SSH OrchestratorBLOCK
Secure SSH access for AI agents via MCP. Execute commands across your server fleet with policy enforcement, network controls, and comprehensive audit logging.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP SSH Orchestrator
Zero-Trust SSH Orchestration for AI Assistants Enforce declarative policy-as-code and audited access for Claude Desktop, Cursor, and any MCP-aware client. Launch in minutes with Docker + MCP tooling, deny-by-default controls, and hardened SSH key management.
[](LICENSE) [](https://pypi.org/project/mcp/1.29.1/) [](https://python.org) [](https://github.com/samerfarida/mcp-ssh-orchestrator) [](https://scorecard.dev/viewer/?uri=github.com/samerfarida/mcp-ssh-orchestrator) [](https://github.com/samerfarida/mcp-ssh-orchestrator/releases) [](https://github.com/samerfarida/mcp-ssh-orchestrator/stargazers) [](https://github.com/samerfarida/mcp-ssh-orchestrator/network/members) [](https://github.com/samerfarida/mcp-ssh-orchestrator/issues) [](https://github.com/samerfarida/mcp-ssh-orchestrator/pulls) [](https://github.com/samerfarida/mcp-ssh-orchestrator/graphs/contributors) [
10 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
ssh_cancel | read | Request cancellation for a running task. |
ssh_cancel_async_task | read | Cancel a running async task. |
ssh_describe_host | read | Return host definition in JSON. |
ssh_get_task_output | read | Get recent output lines from running or completed task. |
ssh_get_task_result | read | Get final result of completed task (SEP-1686 compliant). |
ssh_get_task_status | read | Get current status of an async task (SEP-1686 compliant). |
ssh_list_hosts | read | List configured hosts. |
ssh_ping | read | Health check. |
ssh_plan | read | Show what would be executed and if policy allows. |
ssh_reload_config | read | Reload configuration files. |
ssh_run | write | Execute SSH command with policy, network checks, progress, timeout, and cancellation. |
ssh_run_async | write | Start SSH command asynchronously (SEP-1686 compliant). |
ssh_run_on_tag | write | Execute SSH command on all hosts with a tag (with network checks). |
Trust audit
BLOCKgrade F · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
-----BEGIN PRIVATE KEY-----
-----BEGIN PRIVATE KEY-----
create_key "prod/id_ed25519"
.markdownlint.json
.pre-commit-config.yaml
install -d -m 700 ~/.gnupg
printf 'pinentry-mode loopback\n' > ~/.gnupg/gpg.conf
printf 'allow-loopback-pinentry\n' > ~/.gnupg/gpg-agent.conf
"key_path": "id_ed25519",
"../../etc/passwd",
"../../outside",
"../../../etc/passwd",
"../../outside",
"../../../etc/passwd",
assets/demo.gif
- **Direct shell access** with unlimited privileges
# Dangerous: Unrestricted access
- **Definition**: The act of exploiting a bug or design flaw to gain elevated access
- **Unrestricted access** leads to lateral movement and data exfiltration
cat > ~/mcp-ssh/secrets/prod_db_password.txt <<'EOF'
cat > ~/mcp-ssh/secrets/.env <<'EOF'
2. Read each secret and add to `.env`:
echo "SECRET_NAME=$(cat secrets/SECRET_NAME)" >> secrets/.env
cat secrets/.env
# Or manually add to authorized_keys
Gates applied: critical_finding, no_behavioural_pass.
9e8185e5d7f0full audit observations/trust-audit/mcp-server/samerfarida__ssh-orchestrator.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 9e8185e5d7f0 | BLOCK | F | 60 | first audit |
Questions
What is the SSH Orchestrator MCP server?
Secure SSH access for AI agents via MCP. Execute commands across your server fleet with policy enforcement, network controls, and comprehensive audit logging.
What tools does SSH Orchestrator expose?
13 in total: 10 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SSH Orchestrator safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (60/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does SSH Orchestrator need?
It reads MCP_SSH_KEYS_DIR and MCP_SSH_SECRETS_DIR from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SSH Orchestrator run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-ssh-orchestrator.
How current is this page?
The grade is for one exact copy of the source (9e8185e5d7f0), read on 2026-10-08. The repository is watched and re-audited when it changes.