ssh-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SSH_CONFIG_PATH | No | Path to the OpenSSH client config | ~/.ssh/config |
| SSH_MCP_MAX_OUTPUT | No | Max bytes kept per output stream before truncation | 65536 |
| SSH_MCP_IDLE_TIMEOUT | No | How long an idle pooled connection is kept (ms) | 120000 |
| SSH_MCP_COMMAND_TIMEOUT | No | Default ssh_exec timeout (ms) | 30000 |
| SSH_MCP_OPERATION_TIMEOUT | No | Per-operation SFTP timeout (ms) | 30000 |
| SSH_MCP_CONNECTION_TIMEOUT | No | SSH connection timeout (ms) | 10000 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| ssh_execA | Run a shell command on a remote machine over SSH. |
| ssh_read_fileA | Read the contents of a text file on a remote SSH host. Large files are truncated at a configured size limit; for very large files prefer ssh_exec with head/tail/grep. |
| ssh_write_fileB | Write text to a file on a remote SSH host. The write is atomic (temporary file, then rename), so a failed or interrupted write never leaves a partially-written destination. Parent directories are NOT created automatically. |
| ssh_list_directoryA | List the contents of a directory on a remote SSH host (defaults to the remote user's home directory). Each entry includes type, size, permission bits and modification time. |
| ssh_hostsA | List the SSH host aliases available in the local SSH client configuration (~/.ssh/config). Use these aliases as the |
| ssh_statA | Get metadata about a file or directory on a remote SSH host: type, size, permissions, modification time, owner/group ids. |
| ssh_tunnelA | Start a persistent local port-forward through the pooled SSH connection for |
| ssh_tunnelsB | List currently open SSH port-forward tunnels. |
| ssh_tunnel_stopA | Stop a port-forward tunnel by id (from ssh_tunnel / ssh_tunnels). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 9 tools
Each tool targets a distinct operation: file read/write, command execution, directory listing, metadata stat, host enumeration, and tunnel start/list/stop. The tunnel trio (ssh_tunnel, ssh_tunnels, ssh_tunnel_stop) is clearly differentiated by verb, and file/metadata tools do not overlap. No realistic misselection risk.
All tools use a consistent `ssh_` snake_case prefix, which is strong. Minor deviations exist: some are verb_noun (ssh_read_file, ssh_list_directory), some are bare resource plurals (ssh_hosts, ssh_tunnels), and ssh_tunnel_stop puts the verb last instead of following the verb_noun pattern.
Nine tools is well-scoped for an SSH remote-operations server. Each tool covers a distinct capability (file I/O, exec, directory listing, stat, hosts, tunnel lifecycle) without redundancy or bloat.
The surface covers core SSH workflows: read, write, execute, list, stat, host discovery, and tunnel lifecycle. Gaps exist for dedicated delete, mkdir, move, and binary/SCP-style transfer, but most of these are workable via ssh_exec with shell commands.