websiteURL should be present for marketplace readiness.

SysKnife
Linux sysadmin co-pilot as an MCP server for Codex: plain-language requests become typed, risk-classified actions that a privileged daemon runs only after out-of-band terminal approval, with an Ed25519-signed audit chain and automatic rollback.
lacs-project/sysknife · v0.25.0 · Tools & Integrations
Trust Score
60
Security
59
Surfaces
1
What is SysKnife?
SysKnife is a published tools & integrations plugin for AI coding agents in the mcp ecosystem, developed by LACS Project and distributed through the HOL AI plugin registry. Linux sysadmin co-pilot as an MCP server for Codex: plain-language requests become typed, risk-classified actions that a privileged daemon runs only after out-of-band terminal approval, with an Ed25519-signed audit chain and automatic rollback.
- Canonical slug
- lacs-project/sysknife
- Version
- v0.25.0 · updated Oct 8, 2026
- Open data
- entity.json (JSON-LD)
Trust & Reputation
Factor Analysis
Per-metric points (0–100 each) combined via a weighted average into the overall score.
Registry Snapshot
- Repository
- https://github.com/lacs-project/sysknife
- Canonical profile
- https://hol.org/registry/plugins/lacs-project%2Fsysknife
- Publisher verification
- No
- Marketplace source
- Unknown
- Scanner
- Broker fallback
- Safety label
- caution
- Digest verified
- Yes
Trust & reputation
Trust & Reputation
Factor Analysis
Per-metric points (0–100 each) combined via a weighted average into the overall score.
Provenance
- Plugin root
- .
- Source repo
- https://github.com/lacs-project/sysknife
- Source commit
- ca8f4ca5d7bf…
- Publisher verified
- No
- Owner verified
- @vladimirrott
Continuous scanner CI not detected
This plugin remains listed. Its overall trust score is reduced by 10% because security checks are not maintained in the source repository's CI.
Optional: maintain the scanner in the source repository's CI to receive the full trust score. Listing does not require that change.
Verified badge not detected
Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.
Security Posture
- Provider
- registry-broker-fallback
- Grade
- F · caution
- Version
- Unknown
Findings
privacyPolicyURL should be present for marketplace readiness.
termsOfServiceURL should be present for marketplace readiness.
Repository snapshot does not include a lockfile.
SysKnife — Frequently asked questions
- What is SysKnife?
- SysKnife is an AI plugin in the HOL registry. Linux sysadmin co-pilot as an MCP server for Codex: plain-language requests become typed, risk-classified actions that a privileged daemon runs only after out-of-band terminal approval, with an Ed25519-signed audit chain and automatic rollback.
- How do I install SysKnife?
- Install SysKnife in your harness: Codex — codex plugin marketplace add lacs-project/sysknife; MCP — git clone https://github.com/lacs-project/sysknife. Full step-by-step guidance is on the HOL plugin page.
- How do I install SysKnife in Codex?
- To install SysKnife in Codex, start with codex plugin marketplace add lacs-project/sysknife. The complete step-by-step install guide for Codex is on the HOL plugin page.
- How do I install SysKnife in MCP?
- To install SysKnife in MCP, start with git clone https://github.com/lacs-project/sysknife. The complete step-by-step install guide for MCP is on the HOL plugin page.
- Is SysKnife free?
- Pricing for SysKnife is published on its HOL plugin page when the maker schedules a launch.
- Who publishes SysKnife?
- SysKnife is published by LACS Project and listed on HOL.
- Is SysKnife available now?
- SysKnife availability is listed on its HOL plugin page.
Install Guidance
Install in Codex
Install through the Codex CLI plugin marketplace.
- 1
Register the marketplace
Run in any terminal. Codex reads the marketplace entry from .agents/plugins/marketplace.json (or the legacy .claude-plugin path) in the repository. If the repository ships none, add the generated entry from the Advanced section below first.
shell - 2
Install from the Plugins browser
Open Codex, open the Plugins browser, choose the sysknife marketplace, and install sysknife.
- 3
Verify the marketplace registration
shell
Plugin Manifest
{
"name": "sysknife",
"version": "0.25.0",
"description": "Linux sysadmin co-pilot as an MCP server: plain-language requests become typed, risk-classified actions that a privileged daemon runs only after out-of-band terminal approval, with an Ed25519-signed audit chain and automatic rollback.",
"repository": "https://github.com/lacs-project/sysknife",
"homepage": "https://lacs-project.github.io/sysknife/",
"author": {
"name": "LACS Project",
"url": "https://github.com/lacs-project"
},
"license": "MIT",
"keywords": [
"linux",
"sysadmin",
"mcp",
"codex",
"audit",
"approval",
"devops"
],
"interface": {
"displayName": "SysKnife",
"developerName": "LACS Project",
"shortDescription": "Run Linux admin tasks from Codex behind a typed approval gate",
"longDescription": "SysKnife turns a plain-language request into a plan of typed, risk-classified actions. Nothing executes on the model's word: the privileged daemon is the only component that runs anything, it refuses any action outside its catalogue, and medium- and high-risk steps require a single-use approval receipt minted out-of-band by a human running `sysknife approve` in a terminal. Every authorisation decision, and every approval grant, consumption and revocation, is recorded in Ed25519-signed forward hash chains that a third party can verify with only the exported public key. Failed system updates roll back automatically on atomic-host distros.",
"category": "DevOps",
"capabilities": [
"Read",
"Write"
],
"defaultPrompt": [
"What is using disk space on this machine?",
"Install ripgrep",
"Show me what SysKnife has run recently",
"Verify the audit chain"
],
"brandColor": "#FF6B1A",
"composerIcon": "./assets/raster/sysknife-256.png",
"logo": "./assets/logo/sysknife.svg"
},
"mcpServers": "./.registry/mcp.json",
"holManifestOrigin": "repository",
"registryIndexVersion": 5
}Marketplace Source
- Repo URL
- https://github.com/lacs-project/sysknife
- Marketplace path
- Unknown
- Source path
- plugins/lacs-project/sysknife
- Install policy
- AVAILABLE
File Inventory
.codex-plugin/mcp.json
file
108 bytes
abdd00fab8679f07…
.codex-plugin/plugin.json
plugin-manifest
1,781 bytes
50b635fa909d23bc…
.registry/mcp.json
mcp-config
72 bytes
68b5794434ae45ed…
assets/logo/sysknife.svg
asset
6,065 bytes
4db044a6874997bb…
assets/raster/sysknife-256.png
asset
21,632 bytes
7179ab4800fddbd8…
CLAUDE.md
file
10,287 bytes
c8a4798d635b8793…
README.md
file
24,249 bytes
baa3ae1a6054e601…
SECURITY.md
file
28,662 bytes
4af8cd2c227f2ac0…