jark006/RemoteOps

Plugin插件 ⭐ 2 MIT Notifications & Remote通知与远程

RemoteOps 是一个面向远程系统维护和嵌入式 Linux 开发的 MCP 工具。

Project Overview项目介绍

RemoteOps is an MCP tool set designed for remote system maintenance and embedded Linux development. It consists of two components: a PC-side proxy called remote-ops-proxy and an agent called remote-ops-agent that runs on the remote controlled device. Once both are deployed and configured correctly, various AI coding agents running on your PC can remotely operate the target device through the MCP protocol. It supports multiple MCP-compatible AI agents including Claude Code, Codex, and DeepSeek Harness (DSH), and exposes 38 MCP tools that cover common file system, process, and shell operations.

To get started, you first download the latest prebuilt executable from the project’s release page. Put the remote-ops-proxy executable in a directory that’s included in your PC’s system PATH, then transfer the remote-ops-agent executable to your remote target device, such as an embedded development board. After starting the agent as a background process on the target device, add the remote-ops MCP server configuration to your AI agent’s config file, then restart the AI agent to apply the changes. This tool is ideal for developers who need AI assistance for cross-platform embedded development and remote device maintenance.

RemoteOps is released under the permissive MIT open source license. If you want to build the binaries from source yourself, you will need a working Rust development environment and the Zig cross-compilation toolchain, along with the cargo-zigbuild extension. It can be built for 9 different target architectures across Windows, macOS, and Linux, including niche embedded targets like MIPS32r2. There are important security caveats to note: the current protocol does not encrypt traffic, and the agent grants full shell access to the remote device. You must only use it on a trusted local network, never expose it directly to the public internet.

RemoteOps 是一套面向远程系统维护和嵌入式 Linux 开发的 MCP 工具集,分为 PC 端代理 proxy 和远端被控端 agent 两个组件。在 PC 部署 remote-ops-proxy 并配置 MCP 服务,在远端被控设备部署 remote-ops-agent,即可让 PC 端的 AI 编码代理远程控制远端设备执行各类操作,当前共暴露 38 个 MCP 工具,覆盖文件、进程、Shell 等操作。它支持 Claude Code、Codex 以及 DSH 等符合 MCP 规范的 AI 代理平台使用。

典型使用流程为,用户先从项目 Release 页面下载对应目标平台的可执行文件,将 proxy 加入 PC 端环境变量,将 agent 传到需要控制的远端开发板或目标系统,启动 agent 在后台运行后,在 AI 代理的 MCP 配置中添加 remote-ops 服务,重启代理即可使用。适合需要 AI 代理协助进行跨平台嵌入式开发、远程设备维护的开发者使用。

该项目采用 MIT 许可开源,支持编译构建 Windows、macOS、Linux 多架构共 9 个目标平台,本地自行编译需要 Rust 开发环境和 Zig 交叉编译工具链。需要注意的是,当前协议不加密传输内容,agent 提供完整远程 shell 权限,因此只能部署在本地可信网络中,不要暴露到公网。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 2 warnings2 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
  • No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
  • Not DSH-native: a multi-platform tool that may require Node / Electron or another runtime first非 DSH 原生,是多平台兼容工具:可能要先装 Node / Electron 等运行时
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:jark006/RemoteOps

把 jark006/RemoteOps 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

🛰️ RemoteOps

RemoteOps 是一个面向远程系统维护和嵌入式 Linux 开发的 MCP 工具。 在 PC 端部署 remote-ops-proxy 并配置 MCP,远端设备部署 remote-ops-agent,则 PC 端的 Claude Code / Codex 即可远程控制远端设备。

Claude Code / Codex
       v
   MCP stdio
       v
remote-ops-proxy
       ^
       v
remote-ops-agent
       v
remote filesystem / process / shell

🚀 快速上手

到 Release 里下载最新的 PC 端 remote-ops-proxy 可执行文件,再丢到环境变量的某个目录里。再下载被控端的 remote-ops-agent 可执行文件,丢到开发板或需要被控制的系统。

⚠️ 这些可执行文件都带了目标平台的名称后缀,要么重命名将其移除,要么在下面配置的时候使用完整文件名。

🤖 启动被控端 agent

在被控端 Ubuntu 或 嵌入式 Linux 执行:

# 启动进程到后台 默认监听 0.0.0.0:8022
nohup ./remote-ops-agent > /dev/null 2>&1 &

# 也可以指定监听IP及端口
nohup ./remote-ops-agent --listen 0.0.0.0:8022 > /dev/null 2>&1 &

如果被控端是 Windows 则执行:

.\remote-ops-agent.exe --listen 0.0.0.0:8022

查看版本:

./remote-ops-agent --version

🔧 配置 MCP proxy

通用 MCP 客户端配置示例如下,可以直接把以下内容丢给AI让他自己配置,然后重启 Claude Code 或 Codex 即可生效:

Claude Code: ~/.claude.json

{
  "mcpServers": {
    "remote-ops": {
      "type": "stdio",
      "command": "remote-ops-proxy",
      "args": []
    }
  }
}

Codex: ~/.codex/config.toml

[mcp_servers]
[mcp_servers.remote-ops]
type = "stdio"
command = "remote-ops-proxy"
args = []

proxy 参数:

--remote IPv4:PORT           可选,默认 192.168.43.106:8022,也可随时在对话中叫 AI 设定 remote-ops 的受控端 IP
--timeout-ms N               等待远端操作响应的 I/O 超时,默认 310000
--max-transfer-bytes N       单文件上限,默认 4294967296(4 GiB)
--version / -v               打印版本及项目地址后退出

💬 开始对话

用户: 使用 remote-ops 连接到 192.168.43.106 看看远端设备状况。

用户: 新增XX功能/优化XX相关逻辑/优化XX的性能,你要自行完成代码编辑、编译,通过 remote-ops 连接到 192.168.43.106 目标平台进行部署、运行及调试。

🛠️ MCP 工具

proxy 当前暴露 38 个 MCP 工具:

工具 主要参数 说明
read_text path, offset?, max_bytes? 有界读取远端文本,最大 1 MiB。
read_file_lines path, start_line?, end_line?, max_bytes? 按 1-based inclusive 行号读取 UTF-8 文本;默认从第 1 行读取 200 行,最多 10,000 行或返回 1 MiB。
tail_text path, lines?, max_bytes? 有界读取文件尾,最多 10,000 行或 1 MiB。
write_text path, content 原子写入远端文本。
apply_patch path, patch, expected_sha256? 对单个远端 UTF-8 文本文件原子应用上下文补丁。
list_files path, cursor?, limit?, recursive?, pattern?, max_depth? 排序、过滤并分页列出远端目录;可递归返回相对路径。每个条目返回 name、kind、size、mtime、mtime_iso(RFC 3339、Agent 本地时区)和 mode_str(ls -l 风格权限串)。
grep path, pattern, glob?, case_sensitive?, max_results?, max_file_bytes? 对远端普通 UTF-8 文件执行有界逐行 Rust 正则搜索。
stat path 不跟随符号链接读取元数据;返回 size、mtime、mtime_iso(RFC 3339、Agent 本地时区)、mode、mode_str(ls -l 风格权限串)和 kind。
file_hash path, max_bytes? 计算最大 64 MiB 文件的 SHA-256。
mkdir path, recursive?, mode? 创建精确指定的远端目录;可显式递归创建父目录并设置 Unix mode。
remove path, recursive? 删除一个精确路径;目录默认只允许空目录,递归删除必须显式开启。
move source, destination, overwrite? 同一文件系统内移动文件、目录或符号链接;跨文件系统返回结构化错误。
copy source, destination, overwrite?, recursive? 复制普通文件或显式递归复制目录,不跟随符号链接。
chmod path, mode 在 Unix 上设置普通文件或目录 mode,不跟随符号链接。
symlink target, link_path, overwrite?, target_kind? 创建一个符号链接;Windows 必须提供 target_kind。
sync_directory local_path, remote_path, excludes?, max_files?, max_total_bytes?, max_depth? 生成 manifest,只上传变化文件,在远端 staging 完整校验后切换目录并保留旧树。
deploy_release local_path, releases_path, current_path, release_id, start, health, ... Unix 发布事务:preflight、同步独立 release、原子切换 symlink、启动和健康检查,失败自动回滚。
pids filter?, cursor?, limit? Linux/Windows/macOS 进程分页;不可读取的 Windows/macOS 命令行返回空字符串。
process_info pid Linux/Windows/macOS 进程详情;Windows 的 state、uid 返回 null。start_time_seconds 为开机后秒数,start_time_iso 为进程启动墙钟时间(RFC 3339、Agent 本地时区,Linux 无法确定时为 null)。
kill pid, signal? Unix 发送数字信号;Windows 接受 9/15 并强制终止进程。默认 15。
pkill name, signal? 按平台进程名完整匹配(Windows 不区分大小写)并排除 agent 自身,默认 signal 15;Linux/macOS 名称分别最多 15/31 字节,Windows 最多 260 个 UTF-16 单元且 signal 仅接受 9/15。匹配超过 1024 个进程时不执行,返回 matched、signaled_pids 和 failed_pids。
sh_exec command, timeout_ms? Unix 通过 /bin/sh -c 执行;Windows 通过固定路径 Git Bash 执行,不存在时返回 unsupported。最长 300 秒。结果含 duration_ms。
exec program, args?, cwd?, env?, timeout_ms? 不经过 shell 执行程序。结果含 duration_ms。
process_start program, args?, cwd?, env?, timeout_ms? 启动由 agent 管理的后台程序并立即返回 job ID;默认最长 1 小时,最大 24 小时。
process_output job_id, stdout_cursor?, stderr_cursor?, max_bytes? 按绝对字节游标增量读取后台任务的 stdout/stderr。
process_wait job_id, wait_ms? 有界等待后台任务退出,默认 10 秒,最长 30 秒。
process_signal job_id, signal? 向 Unix 任务进程组发送信号;Windows 接受 9/15 并终止整个 Job Object。
process_close job_id 释放已结束任务及其保留输出;运行中的任务必须先 signal 并 wait。
system_info 无 有界读取系统、CPU、身份权限、网络、文件系统、时间(含 RFC 3339 的 time.iso)、init 和工具链画像。
upload_file local_path, remote_path, overwrite?, mode?, resume? 从 proxy 所在 PC 上传一个普通文件,可设置 Unix mode 并校验续传。
download_file remote_path, local_path, overwrite?, resume? 下载一个普通文件到 proxy 所在 PC,可校验续传。
remote_status 无 被动查询地址、缓存连接、生命周期状态,以及最近一次成功、错误、探测和 Agent 信息,不主动连接。
set_remote ip?, port? 动态设置远端 IPv4 或端口;至少提供一项,未提供部分保持不变。
agent_info 无 查询 Agent 版本、协议、构建信息、运行实例、平台、能力和限制。
remote_probe timeout_ms? 主动连接或健康检查远端,返回可达性、延迟、Agent 信息或结构化错误。
wait_remote wait_for?, timeout_ms?, poll_interval_ms?, probe_timeout_ms? 有界轮询远端,等待 online、offline 或 offline_then_online。
reboot delay_ms? 请求 Agent 延迟重启设备,并将 proxy 生命周期状态切换为 rebooting。
agent_update local_path, timeout_ms?, poll_interval_ms?, probe_timeout_ms? 上传并验证 Agent 候选程序,原子替换、重启验证,失败时自动回滚。
batch calls 在一次往返内按顺序执行至多 16 个只读与诊断工具(含 sh_exec/exec),子结果按输入顺序返回 {tool, ok, result|error};写操作整体拒绝。纯 proxy 实现,旧 Agent 无需升级。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-llm-volcengine 下一个 Next dsh-3d-model-viewer →