Atlas / MCP servers / bvisible / SSH Manager

SSH ManagerBLOCK

mcp/bvisible/ssh-manager

MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups, database operations, health monitoring

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
MIT
Stars
495
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that enables Claude Code and OpenAI Codex to manage multiple SSH connections. Execute commands, transfer files, manage databases, create backups, monitor health, and automate DevOps tasks across your servers — directly from your AI assistant.

[](https://www.npmjs.com/package/mcp-ssh-manager) [](https://www.npmjs.com/package/mcp-ssh-manager) [](https://github.com/bvisible/mcp-ssh-manager/releases/tag/v3.8.5) [](https://claude.ai/code) [](https://openai.com/codex) [](https://modelcontextprotocol.io) [](https://scorecard.dev/viewer/?uri=github.com/bvisible/mcp-ssh-manager) [](LICENSE)

[](https://mcptoplist.com/server/glama%2Fbvisible%2Fmcp-ssh-manager)

🎉 What's New in v3.8.5

🔒 Security release — three command-injection advisories fixed, one of which defeated `readonly` mode (Released: August 28, 2026)

*Upgrade if you use `ssh_backup_`,

Read from source at commit bd9add792e27OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-ssh-manager -- npx -y [email protected]
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
minimalreadMinimal profile
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (15 observation(s))
Network
none-observed
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/commands/server.sh:43
prompt_input "SSH key path" "$HOME/.ssh/id_rsa" "auth_value"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/install.sh:98
echo "  ~/.ssh-manager/              # Config directory"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/lib/menu.sh:150
echo "  • ~/.ssh/id_rsa (default RSA key)"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/lib/menu.sh:151
echo "  • ~/.ssh/id_ed25519 (modern ED25519 key)"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/lib/menu.sh:152
echo "  • ~/.ssh/custom_key (custom key)"
Why it matters. touches a credential store
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test-logger-redaction.js:28
const SECRET = 'hunter2-prod-password';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test-sudo-stdin.js:23
const SECRET = 'sup3r-s3cret-sudo-pw';
LOWInventory / provenance · inv.hidden_file · CWE-1104
.flake8
.flake8
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.hooks-config.json
.hooks-config.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test-sudo-stdin.js:50
exec(cmd, cb) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/migrate.sh:20
"../../mcp-ssh-manager/.env"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@iarna/toml, @modelcontextprotocol/sdk, dotenv, ssh2, zod, eslint, knip, prettier
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:223
5. **Environment Loading**: Uses dotenv to load configuration from `.env` file in project root
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
mcp-ssh-manager-setup.md:93
// Load environment variables
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
mcp-ssh-manager-setup.md:99
// Load server configuration from .env
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
mcp-ssh-manager-setup.md:376
"""Load servers from .env file"""
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
INSTALLATION.md:108
# Add to your PATH
Why it matters. instructs the agent to persist itself in the user's environment
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
cli/README.md:218
# Add to ~/.bashrc or ~/.zshrc
Why it matters. instructs the agent to persist itself in the user's environment
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
cli/README.md:247
# Add to PATH if needed
Why it matters. instructs the agent to persist itself in the user's environment
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:146
- **`readonly`** — blocks mutating tools (`ssh_upload`, `ssh_deploy`, `ssh_sync`, `ssh_execute_sudo`, `ssh_backup_*`, `ssh_db_import/dump`, plus action-gated `ssh_key_manage accept|remove`, `ssh_alert
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:448
- **`readonly`** — blocks `ssh_upload`, `ssh_deploy`, `ssh_sync`, `ssh_execute_sudo`, backup/db write tools, and built-in destructive commands (`rm`, `mv`, `sudo`, `systemctl restart`, redirects outsi
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:164
- **🎯 Marker-based SSH session sync** — UUID v4 protocol boundaries with `ECHO: 0` PTY, real `$?` exit codes, no more "Timeout waiting for shell prompt" on custom/slow/AIX shells ([#30](https://github
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
docs/images/[email protected]
docs/images/[email protected]
Why it matters. 1641240 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/images/ssh-manager-cli-menu.png
docs/images/ssh-manager-cli-menu.png
Why it matters. 1559581 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha bd9add792e27full audit observations/trust-audit/mcp-server/bvisible__ssh-manager.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-01bd9add792e27BLOCKD69first audit
06

Questions

What is the SSH Manager MCP server?

MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups, database operations, health monitoring

What tools does SSH Manager expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SSH Manager safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does SSH Manager need?

It reads SSH_AUTH_SOCK, SSH_E2E_KEYPATH, SSH_E2E_PASSPHRASE and SSH_E2E_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SSH Manager run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-ssh-manager at 3.8.5.

How current is this page?

The grade is for one exact copy of the source (bd9add792e27), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement