Skip to main content
Glama
KinoThe-Kafkaesque

SSH MCP Server

README.md
# SSH MCP Server

[![smithery badge](https://smithery.ai/badge/@KinoThe-Kafkaesque/ssh-mcp-server)](https://smithery.ai/server/@KinoThe-Kafkaesque/ssh-mcp-server)

A Model Context Protocol (MCP) server implementation that provides SSH
capabilities. This server allows for secure remote access and execution through
the MCP protocol.

## Features

- SSH server implementation using MCP protocol
- SQLite database integration for data persistence
- TypeScript implementation for type safety and better development experience

## Prerequisites

- Node.js 18 or higher
- npm or yarn package manager
- TypeScript knowledge for development

## Installation

### Installing via Smithery

To install SSH Server for Claude Desktop automatically via [Smithery](https://smithery.ai/server/@KinoThe-Kafkaesque/ssh-mcp-server):

```bash
npx -y @smithery/cli install @KinoThe-Kafkaesque/ssh-mcp-server --client claude
```

### Manual Installation
1. Clone the repository:

```bash
git clone <repository-url>
cd ssh-server
```

2. Install dependencies:

```bash
npm install
```

3. Build the project:

```bash
npm run build
```

## Usage

### Configuration

The server uses a SQLite database (`ssh.db`) to store SSH credentials. The
database file will be created automatically when the server starts.

### Tools

The server stores named credentials, then every remote action refers to a
`credentialName`. `privateKeyPath` must point to an existing private key.

- `add_credential`: save `{ "name", "host", "username", "privateKeyPath" }`.
- `list_credentials`: list stored credential records.
- `remove_credential`: delete `{ "name" }`.
- `ssh_exec`: run a shell command with `{ "credentialName", "command", "timeout" }`.
- `ssh_exec_raw`: run an argv-style command array, for example `{ "credentialName": "prod", "command": ["grep", "-E", "foo|bar", "/var/log/app.log"] }`.
- `scp_copy`: copy one file over SFTP with `{ "credentialName", "localPath", "remotePath", "direction" }`.
- `rsync_copy`: copy directories or larger trees with rsync and the same transfer shape.
- `ssh_session_start`, `ssh_session_send`, `ssh_session_read`, `ssh_session_end`, `ssh_session_list`: manage interactive SSH sessions.
- `ssh_tunnel_start`, `ssh_tunnel_list`, `ssh_tunnel_stop`: manage local or remote port-forwarding tunnels.

Example:

```json
{
  "tool_name": "ssh_exec",
  "arguments": {
    "credentialName": "prod",
    "command": "uptime",
    "timeout": 120000
  }
}
```

### Starting the server

```bash
npm start
```

The server will start running on the configured port (default settings can be
modified in the source code).

## Project Structure

- `src/` - Source code directory
- `build/` - Compiled JavaScript output
- `node_modules/` - Project dependencies

## Dependencies

- `@modelcontextprotocol/sdk`: MCP protocol implementation
- `sqlite3`: SQLite database driver
- `typescript`: Development dependency for TypeScript support

## Development

To make changes to the project:

1. Make your changes in the `src/` directory
2. Rebuild the project:

```bash
npm run build
```

3. Start the server to test your changes:

```bash
npm start
```

## License

MIT

## Contributing

1. Fork the repository
2. Create your feature branch
3. Commit your changes
4. Push to the branch
5. Create a new Pull Request

TDQS

A3.5/5.0

Scored across 5 tools

Disambiguation5/5

Each tool has a clearly distinct purpose with no overlap: credential management (add, list, remove) is separate from remote operations (rsync, ssh_exec). The descriptions clearly differentiate between managing stored credentials and performing remote actions, eliminating any potential for misselection.

Naming Consistency5/5

All tools follow a consistent verb_noun pattern with snake_case: add_credential, list_credentials, remove_credential, rsync_copy, ssh_exec. The naming is predictable and readable throughout, with no deviations or mixed conventions.

Tool Count5/5

With 5 tools, this server is well-scoped for SSH operations. Each tool earns its place by covering essential functions: credential management (3 tools) and remote execution/copy (2 tools). This count is appropriate for the domain without being too thin or heavy.

Completeness4/5

The tool surface covers core SSH workflows: credential lifecycle (add, list, remove) and remote operations (execute, copy). A minor gap exists in credential updates (e.g., update_credential), but agents can work around this by removing and re-adding. Overall, the set provides good coverage for the stated purpose.

Maintenance

ActivityInactive
ResponsivenessResponsive