HopBLOCK
Fast, elegant SSH connection manager with a TUI dashboard and MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
hop
Stop typing long SSH commands. Just hop prod and you're in.
Why hop?
# Before: remembering and typing this every time ssh -i ~/.ssh/work_key [email protected] -p 2222 # After hop prod
hop prod # fuzzy match any server hop exec production "uptime" # run command on all prod servers hop import # import your existing ~/.ssh/config hop # launch the TUI, manage everything
Install
Homebrew (macOS/Linux)
brew install danmartuszewski/tap/hop
Go
go install github.com/danmartuszewski/hop/cmd/hop@latest
From source
git clone https://github.com/danmartuszewski/hop.git && cd hop && make build ./bin/hop
Install with an AI agent
Using Claude Code, Codex, Cursor, or another coding agent? Paste the block below into your agent and it will pick the right install path for your machine, register hop's MCP server, and verify the install.
Install hop on this machine and register its MCP server. Do the steps in order; stop and report on the first failure. 1. Pick ONE install method, in this priority: a. Homebrew (macOS or Linux): brew install danmartuszewski/tap/hop b. Go 1.22+ available: go install github.com/danmartuszewski/hop/cmd/hop@latest c. From source (no brew, no Go on PATH): git clone https://github.com/danmartuszewski/hop.git && cd hop && make install 2. Verify the binary is on PATH: hop version 3. Register the MCP server with whichever agent the user is running. Skip clients the user does not use: - Claude Code: claude mcp add hop -- hop mcp - Codex CLI: codex mcp add hop -- hop mcp - Claude Desktop / Cursor
ca4dbb29be8fOBSERVED · 2026-10-07Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (13)
COPY example-ssh-config /home/hopuser/.ssh/config
RUN chown -R hopuser:hopuser /home/hopuser/.ssh && chmod 700 /home/hopuser/.ssh && chmod 600 /home/hopuser/.ssh/config
hop get staging identity_file --default ~/.ssh/id_rsa
.goreleaser.yaml
IdentityFile: "~/.ssh/prod_id",
if got, want := stdout.String(), "~/.ssh/prod_id\n"; got != want {# Zsh (add to ~/.zshrc)
assets/hop1.png
assets/hop2.png
assets/hop3.png
assets/mcp.png
demo/hop-search.gif
Gates applied: no_behavioural_pass.
ca4dbb29be8ffull audit observations/trust-audit/mcp-server/danmartuszewski__hop.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ca4dbb29be8f | BLOCK | D | 69 | first audit |
Questions
What is the Hop MCP server?
Fast, elegant SSH connection manager with a TUI dashboard and MCP server
Is Hop safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Hop need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (ca4dbb29be8f), read on 2026-10-07. The repository is watched and re-audited when it changes.