Skip to main content
Glama

manage_remote_hosts

Destructive

Add, list, test, or remove SSH hosts so run_tool can execute security tools remotely on Kali/Linux instead of locally.

Instructions

Add, list, test, or remove the SSH hosts that run_tool can target remotely.

Manages the remote-host registry that lets run_tool (and check_installed) run a tool on a remote Kali/Linux box over SSH instead of locally, so the tool only has to be installed on the remote. The action selects the operation: "list" shows every configured host; "add" registers or updates a host (needs name and hostname, plus optional user, port, ssh_key, and a tool_allowlist that restricts which tools may run there); "remove" deletes a host by name; "test" opens an SSH connection to confirm the host is reachable.

Connections use StrictHostKeyChecking=accept-new, so the key presented on the first connection is pinned in ~/.ssh/known_hosts and any later change is rejected. Verify that first fingerprint out-of-band for a host you do not control, or add the key to known_hosts before "test".

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNoHost name (required for add/remove/test).
portNoSSH port (default 22).
userNoSSH username (default "kali").kali
actionYesOperation to perform: "list", "add", "remove", or "test".
ssh_keyNoPath to SSH private key (e.g. "~/.ssh/id_kali").
hostnameNoIP address or hostname of the remote machine (required for add).
descriptionNoHuman-readable description of the host.
tool_allowlistNoComma-separated list of allowed tool names (e.g. "nmap,gobuster,sqlmap"). None means all tools allowed.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changedv1.2.1
    • changedInput schema / properties / action / description
      Previous value: -"One of \"list\", \"add\", \"remove\", \"test\"."New value: +"Operation to perform: \"list\", \"add\", \"remove\", or \"test\"."
    • addedInput schema / properties / action / enum
      Added value: +[
      +  "list",
      +  "add",
      +  "remove",
      +  "test"
      +]
  2. First observedv1.2.0

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already flag destructive/openWorld/non-idempotent, and the description adds genuinely new behavioral context: the StrictHostKeyChecking=accept-new policy, that the first-seen key is pinned in ~/.ssh/known_hosts and later changes are rejected, and the out-of-band fingerprint verification advice. That is security-relevant disclosure beyond the structured fields.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads purpose, then enumerates actions, then ends with the SSH key-pinning caveat. Every paragraph adds information, though the per-action enumeration is dense and slightly overlaps the schema's own descriptions.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a multi-action mutation tool with side effects, an output schema present (so returns need no explanation), and full annotation coverage, the description supplies the missing pieces: action semantics, credential requirements, and the connection-security caveat. An agent has enough to select actions and call them correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% so the baseline is 3, but the description adds real meaning: which parameters each action requires (name for add/remove/test, hostname for add) and what tool_allowlist actually does (restricts which tools may run on that host, with None meaning all). It stops short of restating defaults like user='kali' or port=22.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Starts with a specific verb set (add/list/test/remove) and a concrete resource (SSH remote hosts), and names the dependent sibling tools run_tool and check_installed. An agent can immediately distinguish this registry-management tool from the execution tools in the sibling list.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explains that the action parameter selects the operation and gives per-action conditions (add needs name+hostname, remove takes a name, test opens a connection), plus the prerequisite context that hosts enable remote execution via run_tool. It does not, however, state explicit when-not-to-use cases or an ordering rule such as 'add before test before run_tool'.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.