MCP server exposing policy-gated, audited SSH access for Linux and Windows hosts via the Model Context Protocol.
SSH MCP server demonstrates solid definition quality with consistent naming conventions, explicit schemas, and comprehensive parameter descriptions. All 11 tools are properly defined with input schemas and descriptions. Tool names follow verb_noun patterns (read-command, run-command, sftp-upload, etc.). Schemas are well-structured with proper types and constraints. However, output schemas are not explicitly documented in the visible source, descriptions are mostly functional but lack LLM-optimized guidance on when/why to use each tool, and error handling recovery guidance is minimal. Risk annotations (READ_ONLY, WRITE, DESTRUCTIVE) demonstrate security awareness but lack permission gate documentation. The server shows production-ready implementation patterns but misses some polish in guidance and composition.
Session name to close
List all configured SSH connections with their current status and session counts
List all active sessions on a connection
Session name (alphanumeric, dash, underscore, max 64 chars)
Command to execute with sudo
Read-only shell command (must be in the allowlist)
Background session name
Output schemas not explicitly documented in tool definitions
Descriptions lack LLM-optimized context on WHEN to use each tool and dependency hints for multi-step workflows
No explicit error handling guidance or recovery suggestions in tool descriptions (e.g., what to do if command fails, how to retry)
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 31 | - | v1 |
Shell command to execute
Remote file path to download
Remote file path
Process ID to signal (positive integer)
Permission requirements not explicitly documented per tool despite risk classification
Session management tools (open-session, close-session, run-command with session) could benefit from clearer composition guidance