by bvisible
MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups, database operations, health monitoring
# Add to your Claude Code skills
git clone https://github.com/bvisible/mcp-ssh-managerGuides for using mcp servers skills like mcp-ssh-manager.
Last scanned: 5/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-30T15:31:22.616Z",
"npmAuditRan": true,
"pipAuditRan": true
}See how mcp-ssh-manager compares with popular alternatives.
mcp-ssh-manager is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by bvisible. MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups, database operations, health monitoring. It has 493 GitHub stars.
Yes. mcp-ssh-manager passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/bvisible/mcp-ssh-manager" and add it to your Claude Code skills directory (see the Installation section above).
mcp-ssh-manager is primarily written in JavaScript. It is open-source under bvisible on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh mcp-ssh-manager against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
A Model Context Protocol (MCP) server that enables Claude Code and OpenAI Codex to manage multiple SSH connections. Execute commands, transfer files, manage databases, create backups, monitor health, and automate DevOps tasks across your servers — directly from your AI assistant.
🔒 Security release — three command-injection advisories fixed, one of which defeated readonly mode (Released: August 28, 2026)
Upgrade if you use ssh_backup_*, ssh_db_dump, ssh_service_status or ssh_tail — and especially if you rely on the readonly / restricted security modes.
readonly / restricted (GHSA-m793-whw6-f537) — ssh_service_status and ssh_tail are read-only, so they stay enabled on servers you locked down, and neither quoted its arguments nor consulted the policy layer. A service name like nginx; id > /tmp/pwned executed. This defeated the exact control those modes exist to provide.ssh_db_dump (GHSA-796j-h5q5-jx6p) — the stat command run after the dump interpolated the output path raw. The v3.6.7 patch had stopped one line short.ssh_backup_* tool (GHSA-qwwm-vrm9-4mw8) — backup-manager.js had zero shell escaping across its 9 builders, while database-manager.js had 95. The v3.6.7 fix was never extended to it.The quoting helper now lives in one module (src/shell-quote.js) so "did this builder quote its inputs?" has a single answer, and a new test drives 340 builder × argument × payload combinations through a real shell to prove none of them execute.
An MCP SSH server is the most dangerous tool you can hand an AI agent: a shell on machines that matter. This one is built so you decide how far the agent can go — per server, not globally.
| Mode | What the agent can do |
|---|---|
unrestricted (default) |
Everything. Same behaviour as any other SSH MCP server. |
readonly |
Mutating tools are refused outright — no deploy, no upload, no sudo, no database import. Read commands still work. |
restricted |
Every command must match an allow pattern and no deny pattern. Anything else is refused before it reaches the host. |
SSH_SERVER_PROD_MODE=readonly
SSH_SERVER_STAGING_MODE=restricted
SSH_SERVER_STAGING_ALLOW_PATTERNS=^systemctl (status|restart) myapp$;^tail -n \d+ /var/log/
Alongside that:
ps, in /proc/<pid>/cmdline, or
in an auditd trail — unlike the echo "$pass" | sudo -S pattern common in
this category (#34).ssh_db_query refuses anything
that is not a SELECT.npm ci, and a test enforces that every dependency resolves to
registry.npmjs.org with an integrity hash and no unreviewed install scripts.~/.ssh-manager.log and stderr (which your MCP host captures), so one call site handing it a server config would have persisted a production password. Redaction now happens inside the logger. Also: CodeQL on every push, every action pinned by SHA, and a broken example that never parsed. Full changelog →echo "<password>" | sudo -S, readable in ps and /proc/<pid>/cmdline by every account on the host. It now goes over the SSH channel's stdin. Also: listed in the official MCP Registry as io.github.bvisible/mcp-ssh-manager, releases published from CI with SLSA provenance and a CycloneDX SBOM, and the per-server security modes documented at last. Full changelog →npm run test:lockfile guarding it against drift and tampering. CI installs with npm ci; ESLint and the JSDoc typecheck became blocking gates after being purely decorative. Full changelog →ssh_sync on Windows, tunnel crash fix (August 14, 2026)group field per server (#56 — contributed by @ice616, requested in #55) — tag a server with group = "production" and it is in that group: ssh_execute_group resolves members straight from your .env/TOML, union'd with any .server-groups.json you already keep. Also: ssh_sync fixed from a Windows host (#59 — contributed by @2836603852), a tunnel on a busy port no longer takes the whole MCP server down, the @modelcontextprotocol/sdk floor raised to ^1.30.0 over three advisories, and JSDoc type-checking added to CI. Full changelog →FORWARD_AGENT / forward_agent option (#53 — requested by @raphaelbahat in #52) — the equivalent of OpenSSH's ForwardAgent yes, per server: processes on the remote host authenticate to other SSH hosts with the keys in your local ssh-agent, without copying any private key. Requires a running agent and defaults to false. Full changelog →ssh_db_* argument is now shell-quoted (#51 — responsibly disclosed by Ugur Ozer, Aeon AI Risk Management (http://airiskmanagement.ca), see #48) — caller-controlled values (ssh_db_list most notably, which stayed allowed in readonly/restricted modes) were interpolated into shell-evaluated strings, allowing arbitrary command execution on the SSH target. A centralized shellQuote() now wraps every value across all 15 builders, guarded by a 648-combination injection test. Full changelog →SUDO_PASSWORD / DEFAULT_DIR / ssh_sync key auth work again (July 11, 2026)ssh_execute_sudo ignored SUDO_PASSWORD, DEFAULT_DIR was ignored by ssh_execute/ssh_group_execute/ssh_list_servers, and ssh_sync never passed the configured SSH key to rsync. All aligned with the loader's camelCase fields, with a regression test locking the loader output shape. Full changelog →ssh_db_query shell-injection security fix + real row_count (June 30, 2026)$(…) ins