SSH ManagerBLOCK
MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups, database operations, health monitoring
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that enables Claude Code and OpenAI Codex to manage multiple SSH connections. Execute commands, transfer files, manage databases, create backups, monitor health, and automate DevOps tasks across your servers — directly from your AI assistant.
[](https://www.npmjs.com/package/mcp-ssh-manager) [](https://www.npmjs.com/package/mcp-ssh-manager) [](https://github.com/bvisible/mcp-ssh-manager/releases/tag/v3.8.5) [](https://claude.ai/code) [](https://openai.com/codex) [](https://modelcontextprotocol.io) [](https://scorecard.dev/viewer/?uri=github.com/bvisible/mcp-ssh-manager) [](LICENSE)
[](https://mcptoplist.com/server/glama%2Fbvisible%2Fmcp-ssh-manager)
🎉 What's New in v3.8.5
🔒 Security release — three command-injection advisories fixed, one of which defeated `readonly` mode (Released: August 28, 2026)
*Upgrade if you use `ssh_backup_`,
bd9add792e27OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-ssh-manager -- npx -y [email protected]
Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
minimal | read | Minimal profile |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (15 observation(s))
- Network
- none-observed
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
prompt_input "SSH key path" "$HOME/.ssh/id_rsa" "auth_value"
echo " ~/.ssh-manager/ # Config directory"
echo " • ~/.ssh/id_rsa (default RSA key)"
echo " • ~/.ssh/id_ed25519 (modern ED25519 key)"
echo " • ~/.ssh/custom_key (custom key)"
const SECRET = 'hunter2-prod-password';
const SECRET = 'sup3r-s3cret-sudo-pw';
.flake8
.hooks-config.json
.pre-commit-config.yaml
exec(cmd, cb) {"../../mcp-ssh-manager/.env"
@iarna/toml, @modelcontextprotocol/sdk, dotenv, ssh2, zod, eslint, knip, prettier
5. **Environment Loading**: Uses dotenv to load configuration from `.env` file in project root
// Load environment variables
// Load server configuration from .env
"""Load servers from .env file"""
# Add to your PATH
# Add to ~/.bashrc or ~/.zshrc
# Add to PATH if needed
- **`readonly`** — blocks mutating tools (`ssh_upload`, `ssh_deploy`, `ssh_sync`, `ssh_execute_sudo`, `ssh_backup_*`, `ssh_db_import/dump`, plus action-gated `ssh_key_manage accept|remove`, `ssh_alert
- **`readonly`** — blocks `ssh_upload`, `ssh_deploy`, `ssh_sync`, `ssh_execute_sudo`, backup/db write tools, and built-in destructive commands (`rm`, `mv`, `sudo`, `systemctl restart`, redirects outsi
- **🎯 Marker-based SSH session sync** — UUID v4 protocol boundaries with `ECHO: 0` PTY, real `$?` exit codes, no more "Timeout waiting for shell prompt" on custom/slow/AIX shells ([#30](https://github
docs/images/[email protected]
docs/images/ssh-manager-cli-menu.png
Gates applied: no_behavioural_pass.
bd9add792e27full audit observations/trust-audit/mcp-server/bvisible__ssh-manager.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | bd9add792e27 | BLOCK | D | 69 | first audit |
Questions
What is the SSH Manager MCP server?
MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups, database operations, health monitoring
What tools does SSH Manager expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SSH Manager safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does SSH Manager need?
It reads SSH_AUTH_SOCK, SSH_E2E_KEYPATH, SSH_E2E_PASSPHRASE and SSH_E2E_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SSH Manager run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-ssh-manager at 3.8.5.
How current is this page?
The grade is for one exact copy of the source (bd9add792e27), read on 2026-10-01. The repository is watched and re-audited when it changes.