Hungry Nova Labs

Nova MCP

A catalog of sysadmin toolpacks for Cursor, Claude, and Nova Ops. One job per server. Tight tool lists. Risk on every tool. Packs run on your machines — this is the shelf.

read observe write changes state exec runs commands danger needs a plan

Packs

hn-host

Host

12 tools · 0.1.0

One Linux/Mac host over SSH or local — facts, logs, ports, plan-then-run

readwriteexecdanger
host_listhost_factshost_processeshost_service_statushost_tail_loghost_diskhost_listen_portshost_run_planhost_runhost_file_readhost_file_write_planhost_file_write
hn-net

Net

8 tools · 0.1.0

Network truth without a full NMS — DNS, HTTP, TLS, TCP, ping, path, whois, report

read
dns_lookuphttp_checktls_inspecttcp_checkping_checktrace_pathwhois_lookupnet_report
hn-containers

Containers

8 tools · 0.1.0

Docker first. Read status/logs/stats, then plan → approve → restart

readwriteexecdanger
docker_psdocker_inspectdocker_logsdocker_statsdocker_compose_psdocker_restart_plandocker_restartdocker_exec
hn-incident

Incident

8 tools · 0.1.0

Triage workflow: open, gather evidence, hypotheses, runbook, checklist, close

readwritedanger
incident_openincident_noteincident_gatherincident_hypothesesincident_runbook_getincident_checklistincident_pageincident_close

Coming later · hn-iac · hn-k8s-read · hn-k8s-write

Profiles

homelab

Read plus careful write. Danger tools are visible but plan-gated.

msp

Multi-tenant safe defaults: every host call needs tenant. No exec, no danger.

prod-readonly

Observe only. An admin should trust this profile with no fear. Danger tools never appear.

incident

Read plus limited exec. Destroy/danger commands stay hidden. Writes are plan-gated.