VibeShellBLOCK
Local-first SSH/SFTP workspace for humans and coding agents: visible operations, shared sessions, integrated files and discoverable plugins.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
VibeShell Keep your servers, files, and AI work in the same place. An SSH terminal you can work in yourself, share with an agent, and make your own.
English · 简体中文 · 日本語
[](https://github.com/veithly/vibeshell/actions/workflows/ci.yml) [](https://github.com/veithly/vibeshell/releases) [](LICENSE)
Download · Agent / CLI guide · Changelog · Contribute
Real VibeShell components, synthetic Northstar demo data. The gallery uses an isolated browser fixture: no live servers, credentials, model calls, or service restarts. Agent transcripts and command results are examples, not recordings of an actual agent run. Reproduce the screenshots.
Less passing context between tools
A routine server task rarely stays in one terminal. You check a log, find a configuration file, open an editor, ask an agent for help, then work out which machine and session each tool is using.
VibeShell keeps that work together. SSH and local terminals, coding agents, remote files, Git changes, and operations dashboards share a tabbed workspace. Use it as a normal terminal; bring AI into the parts where it helps. You do not need a model account for ordinary terminal and file work.
The difference is the workflow, not a new SSH protocol. OpenSSH, tmux, editors and scripts can cover m
d6bee0e435f8OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add vibeshell --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"vibeshell": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
}
}
}
}Exposed tools (20)
20 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Containers | read | List containers |
DISPLAY | read | X display server |
EDITOR | read | Default text editor |
HOME | read | User home directory |
HOSTNAME | read | System hostname |
LANG | read | System language |
LC_ALL | read | Locale setting |
LOGNAME | read | Login name |
PATH | read | Executable search path |
PWD | read | Present working directory |
SHELL | read | Current shell |
SSH_AUTH_SOCK | read | SSH agent socket |
SSH_CLIENT | read | SSH client info |
SSH_CONNECTION | read | SSH connection info |
TERM | read | Terminal type |
TMPDIR | read | Temporary directory |
USER | read | Current username |
XDG_CACHE_HOME | read | XDG cache directory |
XDG_CONFIG_HOME | read | XDG config directory |
XDG_DATA_HOME | read | XDG data directory |
Trust audit
BLOCKgrade F · trust 23/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (20 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
b64decode( ... subprocess.
"-----BEGIN OPENSSH PRIVATE KEY-----\nkey\n-----END OPENSSH PRIVATE KEY-----\n";
- Report the server name, session alias, command exit status, and relevant output. Do not claim success from command submission alone.
- Report the server name, session alias, command exit status, and relevant output. Do not claim success from command submission alone.
pub fn exec(session_id: &str, command: &[String]) -> Result<()> {Exec(ExecArgs),
Some(Commands::Exec(args)) => {commands::session::exec(&resolved, &command)
cat "$fixture/ed25519.pub" "$fixture/rsa.pub" "$fixture/ecdsa.pub" "$fixture/encrypted.pub" "$fixture/rsa-pem.pub" > "$fixture/authorized_keys"
docker cp "$fixture/authorized_keys" "$container:/home/audit/.ssh/authorized_keys"
docker exec "$container" sh -c 'chown audit:audit /home/audit/.ssh/authorized_keys; chmod 600 /home/audit/.ssh/authorized_keys'
let key_path = temp_dir.path().join("id_ed25519");let key_path = temp.path().join("id_ed25519");icon.icns
const markdown = `# Northstar deployment notes\n\nA small runbook, kept next to the terminal.\n\n## Before you deploy\n\n- [x] Review the retry change\n- [x] Check the staging health endpoint\n- [ ] A
['cli:session_exec', 'curl -fsS http://127.0.0.1:8080/health', 'demo-session-api'],
case 'get_agent_gateway_status': return { running: true, endpoint: 'http://127.0.0.1:0/demo-only', manifestPath: '/demo/agent-gateway.json', pid: null, protocolVersion: '2024-11-05' };endpoint: "http://127.0.0.1:8080/vibeshell.json".to_string(),
import { useState, useEffect, useCallback, useRef, memo } from 'react';useSessionStore.setState({ sessions: [{ ...session, password: 'never-store-password' } as Session], activeSessionId: 'new' });include_str!("../../NOTICE"),include_str!("../../LICENSE")assert!(include_str!("../../LICENSE").contains("Version 3, 29 June 2007"));let example = include_str!("../../examples/plugins/system-info/plugin.json");import type { PluginManifest, PluginRecord } from '../../src/plugins/types';Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
d6bee0e435f8full audit observations/trust-audit/mcp-server/veithly__vibeshell.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d6bee0e435f8 | BLOCK | F | 23 | first audit |
Questions
What is the VibeShell MCP server?
Local-first SSH/SFTP workspace for humans and coding agents: visible operations, shared sessions, integrated files and discoverable plugins.
What tools does VibeShell expose?
20 in total: 20 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is VibeShell safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (23/100) and found 13 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does VibeShell need?
It reads GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (d6bee0e435f8), read on 2026-10-07. The repository is watched and re-audited when it changes.