SSH-PowerShell MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@SSH-PowerShell MCP Serverrun 'df -h' on server 192.168.1.100 to check disk space"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
SSH-PowerShell MCP Server
π Enterprise-grade Model Context Protocol (MCP) server for secure SSH and PowerShell command execution with Claude Desktop.
β¨ Features
οΏ½ Secure SSH command execution on remote servers
β‘ Local PowerShell integration for Windows automation
π‘οΈ Enterprise security with SSH key authentication
π Network scanning and SSH port discovery
π SSH key verification and host key scanning
π Comprehensive logging and error handling
π― Claude Desktop optimized for seamless AI integration
Related MCP server: SSH Read-Only MCP Server
οΏ½π Quick Start
# Clone repository
git clone https://github.com/GUEPARD98/MCP-POWERSHELL.git
cd MCP-POWERSHELL
# Install dependencies
npm install
# Configure environment
Copy-Item config\.env.example config\.env
# Edit config\.env with your SSH settings
# Start server
npm startπ Project Structure
MCP-POWERSHELL/
βββ π config/ # Environment configurations
β βββ .env.example # Configuration template
β βββ .env.development # Development settings
β βββ .env.production # Production settings
β βββ .env.test # Test settings
βββ π docs/ # Complete documentation
β βββ README.md # Detailed guide
β βββ API.md # API reference
β βββ ARCHITECTURE.md # Technical architecture
β βββ SECURITY.md # Security best practices
βββ π scripts/ # PowerShell automation scripts
β βββ start.ps1 # Start server
β βββ stop.ps1 # Stop server
β βββ setup.ps1 # Initial setup
β βββ test.ps1 # Run tests
βββ π src/ # Source code
β βββ index.js # Main MCP server
βββ π tests/ # Automated testsπ οΈ Available Commands
Command | Description |
| Start MCP server |
| Run test suite |
| Development mode with PowerShell scripts |
| Initial configuration |
β‘ MCP Tools
π ssh_execute
Execute commands on remote SSH servers
// Example: Run 'ls -la' on remote server
{
"name": "ssh_execute",
"arguments": {
"command": "ls -la",
"host": "192.168.1.100",
"user": "root"
}
}π» powershell_execute
Execute PowerShell commands locally
// Example: Get Windows processes
{
"name": "powershell_execute",
"arguments": {
"command": "Get-Process | Select-Object -First 10"
}
}π ssh_scan
Scan network for SSH services
// Example: Scan local network
{
"name": "ssh_scan",
"arguments": {
"target": "192.168.1.0/24"
}
}π ssh_keyscan
Verify SSH host keys
// Example: Get host key fingerprint
{
"name": "ssh_keyscan",
"arguments": {
"host": "192.168.1.100"
}
}π§ Configuration
Environment Setup
Copy
config/.env.exampletoconfig/.envConfigure your SSH settings:
# SSH Configuration
SSH_KEY_PATH=/path/to/your/ssh/key
SSH_DEFAULT_HOST=your.server.ip
SSH_DEFAULT_USER=your_username
SSH_DEFAULT_PORT=22
# Security Settings
SSH_STRICT_HOST_KEY_CHECKING=no
COMMAND_TIMEOUT=30000
LOG_LEVEL=infoClaude Desktop Integration
The server automatically configures Claude Desktop. Manual setup:
{
"mcpServers": {
"ssh-powershell-mcp": {
"command": "node",
"args": ["path/to/MCP-POWERSHELL/src/index.js"],
"env": {
"NODE_ENV": "production"
}
}
}
}οΏ½ Security
β SSH key authentication only (no passwords)
β Command sanitization with shell-escape
β Environment isolation for different configurations
β Comprehensive input validation
β Secure credential handling
See SECURITY.md for detailed security practices.
π Documentation
Complete Guide - Detailed installation and usage
API Reference - Full MCP API documentation
Architecture - Technical design and diagrams
Security Guide - Security best practices
π§ͺ Testing
# Run all tests
npm test
# Run specific test types
.\scripts\test.ps1 -TestType unit
.\scripts\test.ps1 -TestType integration
.\scripts\test.ps1 -TestType sshπ€ Contributing
Fork the repository
Create feature branch (
git checkout -b feature/amazing-feature)Commit changes (
git commit -m 'Add amazing feature')Push to branch (
git push origin feature/amazing-feature)Open Pull Request
π License
This project is licensed under the MIT License - see the LICENSE file for details.
πββοΈ Support
π Check the documentation
π Report issues on GitHub Issues
π¬ Join discussions in GitHub Discussions
π Acknowledgments
Model Context Protocol for the excellent SDK
Claude Desktop for AI integration capabilities
The open-source community for inspiration and tools
π’ Enterprise Ready | π Secure by Design | β‘ Claude Optimized
Made with β€οΈ by GUEPARD98
Available Tools
4 toolspowershell_executeC
Ejecutar comandos PowerShell localmente
| Name | Required | Description | Default |
|---|---|---|---|
| command | Yes | Comando PowerShell a ejecutar |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden for behavioral disclosure. It states the action ('ejecutar') but lacks critical details: it doesn't specify execution context (e.g., permissions needed, shell environment), potential side effects (e.g., system changes, file modifications), error handling, or output format. For a command execution tool with zero annotation coverage, this is a significant gap in transparency.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence with zero wasted words. It front-loads the core action and context ('Ejecutar comandos PowerShell localmente'), making it immediately understandable. Every word earns its place without redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity of a command execution tool with no annotations and no output schema, the description is incomplete. It lacks essential context: execution environment details, safety warnings (e.g., destructive commands), output handling, and error scenarios. The agent would struggle to use this tool effectively without guessing behavioral aspects.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, with the single parameter 'command' fully documented in the schema. The description adds no additional parameter semantics beyond what the schema provides (e.g., no examples of valid commands, syntax constraints, or security considerations). Baseline 3 is appropriate when the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb ('ejecutar') and resource ('comandos PowerShell'), specifying it operates 'localmente'. It distinguishes from sibling tools like ssh_execute by indicating local rather than remote execution. However, it doesn't explicitly differentiate from other potential local command execution tools beyond the sibling context.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It mentions 'localmente' which implicitly contrasts with SSH-based siblings, but offers no explicit when/when-not criteria, prerequisites, or comparison to other local execution methods. This leaves the agent with minimal usage direction.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ssh_executeC
Ejecutar comandos en mΓ‘quinas remotas vΓa SSH usando clave SSH
| Name | Required | Description | Default |
|---|---|---|---|
| command | Yes | Comando a ejecutar en el servidor remoto | |
| host | Yes | DirecciΓ³n IP o hostname del servidor remoto | |
| keyPath | No | Ruta a la clave SSH privada (opcional) | |
| user | Yes | Nombre de usuario para SSH |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden for behavioral disclosure. It states the tool executes commands via SSH with key authentication, implying mutation and potential security/permission needs, but doesn't cover execution timeouts, error handling, output format, or side effects. For a command execution tool with zero annotation coverage, this is inadequate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence in Spanish that directly states the tool's function without unnecessary words. It's appropriately sized and front-loaded with the core purpose.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given this is a command execution tool with no annotations and no output schema, the description is incomplete. It doesn't explain what the tool returns (e.g., stdout, stderr, exit code), error conditions, security implications, or execution environment. For a tool that can have significant side effects, more context is needed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all 4 parameters thoroughly. The description adds no additional parameter context beyond implying SSH key usage relates to keyPath. Since the schema does the heavy lifting, baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Ejecutar comandos') and target ('en mΓ‘quinas remotas vΓa SSH'), specifying the authentication method ('usando clave SSH'). It distinguishes from sibling tools like powershell_execute (different protocol) and ssh_keyscan/ssh_scan (different operations). However, it doesn't explicitly mention what type of commands or their scope, keeping it at 4 rather than 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives like powershell_execute or ssh_keyscan. It mentions SSH key usage but doesn't explain prerequisites, error conditions, or typical use cases. Without any when/when-not context, this scores a 2.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ssh_keyscanC
Obtener fingerprint de claves SSH de un host
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | Host para obtener claves SSH |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It states the action ('obtener fingerprint') but doesn't describe what the tool returns (e.g., format of the fingerprint), error conditions, network behavior, or security implications. This is a significant gap for a tool that interacts with SSH keys.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that directly states the tool's purpose without unnecessary words. It is appropriately sized and front-loaded, making it easy to parse quickly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity of SSH key operations and the lack of annotations and output schema, the description is incomplete. It doesn't explain what the fingerprint output looks like, potential errors, or how it differs from sibling tools, leaving the agent with insufficient context for reliable use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, with the single parameter 'host' documented as 'Host para obtener claves SSH'. The description adds no additional meaning beyond this, such as examples or constraints, so it meets the baseline for adequate but not enhanced parameter semantics.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb ('obtener fingerprint') and resource ('claves SSH de un host'), making the purpose understandable. However, it doesn't explicitly differentiate this tool from sibling tools like 'ssh_scan' or 'ssh_execute', which might have overlapping or related functionality.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives like 'ssh_scan' or 'ssh_execute'. It lacks context about prerequisites, typical use cases, or exclusions, leaving the agent to infer usage from the tool name and description alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ssh_scanC
Escanear red para encontrar hosts SSH disponibles
| Name | Required | Description | Default |
|---|---|---|---|
| network | Yes | Red a escanear (ej: 192.168.1.0/24) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It states the tool scans for available SSH hosts but doesn't mention critical behaviors like whether it's read-only (likely, but not confirmed), network impact (e.g., bandwidth usage or potential intrusion detection triggers), output format, or error handling. This leaves significant gaps for an agent to understand operational implications.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that directly states the tool's purpose without unnecessary words. It's appropriately sized and front-loaded, making it easy for an agent to parse quickly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity of a network scanning tool with no annotations and no output schema, the description is insufficient. It lacks details on what 'available SSH hosts' means (e.g., open port 22, SSH service responding), how results are returned, potential side effects, or security considerations. This leaves the agent with incomplete context for safe and effective use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage, with the 'network' parameter clearly documented in the schema itself. The description doesn't add any meaningful parameter semantics beyond what the schema provides (e.g., no examples of valid networks beyond the schema's example, no clarification on format requirements). This meets the baseline for high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('escanear' meaning 'scan') and target ('red para encontrar hosts SSH disponibles' meaning 'network to find available SSH hosts'), providing a specific verb+resource combination. However, it doesn't explicitly differentiate from sibling tools like 'ssh_keyscan' or 'ssh_execute', which prevents a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives like 'ssh_keyscan' (which might scan for SSH keys) or 'ssh_execute' (which executes commands via SSH). There's no mention of prerequisites, limitations, or typical use cases beyond the basic purpose.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
4 tool updates
v1.0.0- First observed
powershell_execute - First observed
ssh_execute - First observed
ssh_keyscan - First observed
ssh_scan
TDQS
Scored across 4 tools
Each tool has a clearly distinct purpose: powershell_execute is for local PowerShell commands, ssh_execute is for remote SSH command execution, ssh_keyscan retrieves SSH key fingerprints, and ssh_scan discovers SSH hosts on a network. There is no overlap or ambiguity between these functions.
All tool names follow a consistent snake_case pattern with a clear verb_noun structure: powershell_execute, ssh_execute, ssh_keyscan, ssh_scan. The naming is uniform and predictable across all tools.
With 4 tools, the count is reasonable for an SSH/PowerShell server, covering core remote execution and SSH management tasks. It might be slightly thin for advanced scenarios (e.g., missing file transfer or session management), but it's well-scoped for basic operations.
The toolset covers key SSH and PowerShell operations: remote command execution, host discovery, and key verification. Minor gaps exist, such as no file transfer (e.g., SCP/SFTP) or SSH configuration management, but agents can work around these with the provided tools for most workflows.
Maintenance
Related MCP Connectors
Scoped, audited SSH exec, sessions, and SFTP on your saved servers without exposing credentials
- emisarOAuthdev.emisar
Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
AI-powered corporate learning platform β manage courses, users, and insights via Claude.
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables SSH remote access to servers through Claude, allowing users to execute commands, transfer files via SFTP, and manage multiple remote connections using natural language.128MIT
- FlicenseAqualityDmaintenanceEnables secure remote SSH command execution with strict read-only enforcement, allowing safe delegation of SSH access to Claude while preventing write operations. Supports connection pooling, command validation, and comprehensive logging for audit trails.51-
- AlicenseAqualityCmaintenanceSSH/SFTP server enabling remote command execution and secure file transfers, with integration for Claude AI.1816 npm2MIT
- -licenseNot gradedqualityNot gradedmaintenanceEnables Claude Code to control remote servers via SSH for automated deployment, testing, and operations, including command execution and file transfer.4-