Secure Remote Command Execution via SSH with allowlist-based command filtering
This SSH server has 4 tools with basic naming (all start with ssh_ verb-prefix) and present descriptions. However, significant gaps exist: input schemas lack JSON Schema type annotations; parameter descriptions are minimal or absent in schema format; no output schemas are documented; error messages are user-friendly but lack recovery guidance for agents; no permission gates or audit logging despite security-sensitive operations; no tool annotations (readOnlyHint, destructiveHint, idempotentHint) to guide agent decision-making. The code is well-commented and the allowlist mechanism is sound, but the MCP interface itself is underdeveloped for production agent use.
Executes an allowed command on the remote server via SSH. Args: command: Command to execute (must be in allowlist) Returns: Command output or error message Security: - Only commands matching regex patterns in ALLOWED_COMMANDS will run. - Timeout protection is active. - Uses SSH key authentication.
Shows the current SSH configuration. Returns: Active configuration details
Shows the allowlist of permitted commands. Returns: All regex patterns in the allowlist
Tests the SSH connection. Returns: Connection status and server information
Input and output schemas are not formally documented in JSON Schema format. Tools only define parameter type as 'string' or empty object, with no structured output schemas.
Parameter descriptions are minimal or absent in the schema. LLMs cannot understand constraints, expected formats, or valid ranges. E.g., ssh_exec parameter 'command' description does not document the allowlist patterns or examples of valid commands.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) present. Agents cannot automatically infer whether ssh_exec is safe to retry, whether it modifies state, or what the side effects are.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 42 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 40 | - | v1 |
No permission gates or per-tool scope declarations. ssh_exec is a write operation (RISK: WRITE) but has no checks for agent authorization, no audit logging, and no scope declaration (e.g., 'requires:ssh.exec').
Error messages are human-friendly but lack recovery guidance for agents. E.g., 'DENIED: Command is not in the allowlist' does not tell an agent to call ssh_list_allowed() to discover valid patterns. Error categories (retryable, user-fixable, fatal) are not declared.
Descriptions are too short to provide LLM-optimal context. ssh_test_connection (72 chars), ssh_get_config (42 chars), ssh_list_allowed (62 chars) fall below baseline (avg 194 chars, p10 34, p90 392). Short descriptions risk tool selection ambiguity.