Timeweb Cloud plugin with confirmation guards

timeweb-mcp

A Claude plugin for Timeweb Cloud: servers, domains, DNS and balance, with dangerous operations gated by explicit confirmation and name checks

Plugin

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • ssh_exec and service_control run arbitrary commands on a live server
  • create_server and delete_server change the Timeweb Cloud account's infrastructure and spending
All reasons and checks
Russian stack

k2spam/timeweb-mcp

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add plugins/timeweb-mcp

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run one by one in the Claude Code chat

/plugin marketplace add k2spam/timeweb-mcp
/plugin install timeweb-mcp@k2spam-tools

Checked against the repository on Sep 25, 2026, commit 6b1dcbf.

Text for your agent

In Claude, run /plugin marketplace add https://github.com/k2spam/timeweb-mcp, then /plugin install timeweb-mcp@k2spam-tools, and configure your Timeweb Cloud API token per the plugin's instructions.

Other ways from the author
/plugin marketplace add https://github.com/k2spam/timeweb-mcp
/plugin install timeweb-mcp@k2spam-tools

Installing the plugin directly from git, per the README.

This is third-party code. Review the repository files before installing.

What it does

The plugin installs an MCP server and a timeweb-ops skill for managing Timeweb Cloud: account status and balance, server list and status, logs, presets and images, powering servers on and off, creating and deleting servers, domains and DNS records, plus SSH diagnostics, systemctl-based service control, and arbitrary commands. Dangerous operations are flagged in the README: some only run with a confirm: true parameter, and deleting a server additionally requires expected_name, which is checked against the server's real name and rejected on a mismatch. The API token is stored in a file with 600 permissions and is never passed through command arguments.

Who it is for. For Timeweb Cloud infrastructure owners who want to manage servers and DNS through an agent without fear of accidentally deleting the wrong server.

Good fit when

  • You need to manage Timeweb Cloud servers, domains and DNS from Claude with a single phrase
  • You need protection against accidentally deleting a server via an expected-name check
  • You need SSH access to a server with explicit confirmation before running commands

Not a fit when

  • You do not want to give the agent ssh_exec with arbitrary commands, even with confirmation
  • You need support for clouds other than Timeweb Cloud: the plugin is built only for it

Example request

Show my Timeweb Cloud balance and the status of all servers, without changing anything

Limitations

The project is not affiliated with Timeweb, as the README itself states. It has a single author and installs from git rather than being published in an official plugin marketplace. Full access via ssh_exec, even gated by confirmation, remains a powerful tool: the agent can run any command on the server if the user confirms the request without reading it carefully.

How to disable. Remove the plugin with /plugin uninstall timeweb-mcp@k2spam-tools in Claude Code.

Security check

  • ssh_exec and service_control run arbitrary commands on a live server
  • create_server and delete_server change the Timeweb Cloud account's infrastructure and spending

README in short

The Russian README explains MCP as a protocol that gives an agent hands for Timeweb Cloud infrastructure, lists tools by group (account, servers, domains and DNS, SSH) with icons for confirm-gated and dangerous operations, and describes the timeweb-ops skill with scenarios and a confirmation protocol. It separately details the safety measures: confirm: true, the expected_name check on server deletion, and storing the token in a 600-permission file.

FAQ

Can the agent delete the wrong server by mistake?

The delete_server tool requires an expected_name parameter checked against the server's real name, and rejects the deletion on a mismatch.

Do dangerous operations run without asking?

No, they are flagged and require an explicit confirm: true parameter, otherwise the agent is refused and must ask again.

Editors’ pick

An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant

MCP serverMedium riskNo VPN needed80.7KRepository stars
Editors’ pick

GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent

MCP serverHigh risk33.3KRepository stars

Agent Skills for Google products

Agent Skills for Google products and technologies

Editors’ pick

Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent

SkillHigh risk20.5KRepository stars
Official

AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring

MCP serverHigh risk9.7KRepository stars
Foxx AITimeweb Cloud plugin with confirmation guards

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.