Safety
What the AI can do with your account, and the limits that are built in.
What the AI can do #
The session stored by this server grants full control of your Minehut account. The AI can start and stop servers, send console commands with operator privileges, change RAM, read logs and click through the dashboard including plugin and billing settings.
Built-in limits #
- Destructive actions are not automated by default. There is no tool for server reset or account deletion.
- Console commands reach the server only through
minehut_command, which the AI calls with the exact command string. - The session file is created with permissions 600.
browser_closeexists so the whole browser session can be shut down on demand.
Recommended practices #
- Review what you ask the AI to run. A misphrased command is exactly as damaging as typing it yourself.
- Run the server only on machines you trust. It stores real credentials in your home directory.
- Rotate your Minehut password and re-login after any machine compromise.
- Do not paste credentials, tokens or session files into support chats or issue trackers.
- Disable the MCP server when you are done for the day. Most clients allow per-project enable and disable.
Operator privileges. Every console command sent through
minehut_command runs as the server operator. There is no sandbox between the
AI and your server, by design.
Account-level precautions #
Consider a dedicated Minehut account with a strong unique password for any long-running automation setup. The server works with any account, so slotting in a throwaway account costs nothing.