SSH hub MCP server for managing SSH projects, hosts, and sessions with remote command execution
sshub-mcp demonstrates solid tool design with clear naming (verb_noun pattern), comprehensive descriptions (150-250 chars each), and well-structured input schemas. All 6 tools have explicit type definitions and parameter descriptions. However, output schemas are not documented in the source code, and error handling guidance is absent. Tool composition is excellent, list_projects → list_hosts → ssh_create_session → ssh_exec forms a logical chain with proper ID threading. No security issues detected (no credentials in params). Descriptions are LLM-optimized and include prerequisites ('Call this first'). Missing: documented return types, error recovery guidance, and pagination support for list operations.
List SSH hosts for a project. Requires project_id from list_projects. Returns hosts with their IDs, names, addresses, and usernames — use host_id when opening a session.
List projects the user has access to. Call this first to discover available projects before listing hosts or creating SSH sessions. Returns project IDs and names.
Close an SSH session and release resources. Requires session_id. Call when done with a host to free the connection.
Open an SSH session to a host. Requires project_id and host_id from list_hosts. Returns session_id — use it with ssh_exec to run commands. One session per host; shell state (cwd, env) is preserved between ssh_exec calls.
Execute a shell command in an existing SSH session. Requires session_id from ssh_create_session and the command string. Output is returned as plain text. Working directory and exported env vars are preserved between calls.
Output schemas not documented. LLMs cannot infer what fields list_projects, list_hosts, ssh_exec, and ssh_list_sessions return, forcing them to guess at response structure and downstream field names.
No error handling guidance. Tools lack descriptions of failure modes, recovery steps, or actionable error messages. E.g., ssh_create_session should document what happens if the host is unreachable or authentication fails.
No pagination support. list_projects, list_hosts, and ssh_list_sessions lack limit/offset or cursor parameters. Large result sets will blow context windows without pagination.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | A | 85 | 2026-07-28+ | v2 |
List active SSH sessions for a project. Requires project_id. Use to see which sessions are open or to find a session_id for ssh_exec or ssh_close_session.
ssh_exec lacks idempotency guidance. Descriptions do not clarify whether repeated calls with the same command are safe to retry or if they have side effects (e.g., 'rm -rf' executed twice).
No confirmation pattern for destructive operations. ssh_exec can run destructive commands (rm, shutdown, etc.) without a dry-run or confirmation step, risking accidental data loss.