Skip to main content
Glama
YawLabs

SSH MCP Server

by YawLabs

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
ssh_execA

Execute a command on a remote host via SSH. The command is interpreted by the remote login shell — pipes, redirects, globs, and other shell metacharacters work as expected. Returns stdout, stderr, and exit code. Use env to set environment variables for this call without modifying the command string. Subject to SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST if configured (policy is checked against the env-prefixed command).

ssh_read_fileB

Read a file from a remote host via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.

ssh_write_fileA

Write content to a file on a remote host via SFTP. Creates or overwrites the file. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting. NOT gated by SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST: command policy applies only to ssh_exec and ssh_multi_exec, so a blacklist such as ^rm does NOT block this tool.

ssh_uploadA

Upload a local file to a remote host via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting. NOT gated by SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST: command policy applies only to ssh_exec and ssh_multi_exec, so a blacklist such as ^rm does NOT block this tool.

ssh_downloadA

Download a file from a remote host to local filesystem via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.

ssh_lsA

List files in a directory on a remote host via SFTP. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.

ssh_statA

Get metadata for a file or directory on a remote host via SFTP. Returns size, permissions (octal), uid/gid, mtime/atime, and the path type. Symlinks are reported as symlink -> <target kind>: the type describes the link itself while size/mode/mtime describe its TARGET, and a dangling symlink is reported rather than erroring. Use this instead of parsing ls -la output. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting.

ssh_mkdirA

Create a directory on a remote host via SFTP. Set recursive: true to create parent directories as needed (like mkdir -p). Existing intermediate dirs are tolerated; an existing leaf path is still an error. Unlike the other SFTP tools, the path may be relative. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting. NOT gated by SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST: command policy applies only to ssh_exec and ssh_multi_exec, so a blacklist such as ^rm does NOT block this tool.

ssh_deleteA

Delete a file or empty directory on a remote host via SFTP. Auto-detects the path type and calls the right SFTP op (unlink for files/symlinks, rmdir for empty dirs). Recursive directory delete is intentionally NOT supported -- for that, use ssh_exec with rm -rf explicitly so the destructive intent is visible in the tool trace. If the connection pool is full (SSH_MCP_MAX_POOL_SIZE, default 100), waits up to 30s for a free slot before starting. NOT gated by SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST: command policy applies only to ssh_exec and ssh_multi_exec, so a blacklist such as ^rm does NOT block this tool.

ssh_diagnoseA

Diagnose SSH connectivity issues. Checks ssh-agent status, loaded keys, known_hosts, SSH config, and attempts a test connection. Use this BEFORE attempting SSH operations if you suspect connectivity issues, or AFTER a failed SSH operation to understand why it failed.

ssh_agent_ensureA

Ensure ssh-agent is running and reachable. Starts a new agent if needed and sets environment variables so subsequent SSH operations work. Use this FIRST when SSH operations fail with agent-related errors.

ssh_key_listA

List all SSH private keys in ~/.ssh/ with their type, fingerprint, and whether they are loaded in the agent. Use this to find which keys are available and which ones need to be loaded. Reports isError only when ~/.ssh exists but could not be read -- an absent or empty ~/.ssh is a successful answer with a ssh-keygen hint.

ssh_key_loadA

Load an SSH private key into the running agent. Ensures the agent is running first. Use this after ssh_key_list shows a key that is not loaded.

ssh_config_lookupA

Resolve the effective SSH configuration for a host. Shows hostname, user, port, identity files, proxy settings, and all other options from ~/.ssh/config. Use this to understand how SSH will connect to a host.

ssh_known_hosts_fixA

Remove a stale host key from known_hosts and re-scan the host to add the current key. Use this when you see 'Host key verification failed' errors, typically after a server has been recreated or reprovisioned.

ssh_testA

Quick connectivity test to an SSH host. Reports success/failure with timing and actionable error details. Lighter and faster than ssh_diagnose — use this for a quick check before running operations.

ssh_git_checkA

Test Git-over-SSH authentication to a hosting provider (GitHub, GitLab, Bitbucket, etc). Verifies your SSH key is registered and working. Use this when git clone/pull/push fails with SSH errors.

ssh_multi_execA

Execute a command on multiple remote hosts in parallel. Runs at most SSH_MCP_MAX_POOL_SIZE hosts at once (default 100) and works through a longer list as slots free up. timeout is per host: it bounds each host's command, not the whole call. Each parallel slot works through its share of the list one host at a time, so with the pool to itself a call can take up to about ceil(hosts / SSH_MCP_MAX_POOL_SIZE) x (timeout + connect time). The connection pool is shared with every other tool; when it is full this call waits for slots instead of failing, and gives up only when none of its own hosts holds a slot and a full timeout has passed with none of them starting or finishing. The hosts waiting at that point (up to one per parallel slot) and every host still queued then report Connection pool is full; the queued ones are never attempted. Rerun those hosts once the other calls finish, or raise SSH_MCP_MAX_POOL_SIZE. Returns results per host. Use this instead of calling ssh_exec multiple times — it's faster and shows results side by side. Use env to set environment variables for this call without modifying the command string. Subject to SSH_MCP_COMMAND_WHITELIST / SSH_MCP_COMMAND_BLACKLIST if configured (policy is checked once, against the env-prefixed command, before fan-out).

ssh_findB

Search for files on a remote host. Wraps the find command with structured parameters so you don't have to construct find syntax manually.

ssh_tailA

Read the last N lines of a file on a remote host, optionally filtering by a grep pattern. Use this for reading log files instead of ssh_exec with manual tail/grep commands.

ssh_service_statusA

Check the status of a systemd service on a remote host. Returns whether it's active, its PID, uptime, and description. Use this instead of ssh_exec with systemctl.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.6/5.0

Scored across 21 tools

Disambiguation4/5

Most tools have distinct purposes, but ssh_test and ssh_diagnose both probe connectivity, and ssh_read_file/ssh_download as well as ssh_write_file/ssh_upload share file-transfer boundaries. Descriptions clarify these differences well, so ambiguity is limited to a few near-overlaps.

Naming Consistency3/5

All tools share the ssh_ prefix and snake_case formatting, but the verb/noun ordering is inconsistent: some are verb-first (ssh_read_file, ssh_write_file), some are noun-first (ssh_key_load, ssh_config_lookup), and others are bare verbs (ssh_exec, ssh_find). The mixed pattern is readable but not predictable.

Tool Count3/5

With 21 tools, this sits at the heavy end of the borderline range. Each tool fills a niche, but the large count may make selection harder than necessary, especially given overlapping utilities like ssh_test, ssh_diagnose, and ssh_git_check.

Completeness4/5

The toolkit covers agent/key management, connectivity diagnostics, command execution, SFTP file operations, config lookup, and known_hosts repair. Minor gaps like key generation or port forwarding exist, but core SSH workflows are well supported.

Maintenance

ActivityActive
ResponsivenessResponsive