crash-curator-mcp
v0.1.0
Published
Token-bounded systemd crash evidence for MCP clients
Maintainers
Readme
crash-curator-mcp
A small MCP server that turns systemd-coredump and journal evidence into bounded, normalized crash reports before an AI model sees it.
It is intentionally not a general-purpose log reader. Every query has fixed time, row, line, and byte budgets. The server uses Bun 1.4 APIs directly (Bun.spawn, Bun.file, and Bun streams), has no runtime dependencies, and does not use Node.js APIs.
Requirements
- Linux with systemd 257 or newer
- Permission to read the user's coredump and journal metadata
The npm package contains a standalone Linux x64 executable, so Bun is not required at runtime. Building from source requires Bun 1.4 or newer.
Tools
crash_list: scans at most 50 coredump records and returns at most 10 normalized entries.inspect_crash: returns one crash, stack highlights, matching-crash frequency, warnings and process logs from a 30-second window, OOM evidence, and package changes from the preceding 24 hours.
inspect_crash has a hard 12 KB response budget. Common tokens, passwords, API keys, and URL credentials are redacted. It never extracts a core or invokes a debugger.
Install
bun add --global crash-curator-mcpThe package published to npm contains only the compiled executable plus npm's required package metadata, README, and license. Source code and tests are excluded from the tarball.
Develop
bun test
bun run build
./dist/crash-curator-mcpThe server speaks MCP over stdio. Running it directly waits for JSON-RPC input; normally an MCP client starts it.
Codex
Add this to the user-level ~/.codex/config.toml:
[mcp_servers.crash-curator]
command = "crash-curator-mcp"Claude Code
claude mcp add --scope user crash-curator -- crash-curator-mcpOpenCode
Add a user-level entry under mcp in ~/.config/opencode/opencode.json:
{
"mcp": {
"crash-curator": {
"type": "local",
"command": ["crash-curator-mcp"],
"enabled": true
}
}
}MCP has no universal cross-client registry. “Global” means configuring the server once at user scope in each client, rather than embedding it in a project or in Omarchy.
Privacy and scope
- Commands are executed without a shell.
- Journal queries are limited to 30 seconds around the crash.
- Package history is limited to the 24 hours preceding the crash.
- Core memory is never read or copied.
- Raw logs are never returned.
- The output reports when evidence was omitted or truncated.
Symbolization should be a separate, explicit escalation because a core can contain credentials and private documents and debugger output can be very large.
