{"repo":"tufantunc/ssh-mcp","free":true,"listed":false,"github":"https://github.com/tufantunc/ssh-mcp","clone":"git clone https://github.com/tufantunc/ssh-mcp.git","description":"MCP server exposing SSH control for Linux servers via Model Context Protocol.","language":"TypeScript","stars":623,"topics":[],"license":"MIT","category":"mcp-servers","readme_excerpt":"SSH MCP Server v2 SSH MCP Server is a security-first Model Context Protocol server that gives LLM agents controlled SSH access to remote hosts — with command classification, policy-based authorization, human-in-the-loop approval, and full audit logging. The risk this server exists to manage. Giving an LLM shell access on a remote host puts private data, untrusted input and network egress in one place — Simon Willison's \"lethal trifecta\". Prompt injection has no general fix, so ssh-mcp assumes any command may be attacker-influenced: it classifies before executing, authorizes against a role × host-group matrix, gates destructive work behind approval, and records the decision either way. That narrows the blast radius; it does not remove the risk. Two things stay yours: never point it at a root account , and never set auto approval on a production profile . SECURITY.md has the full threat model. --- Quick Start 1. Install 2. Configure Create the config file at the path for your platform: Platform Path --- --- Linux /.config/ssh-mcp/config.toml (or $XDG CONFIG HOME/ssh-mcp/config.toml ) macOS /Library/Application Support/ssh-mcp/config.toml Windows %APPDATA%\\ssh-mcp\\config.toml The config decides which hosts, roles and policy rules this server honours, so it checks that nobody but you can read it — and treats the two platforms differently, because the question has a much clearer answer on one of them. Linux and macOS: enforced. The mode check above, on the file and the directory —","default_branch":null,"files":null,"tree":[],"storefront":"/r/tufantunc","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/tufantunc/ssh-mcp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}