SSH MCP server: run remote commands, transfer files over SFTP, manage ssh-agent keys and known_hosts, and auto-diagnose SSH failures.
This SSH MCP server demonstrates solid engineering with consistent parameter naming, comprehensive descriptions, and well-defined schemas across all 13 tools. Tool names follow verb-noun convention (ssh_exec, ssh_read_file, ssh_delete_file, etc.) with clear action semantics. All tools have detailed descriptions (150-300+ chars) explaining what they do, when to use them, and key constraints. Input schemas are properly typed with Zod validation (z.string(), z.number(), z.record()) and include meaningful parameter descriptions. However, the server lacks error handling guidance (no recovery hints, no error categorization), output schemas are not documented in code, and there are moderate security concerns around password handling that should be surfaced more prominently. The server is well-executed for a STDIO tool but falls short of production A-grade due to missing error recovery patterns and output documentation.
Delete a file from a remote host via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting. NOT gated by SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST: command policy applies only to ssh_exec and ssh_multi_exec, so a blacklist such as `^rm` does NOT block this tool.
Diagnose SSH connectivity issues. Checks SSH configuration, keys, ssh-agent, known_hosts, and attempted connection to help identify problems. Returns a detailed diagnostic report.
Download a file from a remote host via SFTP and return its content as base64. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.
Execute a command on a remote host via SSH. The command is interpreted by the remote login shell — pipes, redirects, globs, and other shell metacharacters work as expected. Returns stdout, stderr, and exit code. Use `env` to set environment variables for this call without modifying the command string. Subject to SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST if configured (policy is checked against the env-prefixed command).
Find files matching patterns on a remote host (like `find`). Supports filtering by name, type, size, and time. NOT gated by SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST: command policy applies only to ssh_exec and ssh_multi_exec, so a blacklist does NOT block this tool.
No documented output schemas. The code shows input schemas via Zod but does not document what each tool returns. LLMs cannot plan downstream tool calls without knowing return field names and types. Critical for tool composition and chaining.
No error recovery guidance. Error descriptions do not tell LLMs what to do next. Example: ssh_exec can fail with connection timeout, authentication failure, command not found, permission denied, but tool description does not explain which are retryable, which require a different authentication method, or which are fatal. Compare to: 'Connection timeout (retryable), increase timeout parameter or check network. Auth failed (fatal), verify privateKeyPath or password.'
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 69 | 2026-07-28+ | v2 |
List files in a remote directory via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.
Create a directory (and parents) on a remote host via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting. NOT gated by SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST: command policy applies only to ssh_exec and ssh_multi_exec, so a blacklist such as `^mkdir` does NOT block this tool.
Execute a command on multiple remote hosts in parallel via SSH. Each host can have its own authentication credentials. Returns results per host with stdout, stderr, and exit code. Subject to SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST if configured (policy is checked against the env-prefixed command).
Read a file from a remote host via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.
Get file metadata (size, permissions, timestamps) from a remote host via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.
Tail the last N lines of a file on a remote host (like `tail -f`). Returns the last N lines or lines after a byte offset. NOT gated by SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST: command policy applies only to ssh_exec and ssh_multi_exec, so a blacklist does NOT block this tool.
Upload a file to a remote host via SFTP. File content is provided as base64. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.
Write a file to a remote host via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.
Password parameter security warning buried in description. Tools accept plaintext passwords as parameters, which is a critical security anti-pattern (passwords enter MCP frames and logs). This deserves a PROMINENT warning at tool registration time, not hidden in parameter text. Consider rejecting password parameters entirely and enforcing ssh-agent or privateKeyPath only in production.
Undocumented mutual exclusivity and parameter relationships. ssh_exec allows both 'password' and 'privateKeyPath', which takes precedence? Can both be provided? This ambiguity forces LLMs to guess. Similarly, 'env' parameters are described but their interaction with command-line arguments is not documented.
Multi-host tool (ssh_multi_exec) lacks per-host output documentation. The description says 'Returns results per host' but does not specify the structure (array of {host, stdout, stderr, exit_code}?) or how errors are aggregated (all-or-nothing, partial success, per-host errors?).
Policy exemption notes (POLICY_EXEMPT_NOTE) appear in descriptions for ssh_delete_file, ssh_mkdir, ssh_tail, ssh_find but not for SFTP operations (read_file, write_file, etc.). This is inconsistent and leaves callers uncertain about which tools are gated by SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST.
timeout parameter only present on ssh_exec and ssh_multi_exec. Other SFTP tools (read_file, write_file, etc.) have a hard 30s pool wait but no way to override it. Documentation notes this in SFTP_POOL_WAIT_NOTE, but an LLM cannot adjust timeout for slow network scenarios.