Skip to main content
Glama
GUEPARD98

SSH-PowerShell MCP Server

by GUEPARD98

SSH-PowerShell MCP Server

πŸš€ Enterprise-grade Model Context Protocol (MCP) server for secure SSH and PowerShell command execution with Claude Desktop.

License: MIT Node.js Version MCP SDK

✨ Features

  • οΏ½ Secure SSH command execution on remote servers

  • ⚑ Local PowerShell integration for Windows automation

  • πŸ›‘οΈ Enterprise security with SSH key authentication

  • 🌐 Network scanning and SSH port discovery

  • πŸ” SSH key verification and host key scanning

  • πŸ“Š Comprehensive logging and error handling

  • 🎯 Claude Desktop optimized for seamless AI integration

Related MCP server: SSH Read-Only MCP Server

οΏ½πŸš€ Quick Start

# Clone repository
git clone https://github.com/GUEPARD98/MCP-POWERSHELL.git
cd MCP-POWERSHELL

# Install dependencies
npm install

# Configure environment
Copy-Item config\.env.example config\.env
# Edit config\.env with your SSH settings

# Start server
npm start

πŸ“ Project Structure

MCP-POWERSHELL/
β”œβ”€β”€ πŸ“ config/           # Environment configurations
β”‚   β”œβ”€β”€ .env.example     # Configuration template
β”‚   β”œβ”€β”€ .env.development # Development settings
β”‚   β”œβ”€β”€ .env.production  # Production settings
β”‚   └── .env.test       # Test settings
β”œβ”€β”€ πŸ“ docs/            # Complete documentation
β”‚   β”œβ”€β”€ README.md       # Detailed guide
β”‚   β”œβ”€β”€ API.md          # API reference
β”‚   β”œβ”€β”€ ARCHITECTURE.md # Technical architecture
β”‚   └── SECURITY.md     # Security best practices
β”œβ”€β”€ πŸ“ scripts/         # PowerShell automation scripts
β”‚   β”œβ”€β”€ start.ps1       # Start server
β”‚   β”œβ”€β”€ stop.ps1        # Stop server
β”‚   β”œβ”€β”€ setup.ps1       # Initial setup
β”‚   └── test.ps1        # Run tests
β”œβ”€β”€ πŸ“ src/             # Source code
β”‚   └── index.js        # Main MCP server
└── πŸ“ tests/           # Automated tests

πŸ› οΈ Available Commands

Command

Description

npm start

Start MCP server

npm test

Run test suite

npm run dev

Development mode with PowerShell scripts

npm run setup

Initial configuration

⚑ MCP Tools

πŸ” ssh_execute

Execute commands on remote SSH servers

// Example: Run 'ls -la' on remote server
{
  "name": "ssh_execute",
  "arguments": {
    "command": "ls -la",
    "host": "192.168.1.100", 
    "user": "root"
  }
}

πŸ’» powershell_execute

Execute PowerShell commands locally

// Example: Get Windows processes
{
  "name": "powershell_execute",
  "arguments": {
    "command": "Get-Process | Select-Object -First 10"
  }
}

🌐 ssh_scan

Scan network for SSH services

// Example: Scan local network
{
  "name": "ssh_scan", 
  "arguments": {
    "target": "192.168.1.0/24"
  }
}

πŸ” ssh_keyscan

Verify SSH host keys

// Example: Get host key fingerprint
{
  "name": "ssh_keyscan",
  "arguments": {
    "host": "192.168.1.100"
  }
}

πŸ”§ Configuration

Environment Setup

  1. Copy config/.env.example to config/.env

  2. Configure your SSH settings:

# SSH Configuration
SSH_KEY_PATH=/path/to/your/ssh/key
SSH_DEFAULT_HOST=your.server.ip
SSH_DEFAULT_USER=your_username
SSH_DEFAULT_PORT=22

# Security Settings  
SSH_STRICT_HOST_KEY_CHECKING=no
COMMAND_TIMEOUT=30000
LOG_LEVEL=info

Claude Desktop Integration

The server automatically configures Claude Desktop. Manual setup:

{
  "mcpServers": {
    "ssh-powershell-mcp": {
      "command": "node",
      "args": ["path/to/MCP-POWERSHELL/src/index.js"],
      "env": {
        "NODE_ENV": "production"
      }
    }
  }
}

οΏ½ Security

  • βœ… SSH key authentication only (no passwords)

  • βœ… Command sanitization with shell-escape

  • βœ… Environment isolation for different configurations

  • βœ… Comprehensive input validation

  • βœ… Secure credential handling

See SECURITY.md for detailed security practices.

πŸ“š Documentation

πŸ§ͺ Testing

# Run all tests
npm test

# Run specific test types
.\scripts\test.ps1 -TestType unit
.\scripts\test.ps1 -TestType integration
.\scripts\test.ps1 -TestType ssh

🀝 Contributing

  1. Fork the repository

  2. Create feature branch (git checkout -b feature/amazing-feature)

  3. Commit changes (git commit -m 'Add amazing feature')

  4. Push to branch (git push origin feature/amazing-feature)

  5. Open Pull Request

πŸ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

πŸ™‹β€β™‚οΈ Support

πŸ† Acknowledgments


🏒 Enterprise Ready | πŸ”’ Secure by Design | ⚑ Claude Optimized

Made with ❀️ by GUEPARD98

Available Tools

4 tools
powershell_executeC

Ejecutar comandos PowerShell localmente

ParametersJSON Schema
NameRequiredDescriptionDefault
commandYesComando PowerShell a ejecutar

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries full burden for behavioral disclosure. It states the action ('ejecutar') but lacks critical details: it doesn't specify execution context (e.g., permissions needed, shell environment), potential side effects (e.g., system changes, file modifications), error handling, or output format. For a command execution tool with zero annotation coverage, this is a significant gap in transparency.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, efficient sentence with zero wasted words. It front-loads the core action and context ('Ejecutar comandos PowerShell localmente'), making it immediately understandable. Every word earns its place without redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity of a command execution tool with no annotations and no output schema, the description is incomplete. It lacks essential context: execution environment details, safety warnings (e.g., destructive commands), output handling, and error scenarios. The agent would struggle to use this tool effectively without guessing behavioral aspects.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with the single parameter 'command' fully documented in the schema. The description adds no additional parameter semantics beyond what the schema provides (e.g., no examples of valid commands, syntax constraints, or security considerations). Baseline 3 is appropriate when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb ('ejecutar') and resource ('comandos PowerShell'), specifying it operates 'localmente'. It distinguishes from sibling tools like ssh_execute by indicating local rather than remote execution. However, it doesn't explicitly differentiate from other potential local command execution tools beyond the sibling context.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives. It mentions 'localmente' which implicitly contrasts with SSH-based siblings, but offers no explicit when/when-not criteria, prerequisites, or comparison to other local execution methods. This leaves the agent with minimal usage direction.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

ssh_executeC

Ejecutar comandos en mΓ‘quinas remotas vΓ­a SSH usando clave SSH

ParametersJSON Schema
NameRequiredDescriptionDefault
commandYesComando a ejecutar en el servidor remoto
hostYesDirecciΓ³n IP o hostname del servidor remoto
keyPathNoRuta a la clave SSH privada (opcional)
userYesNombre de usuario para SSH

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries full burden for behavioral disclosure. It states the tool executes commands via SSH with key authentication, implying mutation and potential security/permission needs, but doesn't cover execution timeouts, error handling, output format, or side effects. For a command execution tool with zero annotation coverage, this is inadequate.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, efficient sentence in Spanish that directly states the tool's function without unnecessary words. It's appropriately sized and front-loaded with the core purpose.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given this is a command execution tool with no annotations and no output schema, the description is incomplete. It doesn't explain what the tool returns (e.g., stdout, stderr, exit code), error conditions, security implications, or execution environment. For a tool that can have significant side effects, more context is needed.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all 4 parameters thoroughly. The description adds no additional parameter context beyond implying SSH key usage relates to keyPath. Since the schema does the heavy lifting, baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action ('Ejecutar comandos') and target ('en mΓ‘quinas remotas vΓ­a SSH'), specifying the authentication method ('usando clave SSH'). It distinguishes from sibling tools like powershell_execute (different protocol) and ssh_keyscan/ssh_scan (different operations). However, it doesn't explicitly mention what type of commands or their scope, keeping it at 4 rather than 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives like powershell_execute or ssh_keyscan. It mentions SSH key usage but doesn't explain prerequisites, error conditions, or typical use cases. Without any when/when-not context, this scores a 2.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

ssh_keyscanC

Obtener fingerprint de claves SSH de un host

ParametersJSON Schema
NameRequiredDescriptionDefault
hostYesHost para obtener claves SSH

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It states the action ('obtener fingerprint') but doesn't describe what the tool returns (e.g., format of the fingerprint), error conditions, network behavior, or security implications. This is a significant gap for a tool that interacts with SSH keys.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, efficient sentence that directly states the tool's purpose without unnecessary words. It is appropriately sized and front-loaded, making it easy to parse quickly.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity of SSH key operations and the lack of annotations and output schema, the description is incomplete. It doesn't explain what the fingerprint output looks like, potential errors, or how it differs from sibling tools, leaving the agent with insufficient context for reliable use.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with the single parameter 'host' documented as 'Host para obtener claves SSH'. The description adds no additional meaning beyond this, such as examples or constraints, so it meets the baseline for adequate but not enhanced parameter semantics.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb ('obtener fingerprint') and resource ('claves SSH de un host'), making the purpose understandable. However, it doesn't explicitly differentiate this tool from sibling tools like 'ssh_scan' or 'ssh_execute', which might have overlapping or related functionality.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives like 'ssh_scan' or 'ssh_execute'. It lacks context about prerequisites, typical use cases, or exclusions, leaving the agent to infer usage from the tool name and description alone.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

ssh_scanC

Escanear red para encontrar hosts SSH disponibles

ParametersJSON Schema
NameRequiredDescriptionDefault
networkYesRed a escanear (ej: 192.168.1.0/24)

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It states the tool scans for available SSH hosts but doesn't mention critical behaviors like whether it's read-only (likely, but not confirmed), network impact (e.g., bandwidth usage or potential intrusion detection triggers), output format, or error handling. This leaves significant gaps for an agent to understand operational implications.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, efficient sentence that directly states the tool's purpose without unnecessary words. It's appropriately sized and front-loaded, making it easy for an agent to parse quickly.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity of a network scanning tool with no annotations and no output schema, the description is insufficient. It lacks details on what 'available SSH hosts' means (e.g., open port 22, SSH service responding), how results are returned, potential side effects, or security considerations. This leaves the agent with incomplete context for safe and effective use.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 100% description coverage, with the 'network' parameter clearly documented in the schema itself. The description doesn't add any meaningful parameter semantics beyond what the schema provides (e.g., no examples of valid networks beyond the schema's example, no clarification on format requirements). This meets the baseline for high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action ('escanear' meaning 'scan') and target ('red para encontrar hosts SSH disponibles' meaning 'network to find available SSH hosts'), providing a specific verb+resource combination. However, it doesn't explicitly differentiate from sibling tools like 'ssh_keyscan' or 'ssh_execute', which prevents a perfect score.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives like 'ssh_keyscan' (which might scan for SSH keys) or 'ssh_execute' (which executes commands via SSH). There's no mention of prerequisites, limitations, or typical use cases beyond the basic purpose.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 4 tool updatesv1.0.0
    • First observedpowershell_execute
    • First observedssh_execute
    • First observedssh_keyscan
    • First observedssh_scan

TDQS

B3.4/5.0

Scored across 4 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: powershell_execute is for local PowerShell commands, ssh_execute is for remote SSH command execution, ssh_keyscan retrieves SSH key fingerprints, and ssh_scan discovers SSH hosts on a network. There is no overlap or ambiguity between these functions.

Naming Consistency5/5

All tool names follow a consistent snake_case pattern with a clear verb_noun structure: powershell_execute, ssh_execute, ssh_keyscan, ssh_scan. The naming is uniform and predictable across all tools.

Tool Count4/5

With 4 tools, the count is reasonable for an SSH/PowerShell server, covering core remote execution and SSH management tasks. It might be slightly thin for advanced scenarios (e.g., missing file transfer or session management), but it's well-scoped for basic operations.

Completeness4/5

The toolset covers key SSH and PowerShell operations: remote command execution, host discovery, and key verification. Minor gaps exist, such as no file transfer (e.g., SCP/SFTP) or SSH configuration management, but agents can work around these with the provided tools for most workflows.

Maintenance

ActivityInactive
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    Enables SSH remote access to servers through Claude, allowing users to execute commands, transfer files via SFTP, and manage multiple remote connections using natural language.
    12
    8
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Enables secure remote SSH command execution with strict read-only enforcement, allowing safe delegation of SSH access to Claude while preventing write operations. Supports connection pooling, command validation, and comprehensive logging for audit trails.
    5
    1
    -
  • -
    license
    Not graded
    quality
    Not graded
    maintenance
    Enables Claude Code to control remote servers via SSH for automated deployment, testing, and operations, including command execution and file transfer.
    4
    -