Atlas / MCP servers / aiondadotcom / SSH Agent

SSH AgentSAFE

mcp/aiondadotcom/ssh-agent

A Model Context Protocol (MCP) server for managing and controlling SSH connections.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
7 7r · 0w · 0d
Transport
stdio
License
MIT
Stars
102
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/AiondaDotCom/mcp-ssh/actions/workflows/test.yml)

A Model Context Protocol (MCP) server for managing and controlling SSH connections. This server integrates seamlessly with Claude Desktop and other MCP-compatible clients to provide AI-powered SSH operations.

Overview

This MCP server provides SSH operations through a clean, standardized interface that can be used by MCP-compatible language models like Claude Desktop. The server automatically discovers SSH hosts from your ~/.ssh/config and ~/.ssh/known_hosts files and executes commands using native SSH tools for maximum reliability.

Quick Start

MCP Bundle Installation (Recommended)

The easiest way to install MCP SSH Agent is as an MCP Bundle:

  1. Download the latest mcp-ssh-*.mcpb file from the GitHub releases page
  2. Double-click the .mcpb file to install it in Claude Desktop
The bundle format was previously called a Desktop Extension and used the .dxt extension. v1.3.9 shipped both files during the transition; later releases carry .mcpb only. If your Claude Desktop is old enough to reject a .mcpb file, update it or use one of the installation methods below.
  1. The SSH tools will be automatically available in your conversations with Claude

Alternative Installation Methods

Installation via npx

npx @aiondadotcom/mcp-ssh

Manual Claude Desktop Configuration

To use this MCP server with Claude Desktop using manual configuration, add the following to your MCP settings file:

On macOS: ~/Library/Application Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json

{
"mcpServers": {
"mcp-ssh": {
"command": "npx",
"args": ["@aiondadotcom/mcp-ssh"]
}
}
}

After adding this configuration, restart Cla

Read from source at commit 73fc6fef7754OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-ssh -- npx -y @aiondadotcom/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-ssh": {
      "command": "npx",
      "args": [
        "-y",
        "@aiondadotcom/[email protected]"
      ]
    }
  }
}
03

Exposed tools (7)

7 read · 0 write · 0 destructive.

ToolRiskDescription
checkConnectivityreadChecks if an SSH connection to the host is possible
downloadFilereadDownloads a file from an SSH host
getHostInforeadReturns all configuration details for an SSH host
listKnownHostsreadReturns a consolidated list of all known SSH hosts, prioritizing ~/.ssh/config entries first, then additional hosts from ~/.ssh/known_hosts
runCommandBatchreadExecutes multiple shell commands sequentially on an SSH host
runRemoteCommandreadExecutes a shell command on an SSH host. For long-running commands, increase the timeout parameter.
uploadFilereadUploads a local file to an SSH host
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (16)

LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ssh-client.test.ts:1097
['authorized_keys', join(sshDir, 'authorized_keys')],
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ssh-client.test.ts:1098
['a private key', join(sshDir, 'id_ed25519')],
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ssh-client.test.ts:1107
it('should refuse a traversal path that lands in ~/.ssh', async () => {
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ssh-client.test.ts:1114
it('should refuse a relative path that resolves into ~/.ssh', async () => {
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ssh-client.test.ts:1126
it('should still allow uploadFile to read from ~/.ssh', async () => {
Why it matters. touches a credential store
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/ssh-client.test.ts:984
const result = await client.downloadFile('test', '/etc/passwd', localPath);
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/ssh-client.test.ts:999
expect(await client.downloadFile('test', '/etc/passwd', '')).toBe(false);
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/ssh-client.test.ts:1010
const result = await client.downloadFile('test', '/etc/passwd', localPath);
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/ssh-client.test.ts:1037
expect(await client.downloadFile('test', '/etc/passwd', 'C:\\Users\\me\\out.txt')).toBe(true);
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/ssh-client.test.ts:1043
expect(await client.downloadFile('test', '/etc/passwd', '\\\\server\\share\\out.txt')).toBe(true);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, glob, ssh-config, @anthropic-ai/mcpb, @eslint/js, @types/node, @vitest/coverage-v8, eslint
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:115
- The `# @password:` annotation is read locally — the password **never** reaches the LLM or cloud provider
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:202
- The `# @password:` annotation is read **locally** by the MCP server — the password **never** reaches the AI model or any cloud provider
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:472
cat ~/.ssh/id_ed25519.pub | ssh user@hostname "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:475
cat ~/.ssh/id_ed25519.pub
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:593
- **`uploadFile` and `downloadFile` give the LLM access to the local filesystem** with the privileges of the user running the MCP server. The LLM can read any file the process can read (including `~/.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 73fc6fef7754full audit observations/trust-audit/mcp-server/aiondadotcom__ssh-agent.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0773fc6fef7754SAFEB89first audit
06

Questions

What is the SSH Agent MCP server?

A Model Context Protocol (MCP) server for managing and controlling SSH connections.

What tools does SSH Agent expose?

7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SSH Agent safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does SSH Agent need?

No credential environment variables were found in its source, so it appears to need none.

How does SSH Agent run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @aiondadotcom/mcp-ssh at 1.3.9.

How current is this page?

The grade is for one exact copy of the source (73fc6fef7754), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement