SSH AgentSAFE
A Model Context Protocol (MCP) server for managing and controlling SSH connections.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/AiondaDotCom/mcp-ssh/actions/workflows/test.yml)
A Model Context Protocol (MCP) server for managing and controlling SSH connections. This server integrates seamlessly with Claude Desktop and other MCP-compatible clients to provide AI-powered SSH operations.
Overview
This MCP server provides SSH operations through a clean, standardized interface that can be used by MCP-compatible language models like Claude Desktop. The server automatically discovers SSH hosts from your ~/.ssh/config and ~/.ssh/known_hosts files and executes commands using native SSH tools for maximum reliability.
Quick Start
MCP Bundle Installation (Recommended)
The easiest way to install MCP SSH Agent is as an MCP Bundle:
- Download the latest
mcp-ssh-*.mcpbfile from the GitHub releases page - Double-click the
.mcpbfile to install it in Claude Desktop
The bundle format was previously called a Desktop Extension and used the.dxtextension. v1.3.9 shipped both files during the transition; later releases carry.mcpbonly. If your Claude Desktop is old enough to reject a.mcpbfile, update it or use one of the installation methods below.
- The SSH tools will be automatically available in your conversations with Claude
Alternative Installation Methods
Installation via npx
npx @aiondadotcom/mcp-ssh
Manual Claude Desktop Configuration
To use this MCP server with Claude Desktop using manual configuration, add the following to your MCP settings file:
On macOS: ~/Library/Application Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json
{
"mcpServers": {
"mcp-ssh": {
"command": "npx",
"args": ["@aiondadotcom/mcp-ssh"]
}
}
}After adding this configuration, restart Cla
73fc6fef7754OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-ssh -- npx -y @aiondadotcom/[email protected]
{
"mcpServers": {
"mcp-ssh": {
"command": "npx",
"args": [
"-y",
"@aiondadotcom/[email protected]"
]
}
}
}Exposed tools (7)
7 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
checkConnectivity | read | Checks if an SSH connection to the host is possible |
downloadFile | read | Downloads a file from an SSH host |
getHostInfo | read | Returns all configuration details for an SSH host |
listKnownHosts | read | Returns a consolidated list of all known SSH hosts, prioritizing ~/.ssh/config entries first, then additional hosts from ~/.ssh/known_hosts |
runCommandBatch | read | Executes multiple shell commands sequentially on an SSH host |
runRemoteCommand | read | Executes a shell command on an SSH host. For long-running commands, increase the timeout parameter. |
uploadFile | read | Uploads a local file to an SSH host |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (16)
['authorized_keys', join(sshDir, 'authorized_keys')],
['a private key', join(sshDir, 'id_ed25519')],
it('should refuse a traversal path that lands in ~/.ssh', async () => {it('should refuse a relative path that resolves into ~/.ssh', async () => {it('should still allow uploadFile to read from ~/.ssh', async () => {const result = await client.downloadFile('test', '/etc/passwd', localPath);expect(await client.downloadFile('test', '/etc/passwd', '')).toBe(false);const result = await client.downloadFile('test', '/etc/passwd', localPath);expect(await client.downloadFile('test', '/etc/passwd', 'C:\\Users\\me\\out.txt')).toBe(true);expect(await client.downloadFile('test', '/etc/passwd', '\\\\server\\share\\out.txt')).toBe(true);@modelcontextprotocol/sdk, glob, ssh-config, @anthropic-ai/mcpb, @eslint/js, @types/node, @vitest/coverage-v8, eslint
- The `# @password:` annotation is read locally — the password **never** reaches the LLM or cloud provider
- The `# @password:` annotation is read **locally** by the MCP server — the password **never** reaches the AI model or any cloud provider
cat ~/.ssh/id_ed25519.pub | ssh user@hostname "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
cat ~/.ssh/id_ed25519.pub
- **`uploadFile` and `downloadFile` give the LLM access to the local filesystem** with the privileges of the user running the MCP server. The LLM can read any file the process can read (including `~/.
Gates applied: no_behavioural_pass.
73fc6fef7754full audit observations/trust-audit/mcp-server/aiondadotcom__ssh-agent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 73fc6fef7754 | SAFE | B | 89 | first audit |
Questions
What is the SSH Agent MCP server?
A Model Context Protocol (MCP) server for managing and controlling SSH connections.
What tools does SSH Agent expose?
7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SSH Agent safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does SSH Agent need?
No credential environment variables were found in its source, so it appears to need none.
How does SSH Agent run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @aiondadotcom/mcp-ssh at 1.3.9.
How current is this page?
The grade is for one exact copy of the source (73fc6fef7754), read on 2026-10-07. The repository is watched and re-audited when it changes.