Atlas / MCP servers / samerfarida / SSH Orchestrator

SSH OrchestratorBLOCK

mcp/samerfarida/ssh-orchestrator

Secure SSH access for AI agents via MCP. Execute commands across your server fleet with policy enforcement, network controls, and comprehensive audit logging.

Verdict
BLOCK
Grade
F
Trust score
60 /100
Exposed tools
13 10r · 3w · 0d
Transport
stdio
License
Apache-2.0
Stars
28
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP SSH Orchestrator

Zero-Trust SSH Orchestration for AI Assistants Enforce declarative policy-as-code and audited access for Claude Desktop, Cursor, and any MCP-aware client. Launch in minutes with Docker + MCP tooling, deny-by-default controls, and hardened SSH key management.

[](LICENSE) [](https://pypi.org/project/mcp/1.29.1/) [](https://python.org) [](https://github.com/samerfarida/mcp-ssh-orchestrator) [](https://scorecard.dev/viewer/?uri=github.com/samerfarida/mcp-ssh-orchestrator) [](https://github.com/samerfarida/mcp-ssh-orchestrator/releases) [](https://github.com/samerfarida/mcp-ssh-orchestrator/stargazers) [](https://github.com/samerfarida/mcp-ssh-orchestrator/network/members) [](https://github.com/samerfarida/mcp-ssh-orchestrator/issues) [](https://github.com/samerfarida/mcp-ssh-orchestrator/pulls) [](https://github.com/samerfarida/mcp-ssh-orchestrator/graphs/contributors) [![GitHub last commit](ht

Read from source at commit 9e8185e5d7f0OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-ssh-orchestrator --env MCP_SSH_KEYS_DIR=${MCP_SSH_KEYS_DIR} --env MCP_SSH_SECRETS_DIR=${MCP_SSH_SECRETS_DIR} -- uvx mcp-ssh-orchestrator
claude-desktop
{
  "mcpServers": {
    "mcp-ssh-orchestrator": {
      "command": "uvx",
      "args": [
        "mcp-ssh-orchestrator"
      ],
      "env": {
        "MCP_SSH_KEYS_DIR": "${MCP_SSH_KEYS_DIR}",
        "MCP_SSH_SECRETS_DIR": "${MCP_SSH_SECRETS_DIR}"
      }
    }
  }
}
03

Exposed tools (13)

10 read · 3 write · 0 destructive.

ToolRiskDescription
ssh_cancelreadRequest cancellation for a running task.
ssh_cancel_async_taskreadCancel a running async task.
ssh_describe_hostreadReturn host definition in JSON.
ssh_get_task_outputreadGet recent output lines from running or completed task.
ssh_get_task_resultreadGet final result of completed task (SEP-1686 compliant).
ssh_get_task_statusreadGet current status of an async task (SEP-1686 compliant).
ssh_list_hostsreadList configured hosts.
ssh_pingreadHealth check.
ssh_planreadShow what would be executed and if policy allows.
ssh_reload_configreadReload configuration files.
ssh_runwriteExecute SSH command with policy, network checks, progress, timeout, and cancellation.
ssh_run_asyncwriteStart SSH command asynchronously (SEP-1686 compliant).
ssh_run_on_tagwriteExecute SSH command on all hosts with a tag (with network checks).
04

Trust audit

BLOCKgrade F · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
scripts/docker-smoketest.sh:52
-----BEGIN PRIVATE KEY-----
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
scripts/test-mcp-inspector-errors.sh:81
-----BEGIN PRIVATE KEY-----
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
scripts/docker-smoketest.sh:60
create_key "prod/id_ed25519"
Why it matters. touches a credential store
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.json
.markdownlint.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/release.yml:75
install -d -m 700 ~/.gnupg
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/release.yml:76
printf 'pinentry-mode loopback\n' > ~/.gnupg/gpg.conf
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/release.yml:77
printf 'allow-loopback-pinentry\n' > ~/.gnupg/gpg-agent.conf
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/test_config.py:56
"key_path": "id_ed25519",
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_config.py:449
"../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_config.py:515
"../../outside",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_config.py:516
"../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_config.py:636
"../../outside",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_config.py:637
"../../../etc/passwd",
INFOInventory / provenance · inv.oversize · CWE-1104
assets/demo.gif
assets/demo.gif
Why it matters. 9346158 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/wiki/01-MCP-Overview.md:67
- **Direct shell access** with unlimited privileges
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/wiki/02-Risks.md:50
# Dangerous: Unrestricted access
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/wiki/15-Glossary.md:233
- **Definition**: The act of exploiting a bug or design flaw to gain elevated access
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/wiki/Home.md:31
- **Unrestricted access** leads to lateral movement and data exfiltration
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:164
cat > ~/mcp-ssh/secrets/prod_db_password.txt <<'EOF'
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:170
cat > ~/mcp-ssh/secrets/.env <<'EOF'
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/wiki/06.2-credentials.yml.md:231
2. Read each secret and add to `.env`:
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/wiki/06.2-credentials.yml.md:234
echo "SECRET_NAME=$(cat secrets/SECRET_NAME)" >> secrets/.env
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/wiki/06.2-credentials.yml.md:240
cat secrets/.env
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/wiki/06.2-credentials.yml.md:416
# Or manually add to authorized_keys
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 9e8185e5d7f0full audit observations/trust-audit/mcp-server/samerfarida__ssh-orchestrator.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-089e8185e5d7f0BLOCKF60first audit
06

Questions

What is the SSH Orchestrator MCP server?

Secure SSH access for AI agents via MCP. Execute commands across your server fleet with policy enforcement, network controls, and comprehensive audit logging.

What tools does SSH Orchestrator expose?

13 in total: 10 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SSH Orchestrator safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (60/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does SSH Orchestrator need?

It reads MCP_SSH_KEYS_DIR and MCP_SSH_SECRETS_DIR from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SSH Orchestrator run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-ssh-orchestrator.

How current is this page?

The grade is for one exact copy of the source (9e8185e5d7f0), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement