SysKnife icon

SysKnife

Linux sysadmin co-pilot as an MCP server for Codex: plain-language requests become typed, risk-classified actions that a privileged daemon runs only after out-of-band terminal approval, with an Ed25519-signed audit chain and automatic rollback.

lacs-project/sysknife · v0.25.0 · Tools & Integrations

LACS ProjectOwner verifiedcaution

Trust Score

60

Security

59

Surfaces

1

What is SysKnife?

SysKnife is a published tools & integrations plugin for AI coding agents in the mcp ecosystem, developed by LACS Project and distributed through the HOL AI plugin registry. Linux sysadmin co-pilot as an MCP server for Codex: plain-language requests become typed, risk-classified actions that a privileged daemon runs only after out-of-band terminal approval, with an Ed25519-signed audit chain and automatic rollback.

Canonical slug
lacs-project/sysknife
Version
v0.25.0 · updated Oct 8, 2026

Trust & Reputation

HOL Trust Score
60

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
64pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
59pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
caution
Digest verified
Yes

Trust & reputation

Trust & Reputation

HOL Trust Score
60

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
64pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
59pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
.
Source repo
https://github.com/lacs-project/sysknife
Source commit
ca8f4ca5d7bf…
Publisher verified
No
Owner verified
@vladimirrott

Continuous scanner CI not detected

This plugin remains listed. Its overall trust score is reduced by 10% because security checks are not maintained in the source repository's CI.

Optional: maintain the scanner in the source repository's CI to receive the full trust score. Listing does not require that change.

Verified badge not detected

Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.

Security Posture

caution
Safety label
59
Security score
0
High findings
Provider
registry-broker-fallback
Grade
F · caution
Version
Unknown
cisco-skill-scanner: not_applicable

Findings

mediumpublishabilitypublishability.link.missing.websiteURL

websiteURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.privacyPolicyURL

privacyPolicyURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.termsOfServiceURL

termsOfServiceURL should be present for marketplace readiness.

lowoperational-securitysupply-chain.lockfile-missing

Repository snapshot does not include a lockfile.

SysKnife — Frequently asked questions

What is SysKnife?
SysKnife is an AI plugin in the HOL registry. Linux sysadmin co-pilot as an MCP server for Codex: plain-language requests become typed, risk-classified actions that a privileged daemon runs only after out-of-band terminal approval, with an Ed25519-signed audit chain and automatic rollback.
How do I install SysKnife?
Install SysKnife in your harness: Codex — codex plugin marketplace add lacs-project/sysknife; MCP — git clone https://github.com/lacs-project/sysknife. Full step-by-step guidance is on the HOL plugin page.
How do I install SysKnife in Codex?
To install SysKnife in Codex, start with codex plugin marketplace add lacs-project/sysknife. The complete step-by-step install guide for Codex is on the HOL plugin page.
How do I install SysKnife in MCP?
To install SysKnife in MCP, start with git clone https://github.com/lacs-project/sysknife. The complete step-by-step install guide for MCP is on the HOL plugin page.
Is SysKnife free?
Pricing for SysKnife is published on its HOL plugin page when the maker schedules a launch.
Who publishes SysKnife?
SysKnife is published by LACS Project and listed on HOL.
Is SysKnife available now?
SysKnife availability is listed on its HOL plugin page.

Install Guidance

Install in Codex

Install through the Codex CLI plugin marketplace.

Codex plugin docs
  1. 1

    Register the marketplace

    Run in any terminal. Codex reads the marketplace entry from .agents/plugins/marketplace.json (or the legacy .claude-plugin path) in the repository. If the repository ships none, add the generated entry from the Advanced section below first.

    shell
  2. 2

    Install from the Plugins browser

    Open Codex, open the Plugins browser, choose the sysknife marketplace, and install sysknife.

  3. 3

    Verify the marketplace registration

    shell

Plugin Manifest

{
  "name": "sysknife",
  "version": "0.25.0",
  "description": "Linux sysadmin co-pilot as an MCP server: plain-language requests become typed, risk-classified actions that a privileged daemon runs only after out-of-band terminal approval, with an Ed25519-signed audit chain and automatic rollback.",
  "repository": "https://github.com/lacs-project/sysknife",
  "homepage": "https://lacs-project.github.io/sysknife/",
  "author": {
    "name": "LACS Project",
    "url": "https://github.com/lacs-project"
  },
  "license": "MIT",
  "keywords": [
    "linux",
    "sysadmin",
    "mcp",
    "codex",
    "audit",
    "approval",
    "devops"
  ],
  "interface": {
    "displayName": "SysKnife",
    "developerName": "LACS Project",
    "shortDescription": "Run Linux admin tasks from Codex behind a typed approval gate",
    "longDescription": "SysKnife turns a plain-language request into a plan of typed, risk-classified actions. Nothing executes on the model's word: the privileged daemon is the only component that runs anything, it refuses any action outside its catalogue, and medium- and high-risk steps require a single-use approval receipt minted out-of-band by a human running `sysknife approve` in a terminal. Every authorisation decision, and every approval grant, consumption and revocation, is recorded in Ed25519-signed forward hash chains that a third party can verify with only the exported public key. Failed system updates roll back automatically on atomic-host distros.",
    "category": "DevOps",
    "capabilities": [
      "Read",
      "Write"
    ],
    "defaultPrompt": [
      "What is using disk space on this machine?",
      "Install ripgrep",
      "Show me what SysKnife has run recently",
      "Verify the audit chain"
    ],
    "brandColor": "#FF6B1A",
    "composerIcon": "./assets/raster/sysknife-256.png",
    "logo": "./assets/logo/sysknife.svg"
  },
  "mcpServers": "./.registry/mcp.json",
  "holManifestOrigin": "repository",
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/lacs-project/sysknife
Marketplace path
Unknown
Source path
plugins/lacs-project/sysknife
Install policy
AVAILABLE

File Inventory

.codex-plugin/mcp.json

file

108 bytes

abdd00fab8679f07…

.codex-plugin/plugin.json

plugin-manifest

1,781 bytes

50b635fa909d23bc…

.registry/mcp.json

mcp-config

72 bytes

68b5794434ae45ed…

assets/logo/sysknife.svg

asset

6,065 bytes

4db044a6874997bb…

assets/raster/sysknife-256.png

asset

21,632 bytes

7179ab4800fddbd8…

CLAUDE.md

file

10,287 bytes

c8a4798d635b8793…

README.md

file

24,249 bytes

baa3ae1a6054e601…

SECURITY.md

file

28,662 bytes

4af8cd2c227f2ac0…