Ssh Mcp

security MCP Server

SSH MCP server that runs locally making it easy to manage hosts and perform commands across a group of hosts

Install Ready
securitysecurity
6 views20 stars4 forksMIT

Why This Matters

Discovered via unknown and last synced 1w ago.

Install Ready
Source
unknown
Stars
20
Last synced
1w ago
Install
Instructions detected

Install

1. Add to claude_desktop_config.json

{
  "mcpServers": {
    "ssh-mcp": {
      "command": "uvx",
      "args": [
        "blc-ssh-mcp"
      ]
    }
  }
}

Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)

41
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (41)

SSH_MCP_HTTP_HOST

`127.0.0.1`

SSH_MCP_HTTP_STATELESS

`false`

download_file

Download a file from a server via SFTP (validates both local and remote paths)

SSH_MCP_HTTP_PORT

`8000`

SSH_MCP_HTTP_ALLOWED_HOSTS

—

SSH_MCP_HTTP_AUTH

`bearer`

list_servers

List configured servers; optionally filter by group

SSH_MCP_HTTP_BACKLOG

`128`

upload_file

Upload a local file to a server via SFTP (validates both local and remote paths)

Tool

will not be available at all if server is started with `--disableSudo`

execute_on_group

Run a command on all servers in a group (parallel; supports `fail_fast` and `force`)

get_os_info

Retrieves the cached operating system information for Linux and Windows hosts. You can specify individual hosts or an entire group.

update_os_info

Updates the cached operating system information for Linux and Windows hosts. You can specify individual hosts or an entire group.

remove_host

Removes a host from the SSH configuration by group and name.

get_groups

Retrieves the list of all groups from the SSH configuration.

Can

be disabled by passing the `--disableSudo` flag at startup if sudo access is not needed or not available

Variable

Default

list_groups

List server groups with member counts

SSH_MCP_HTTP_TOKEN

—

HYPOTHESIS_PROFILE

`dev`

SSH_MCP_CONFIG

—

SSH_MCP_HTTP_KEEPALIVE_TIMEOUT

`2`

execute

Run a shell command on a single server (supports `force` to bypass dangerous-command detection)

SSH_MCP_LOG_FORMAT

`console`

SSH_MCP_HTTP_LIMIT_CONCURRENCY

`256`

SSH_MCP_HTTP_TOKEN_FILE

—

SSH_MCP_TRANSPORT

`stdio`

SSH_MCP_HTTP_NETWORK_NO_AUTH

—

get_hosts

Retrieves the list of hosts from the SSH configuration. Can optionally filter by group.

add_host

Adds a new Linux or Windows host to the SSH configuration with automatic OS detection. Username and password are optional in the connection string - if not provided, the current user and SSH agent will be used for authentication.

description

(optional): Optional description of what this command will do (appended as a comment)

Default

`1000`

Timeout Configuration:

Timeout is configured via command line argument `--timeout` (in milliseconds)

When

a command times out, the server automatically attempts to abort the running process before closing the connection

exec

Execute a shell command on the remote server

For

persistent root access, consider using `--suPassword` instead which establishes a root shell

Notes:

Requires `--sudoPassword` to be set for password-protected sudo

No-limit

mode: set `--maxChars=none` or any `<= 0` value (e.g. `--maxChars=0`)

Parameters:

`command` (required): Shell command to execute as root using sudo

Max Command Length Configuration:

Max command characters are configured via `--maxChars`

bypass

a match, the preview carries an explicit `⚠️ DANGEROUS` banner.