
Explore other popular mcp server tools:
tabby-mcp-server is MCP server for control Tabby terminal. It is categorized as a MCP Server with 85 GitHub stars.
tabby-mcp-server is primarily written in TypeScript.
You can find installation instructions and usage details in the tabby-mcp-server GitHub repository at github.com/thuanpham582002/tabby-mcp-server. The project has 85 stars and 12 forks, indicating an active community.
tabby-mcp-server is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: