SSH MCP
The SSH MCP server enables AI tools like Claude Desktop to securely manage remote servers and network devices through SSH and serial console connections, providing comprehensive infrastructure management capabilities.
Core SSH Operations:
Connection Management: Establish SSH connections with password or key-based authentication (including passphrase support for encrypted keys), custom ports, and connection IDs
Remote Command Execution: Run commands with configurable working directory, timeout settings, and sudo support for privileged operations
File Operations: Upload/download files via SFTP and list directory contents with detailed file information
Ubuntu Server Management:
Nginx Control: Start, stop, restart, reload, check status, and validate configuration
Package Management: Update and upgrade system packages with security-only updates and automatic cleanup options
SSL Certificates: Issue, renew, check status, and list Let's Encrypt certificates with automatic domain verification
Website Deployment: Deploy files with automatic backup creation and restore capabilities
UFW Firewall: Configure rules including enable/disable, allow/deny, and protocol-specific settings
Network Device Management:
Console Access: Connect via USB-to-Serial adapters (FTDI, Prolific, Silicon Labs, CH340)
Device Operations: Discover switch types, show interfaces/VLANs/MAC tables, backup configurations, and run network diagnostics (ping/traceroute)
Automated SSH Setup: Console-to-SSH transition for switches, reducing setup time from 15-20 minutes to under 2 minutes
Firmware Management: Check versions, verify storage, upload firmware via SFTP, verify integrity, install updates, and prepare rollback procedures
Compatibility: Tested with Cisco Catalyst 2960/3560/3750 and Aruba 2530/2930 series switches
Production Reliability: Proven in live network environments with zero downtime incidents during deployments
Planned integration for Apache web server control in future enhancements
Support for .env files to store sensitive configuration information
Supports git for repository management including cloning the MCP server
Repository hosting for the MCP server code
Planned integration for SSL certificate management with Let's Encrypt
Compatible with Linux operating systems for running the MCP server
Compatible with macOS operating systems for running the MCP server
Provides tools to check NGINX server status and planned integration for Nginx web server control
Supports Node.js 18 or higher as a requirement for running the MCP server
Support for Ubuntu website management tools including system package updates and server administration
Planned integration for WordPress management on remote servers
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@SSH MCPconnect to my server at example.com using username 'admin' and password authentication"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP SSH Server
A Model Context Protocol (MCP) server that provides comprehensive SSH and serial console access to remote servers and network devices. Enables AI tools like Claude Desktop to securely manage Linux servers, network switches, and infrastructure devices through both network SSH connections and direct USB-to-Serial console access.
Features
Core SSH Capabilities
SSH connection management with password or key-based authentication
Remote command execution with timeout handling
File upload and download via SFTP
Directory listing and file operations
Secure connection handling
Network Device Management
USB-to-Serial Console Access - Direct console connections via FTDI and other USB adapters
Network Switch Management - Full support for Cisco IOS/IOS-XE and Aruba switches
Device Discovery - Automatic detection of switch types and capabilities
Configuration Management - Backup, restore, and automated configuration
Network Diagnostics - Built-in ping, traceroute, and connectivity testing
Console-to-SSH Transition - Automated SSH setup via console connection
Firmware Management - Upload, verify, install, and rollback switch firmware
Server Management
Ubuntu server management tools (Nginx, SSL, packages, firewall)
Compatible with Claude Desktop, VS Code, and other MCP-compatible clients
Related MCP server: SSH MCP Server
Real-World Production Testing
This tool has been extensively tested in production network environments:
Network Discovery - Successfully discovered previously unknown fluttering ports on production switches that were causing intermittent connectivity issues
Zero Downtime - Managed multiple switches in live production networks without causing any network disruptions or outages
Time Savings - Automated SSH configuration reduced switch setup time from 15-20 minutes to under 2 minutes
Reliability - Zero incidents during production deployments across multiple network devices
USB-to-Serial Compatibility - Tested with FTDI FT232R/FT232H, Prolific PL2303, Silicon Labs CP2102/CP2104, and CH340 adapters
Switch Compatibility - Validated on Cisco Catalyst 2960/3560/3750 and Aruba 2530/2930 series switches
The tool has proven itself reliable enough for production network management tasks without requiring a separate lab environment for testing.
Prerequisites
Node.js 18 or higher
npm or yarn
Compatible with Windows, macOS, and Linux
Installation
Clone the repository:
git clone https://github.com/yourusername/mcp-ssh-server.git cd mcp-ssh-serverInstall dependencies:
npm installBuild the project:
npm run buildInstall globally (optional):
npm install -g .
Configuration
Claude Desktop Configuration
Open Claude Desktop
Go to Settings > Developer (or press Ctrl+Shift+D)
Edit the MCP configuration
Add the following configuration:
{
"mcpServers": {
"ssh-server": {
"command": "node",
"args": ["/path/to/mcp-ssh-server/build/index.js"],
"env": {
"NODE_NO_WARNINGS": "1"
}
}
}
}Important: Replace /path/to/mcp-ssh-server/build/index.js with the absolute path to your built index.js file.
VS Code Configuration (if using MCP extension)
Create or edit .vscode/mcp.json in your workspace:
{
"mcpServers": {
"ssh-server": {
"command": "node",
"args": ["/path/to/mcp-ssh-server/build/index.js"]
}
}
}Available Tools
Core SSH Tools
ssh_connect
Establish an SSH connection to a remote server.
Parameters:
host(required) - Hostname or IP addressusername(required) - SSH usernamepassword(optional) - SSH passwordprivateKeyPath(optional) - Path to private key filepassphrase(optional) - Passphrase for private keyport(optional) - SSH port (default: 22)connectionId(optional) - Unique identifier for this connection
Returns:
success- Boolean indicating successconnectionId- ID to use for subsequent commandsmessage- Connection status message
Example:
Connect to my server at example.com using username 'admin' and password authenticationssh_exec
Execute a command on the remote server.
Parameters:
connectionId(required) - ID from ssh_connectcommand(required) - Command to executecwd(optional) - Working directorytimeout(optional) - Command timeout in milliseconds (default: 60000)
Returns:
code- Exit codesignal- Signal that terminated the process (if any)stdout- Standard outputstderr- Standard error
Example:
Run "ls -la /var/www/html" on the serverssh_upload_file
Upload a file to the remote server.
Parameters:
connectionId(required) - ID from ssh_connectlocalPath(required) - Local file pathremotePath(required) - Remote destination path
Returns:
success- Boolean indicating successmessage- Upload status message
ssh_download_file
Download a file from the remote server.
Parameters:
connectionId(required) - ID from ssh_connectremotePath(required) - Remote file pathlocalPath(required) - Local destination path
Returns:
success- Boolean indicating successmessage- Download status message
ssh_list_files
List files in a directory on the remote server.
Parameters:
connectionId(required) - ID from ssh_connectremotePath(required) - Directory path to list
Returns:
files- Array of file objects with properties:filename- File nameisDirectory- Boolean indicating if it's a directorysize- File sizelastModified- Last modification time
ssh_disconnect
Close an SSH connection.
Parameters:
connectionId(required) - ID from ssh_connect
Returns:
success- Boolean indicating successmessage- Disconnection status message
Usage Examples with Claude
Connect to your server:
Please connect to my VPS at example.com using username 'admin' and my SSH key at ~/.ssh/id_rsaCheck server status:
Run the command "systemctl status nginx" to check web server statusUpload a website file:
Upload my local file ~/websites/index.html to /var/www/html/index.html on the serverList website files:
Show me all files in the /var/www/html directoryDownload a backup:
Download the file /var/backups/website-backup.tar.gz to my local Downloads folderDisconnect when done:
Please disconnect from the SSH session
Network Switch Management Tools
switch_discover_device
Discover and identify network switch device type and capabilities.
Parameters:
connectionId(required) - ID of an active SSH connectionenablePassword(optional) - Enable password for privileged mode
switch_show_interfaces
Show interface status and configuration on network switch.
Parameters:
connectionId(required) - ID of an active SSH connectioninterfaceType(optional) - Type of interfaces to showenablePassword(optional) - Enable password for privileged mode
switch_show_vlans
Show VLAN configuration and status on network switch.
Parameters:
connectionId(required) - ID of an active SSH connectionenablePassword(optional) - Enable password for privileged mode
switch_backup_config
Backup switch configuration (running or startup config).
Parameters:
connectionId(required) - ID of an active SSH connectionconfigType(optional) - Type of configuration to backupenablePassword(optional) - Enable password for privileged mode
switch_network_diagnostics
Run network diagnostics from switch (ping, traceroute).
Parameters:
connectionId(required) - ID of an active SSH connectiontarget(required) - Target IP address or hostnamediagnosticType(optional) - Type of diagnostic to runenablePassword(optional) - Enable password for privileged mode
switch_show_mac_table
Show MAC address table on network switch.
Parameters:
connectionId(required) - ID of an active SSH connectionvlan(optional) - Specific VLAN to show MAC addresses forenablePassword(optional) - Enable password for privileged mode
USB-to-Serial Console Tools
These tools enable direct console access to network devices using USB-to-Serial adapters. This is essential for initial device setup, emergency access when network connectivity is lost, or when SSH has not yet been configured.
Supported USB-to-Serial Adapters:
FTDI FT232R/FT232H (recommended - most reliable)
Prolific PL2303 (widely compatible)
Silicon Labs CP2102/CP2104 (good performance)
CH340/CH341 chipsets (budget-friendly option)
All adapters work with standard Cisco/Aruba console cables (RJ45 to DB9 or direct USB).
serial_list_ports
List available USB-to-Serial ports on the system. Automatically detects FTDI, Prolific, Silicon Labs, and CH340 adapters.
Example:
Show me all available serial portsserial_connect
Connect to a network device via USB-to-Serial console port.
Parameters:
port(required) - Serial port name (e.g., COM3 on Windows, /dev/ttyUSB0 on Linux)baudRate(optional) - Baud rate (default: 9600 for most switches)connectionId(optional) - Unique identifier for connectiondeviceType(optional) - Device type for optimal settings (cisco, aruba, generic)
Example:
Connect to my Cisco switch console on COM3serial_send_command
Send a command to network device via serial connection.
Parameters:
connectionId(required) - ID of an active serial connectioncommand(required) - Command to send to devicewaitForResponse(optional) - Wait for device responsetimeout(optional) - Response timeout in milliseconds
Example:
Send "show version" command to the console connectionserial_discover_device
Discover device type and capabilities via serial connection. Automatically identifies Cisco IOS, Cisco IOS-XE, Aruba, and generic devices.
Parameters:
connectionId(required) - ID of an active serial connection
Example:
Discover what type of device is connectedserial_list_connections
List all active serial connections.
serial_disconnect
Disconnect from a serial port.
Parameters:
connectionId(required) - ID of an active serial connection
Ubuntu Website Management Tools
The following Ubuntu server management tools are available:
ubuntu_nginx_control - Web server control (start, stop, restart, status, reload, check-config)
ubuntu_update_packages - System package updates with security-only option
ubuntu_ssl_certificate - SSL certificate management using Let's Encrypt (issue, renew, status, list)
ubuntu_website_deployment - Website deployment with automatic backup and restore
ubuntu_ufw_firewall - Firewall (UFW) management (enable, disable, allow, deny, delete)
SSH Setup & Automation Tools
These tools automate the process of configuring SSH access on network switches via console connection, enabling a smooth transition from console-only to SSH-based management.
switch_generate_ssh_config
Generate SSH configuration template for a network switch based on device type and security level.
Parameters:
deviceType(optional) - Device type: cisco, aruba (auto-detected if not specified)securityLevel(optional) - Security level: basic, secure (default: basic)hostname(required) - Switch hostnameip_address(required) - Management IP addresssubnet_mask(optional) - Subnet mask (default: 255.255.255.0)gateway(required) - Default gatewayusername(required) - SSH usernamepassword(required) - SSH password
switch_apply_ssh_config
Apply SSH configuration to a switch via an active serial console connection.
Parameters:
serialConnectionId(required) - ID of an active serial connectiondeviceType(optional) - Device type: cisco, arubahostname(required) - Switch hostnameip_address(required) - Management IP addressgateway(required) - Default gatewayusername(required) - SSH usernamepassword(required) - SSH passwordconfirmApply(required) - Must be true to proceed
switch_verify_ssh_status
Check the current SSH configuration status on a switch via serial connection.
Parameters:
serialConnectionId(required) - ID of an active serial connection
switch_test_ssh_connection
Test SSH connectivity to a newly configured switch.
Parameters:
ip_address(required) - Switch IP addressusername(required) - SSH usernamepassword(required) - SSH passwordport(optional) - SSH port (default: 22)
switch_complete_ssh_setup
Complete end-to-end SSH setup workflow via console connection. This automates the entire process of configuring SSH on a switch.
Parameters:
serialConnectionId(required) - ID of an active serial connectionhostname(required) - Switch hostnameip_address(required) - Management IP addressgateway(required) - Default gatewayusername(required) - SSH usernamepassword(required) - SSH passwordconfirmSetup(required) - Must be true to proceed
Console-to-SSH Transition Tools
console_to_ssh_transition
Complete automated workflow to transition a network switch from console-only access to SSH management. This is the recommended tool for initial switch setup.
Parameters:
port(required) - Serial port (e.g., COM3, /dev/ttyUSB0)hostname(required) - Switch hostnameip_address(required) - Management IP addressgateway(required) - Default gatewayusername(required) - SSH usernamepassword(required) - SSH passworddeviceType(optional) - Device type: cisco, aruba (auto-detected if not specified)confirmTransition(required) - Must be true to proceed
Example:
Set up SSH on my Cisco switch connected to COM3 with hostname "switch-core-01", IP 192.168.1.10, gateway 192.168.1.1, username "admin"quick_ssh_check
Quick check of SSH status on a switch via serial connection without making any changes.
Parameters:
port(required) - Serial portbaudRate(optional) - Baud rate (default: 9600)enablePassword(optional) - Enable password if required
Firmware Management Tools
These tools provide comprehensive firmware management capabilities for network switches, including version checking, firmware upload, verification, installation, and rollback preparation.
switch_check_firmware
Check the current firmware version and system information on a network switch.
Parameters:
connectionId(required) - ID of an active SSH connectionenablePassword(optional) - Enable password for privileged mode
Returns:
Current firmware version
Boot version
Device model and serial number
System uptime
Full version output
switch_check_storage
Verify available storage space on the switch before firmware upload.
Parameters:
connectionId(required) - ID of an active SSH connectionenablePassword(optional) - Enable password for privileged mode
Returns:
Flash storage information
Available space
File system details
switch_upload_firmware
Upload a firmware file to the network switch via SFTP. Supports large firmware files with 30-minute timeout.
Parameters:
connectionId(required) - ID of an active SSH connectionlocalFirmwarePath(required) - Local path to firmware fileremotePath(optional) - Remote path on switch (default: flash:/filename)enablePassword(optional) - Enable password for privileged mode
Example:
Upload firmware file ~/downloads/c2960-lanbasek9-mz.150-2.SE11.bin to the switchswitch_verify_firmware
Verify the integrity of an uploaded firmware file on the switch using MD5 checksums.
Parameters:
connectionId(required) - ID of an active SSH connectionfirmwarePath(required) - Path to firmware file on switchenablePassword(optional) - Enable password for privileged mode
Returns:
Verification status
MD5 checksum results
File information
switch_install_firmware
Install firmware on the switch and optionally reboot to apply the update.
Parameters:
connectionId(required) - ID of an active SSH connectionfirmwarePath(required) - Path to firmware file on switchenablePassword(optional) - Enable password for privileged modeautoReboot(optional) - Automatically reboot after installation (default: false)
Important: This modifies the boot configuration. Test in a lab environment first!
Example:
Install firmware flash:/c2960-lanbasek9-mz.150-2.SE11.bin and reboot the switchswitch_prepare_rollback
Prepare information needed for firmware rollback in case of issues with new firmware.
Parameters:
connectionId(required) - ID of an active SSH connectionenablePassword(optional) - Enable password for privileged mode
Returns:
Current boot configuration
Available firmware images
Rollback instructions
USB-to-Serial Console Setup
Hardware Requirements
USB-to-Serial Adapters:
FTDI-based adapters (FT232R, FT232H) - Best choice for reliability
Prolific PL2303 - Widely available and compatible
Silicon Labs CP2102/CP2104 - Good performance and stability
CH340/CH341 - Budget option, works well on most systems
Console Cables:
Cisco console cable (RJ45 to DB9 or USB)
Aruba/HP console cable (RJ45 to DB9 or USB)
Universal console cables work with most devices
Driver Installation
Windows:
FTDI drivers: Usually auto-installed, or download from ftdichip.com
Prolific drivers: Available from prolific.com.tw
Silicon Labs drivers: Download from silabs.com
CH340 drivers: Usually included in Windows 10/11, or download separately
macOS:
FTDI adapters: Usually work out-of-the-box
Other adapters: May require driver installation from manufacturer
Linux:
Most adapters work immediately with kernel drivers
FTDI, Silicon Labs, CH340: Built into kernel
Check
dmesgafter plugging in adapter to verify detection
Quick Start with Console
Connect USB-to-Serial adapter to your computer
Connect console cable from adapter to switch console port
List available ports: "Show me available serial ports"
Connect to port: "Connect to COM3 for Cisco switch"
Send commands or run automated setup
Security Notes
Store SSH private keys securely
Use key-based authentication when possible
Limit SSH access to specific IP addresses
Keep your server updated
Use strong passwords or passphrases (minimum 8 characters)
Secure physical access to console ports and USB-to-Serial adapters
Consider setting up environment variables in a
.envfile for sensitive information
Troubleshooting
Server won't start
Check that Node.js is installed:
node --versionVerify all dependencies are installed:
npm installRebuild the project:
npm run build
Connection issues
Verify SSH server is running on the target
Check firewall settings
Confirm credentials are correct
Test SSH connection manually first
Claude Desktop integration
Ensure the path in configuration is absolute
Restart Claude Desktop after configuration changes
Check Developer Console for error messages
Development
To modify or extend the server:
Edit source files in
src/Rebuild:
npm run buildTest your changes
Restart Claude Desktop or VS Code to pick up changes
Running in Development Mode
For quick testing during development:
npm run devContributing
Contributions for additional tools and features are welcome. Please feel free to submit pull requests or open issues for enhancements and bug fixes.
License
MIT License
Available Tools
11 toolsssh_connectC
Connect to a remote server via SSH
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | Hostname or IP address of the remote server | |
| port | No | SSH port (default: 22) | |
| username | Yes | SSH username | |
| password | No | SSH password (if not using key-based authentication) | |
| privateKeyPath | No | Path to private key file (if using key-based authentication) | |
| passphrase | No | Passphrase for private key (if needed) | |
| connectionId | No | Unique identifier for this connection |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. 'Connect' implies establishing a persistent session, but the description doesn't specify what happens after connection (e.g., whether it maintains state, returns a connection handle, or has timeout behavior). It mentions SSH but doesn't detail security implications, error handling, or what constitutes a successful connection.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, clear sentence that efficiently conveys the core function without unnecessary words. It's front-loaded with the essential action and resource, making it easy for an agent to parse. Every word earns its place in this minimal but complete statement.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with 7 parameters, no annotations, and no output schema, the description is insufficient. It doesn't address what the tool returns (e.g., connection status, session ID), error conditions, or behavioral details like persistence. Given the complexity of SSH connections and the lack of structured metadata, the description should provide more operational context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so all parameters are documented in the schema. The description adds no additional parameter semantics beyond the basic action of connecting. It doesn't explain parameter interactions (e.g., password vs privateKeyPath) or provide context beyond what the schema already specifies. Baseline 3 is appropriate given high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('connect') and target ('to a remote server via SSH'), making the purpose immediately understandable. It distinguishes from siblings like ssh_disconnect or ssh_exec by specifying the connection establishment function. However, it doesn't explicitly differentiate from all SSH-related siblings beyond the basic verb.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It doesn't mention prerequisites like needing authentication credentials, nor does it explain when to choose this over other SSH tools like ssh_exec (which might handle both connection and command execution). The context is implied but not articulated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ssh_disconnectB
Close an SSH connection
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must fully disclose behavior. It states the action but does not mention consequences like terminating active sessions, idempotency, or permission requirements, which is a gap for a state-changing operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single concise sentence with no unnecessary words. It is perfectly sized for a simple tool.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with one parameter and no output schema, the description is largely sufficient. However, the lack of annotations and behavioral context about what happens when disconnecting (e.g., killing active processes) leaves minor ambiguity, making it adequate but not exemplary.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema fully documents the single parameter connectionId with a clear description, and schema description coverage is 100%. The tool description adds no additional meaning beyond what the schema already provides, so the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb 'Close' and resource 'SSH connection', making the action unambiguous. It clearly distinguishes from sibling tools like ssh_connect and ssh_list_connections.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description does not provide any guidance on when to use this tool, such as after completing operations or when needing to terminate a connection. It offers no exclusions or alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ssh_download_fileC
Download a file from the remote server
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection | |
| remotePath | Yes | Path to the file on the remote server | |
| localPath | Yes | Path where the file should be saved locally |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It states the action ('Download') but doesn't describe what happens during execution—such as whether it overwrites local files, handles errors, requires specific permissions, or provides progress feedback. This leaves significant gaps for a file transfer operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that directly states the tool's function without any unnecessary words. It's front-loaded with the core action, making it easy to parse and understand immediately.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a file download tool with no annotations and no output schema, the description is incomplete. It doesn't explain what the tool returns (e.g., success status, error messages, or file metadata), nor does it cover behavioral aspects like error handling or security considerations, which are critical for SSH operations.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all three parameters (connectionId, remotePath, localPath) with clear descriptions. The description adds no additional meaning beyond what's in the schema, such as file format support or path validation rules, meeting the baseline for high coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Download') and resource ('a file from the remote server'), making the tool's purpose immediately understandable. However, it doesn't explicitly differentiate from sibling tools like ssh_upload_file or ssh_list_files, which would require mentioning it's specifically for file retrieval rather than upload or listing.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It doesn't mention prerequisites like needing an active SSH connection (implied by the connectionId parameter but not stated), nor does it differentiate from siblings such as ssh_upload_file for uploading or ssh_list_files for browsing files.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ssh_execC
Execute a command on the remote server
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection | |
| command | Yes | Command to execute | |
| cwd | No | Working directory for the command | |
| timeout | No | Command timeout in milliseconds |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It states the action but lacks critical details: it doesn't mention security implications, permission requirements, output format (e.g., stdout/stderr), error handling, or that it might affect the remote system. This is inadequate for a mutation tool with zero annotation coverage.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence with no wasted words. It's front-loaded with the core action, making it easy to parse quickly, which is ideal for conciseness.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity (executing commands on a remote server), lack of annotations, and no output schema, the description is incomplete. It fails to address behavioral aspects like safety, output, or error handling, which are crucial for an agent to use this tool effectively in context with siblings.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema description coverage is 100%, so all parameters are documented in the schema. The description adds no additional meaning beyond implying command execution, which the schema already covers with parameter descriptions. This meets the baseline of 3 when the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('execute a command') and target ('on the remote server'), which distinguishes it from siblings like ssh_connect or ssh_upload_file. However, it doesn't explicitly differentiate from potential command-execution alternatives in the sibling list, keeping it at 4 rather than 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. It doesn't mention prerequisites (e.g., needing an active SSH connection via ssh_connect), exclusions, or comparisons to other command-related tools, leaving the agent to infer usage context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ssh_list_filesB
List files in a directory on the remote server
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection | |
| remotePath | Yes | Path to the directory on the remote server |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must carry the behavioral disclosure burden. It only states the action without revealing details like whether it lists recursively, includes file metadata, or how errors are handled. For a read operation, this is a notable gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, tightly-worded sentence. It is concise, front-loaded, and free of unnecessary words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no annotations and no output schema, the description should disclose what the tool returns (e.g., list of filenames, full paths, metadata) and any limitations. It does not. For a simple tool it is usable, but it leaves meaningful gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage, so baseline is 3. The description does not add meaning beyond the schema—both remotePath and connectionId are adequately defined in the schema already.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's function: 'List files in a directory on the remote server' with a specific verb and resource. It distinguishes itself from siblings like ssh_read_file and ssh_download_file by focusing on listing directory contents.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage (when you need to list remote directory contents) but does not explicitly mention alternatives or exclusions. Since there are sibling tools, more explicit guidance would be better, but the basic context is present.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ssh_upload_fileB
Upload a file to the remote server
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection | |
| localPath | Yes | Path to the local file | |
| remotePath | Yes | Path where the file should be saved on the remote server |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It does not state whether the upload overwrites existing files, requires an active connection, or has any side effects on the remote server. The description is too terse to convey these important behaviors.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence with no wasted words. It is appropriately front-loaded, stating the core action immediately, and is easily parsed by an agent.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple file upload tool with fully described parameters, the description is minimally viable. However, it lacks behavioral context such as overwrite policy, required connection state, and any error conditions, which could affect an agent's invocation. The absence of an output schema means description should clarify return values, but it does not.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema provides 100% coverage with clear descriptions for all three parameters (localPath, remotePath, connectionId). The description adds no additional parameter semantics beyond what the schema already states, so the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Upload'), the object ('a file'), and the destination ('remote server'), which is specific and distinguishes this tool from siblings like ssh_download_file and ssh_read_file. The verb-resource pairing is unambiguous and matches the tool's name.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives such as ssh_download_file or ssh_exec. It also does not mention prerequisites like having an active SSH connection, though the schema hints at this via connectionId.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ubuntu_nginx_controlC
Control Nginx web server on Ubuntu
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection | |
| action | Yes | Action to perform (start, stop, restart, status, reload, check-config) | |
| sudo | No | Whether to run the command with sudo (default: true) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of disclosing behavioral traits. It only states 'Control Nginx web server on Ubuntu' without mentioning that actions like start, stop, or reload mutate system state, that sudo is likely involved, or what the output/return value looks like. This is inadequate for a service-control tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single short sentence with no wasted words, and the key resource ('Nginx') is front-loaded. However, it is so sparse that it sacrifices informative value, though that is not purely a conciseness issue. It could benefit from listing the actions, but as written it is structurally efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema and no annotations, the description does not explain the operational context: it doesn't mention that it uses an SSH connection, that some actions are destructive, or how results are returned. Given the sibling tools, an agent might infer the domain, but the description alone is insufficient for confident invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%: each parameter is described, including the allowed actions for the 'action' parameter. The tool description adds no extra semantic meaning beyond what the schema already provides, so the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses the vague verb 'Control' but identifies a specific resource: 'Nginx web server on Ubuntu'. It doesn't enumerate the specific operations (start, stop, reload, etc.), making the purpose broad. It is distinguishable from sibling tools like ssh_exec because it targets Nginx specifically, but the verb lacks precision.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives such as ssh_exec or other ubuntu_* tools. There is no mention of prerequisites (e.g., Nginx installed, active SSH connection) or scenarios where this tool is preferred. Usage is only implied by the tool's name and the presence of sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ubuntu_ssl_certificateC
Manage SSL certificates using Let's Encrypt on Ubuntu
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection | |
| action | Yes | Action to perform (issue, renew, status, list) | |
| domain | No | Domain name for the certificate (required for issue and renew) | |
| No | Email address for Let's Encrypt notifications (required for issue) | ||
| webroot | No | Web root path for domain verification (default: /var/www/html) | |
| sudo | No | Whether to run the command with sudo (default: true) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must disclose behavioral traits. It doesn't mention that this tool modifies the server's certificate store, requires root/sudo, or makes network requests to Let's Encrypt. The vague verb 'Manage' gives no safety or side-effect information.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is one short sentence, making it concise and front-loaded. However, it is so generic that it borders on under-specification, repeating the tool's name without meaningful value. It earns a middle score for brevity but lacks substance.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema and no annotations, the description is the only narrative source for expected behavior. It doesn't explain return values, error conditions, or effects on the system. The schema helps with parameters, but the description is insufficient for a tool that can issue and renew certificates.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema documents all six parameters with descriptions (100% coverage), so parameter semantics are already provided programmatically. The description adds no additional meaning beyond what the schema contains.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description identifies the resource (Let's Encrypt SSL certificates on Ubuntu) and implies management operations, but the verb 'Manage' is broad and doesn't specify concrete actions like issue, renew, status, or list. It is clear enough to distinguish from sibling tools (which handle SSH, nginx, firewall), but lacks precision for a high score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool instead of alternatives like ubuntu_nginx_control or ssh_exec. It doesn't mention prerequisites (e.g., domain DNS pointing to server, HTTP server running for webroot validation) or exclude any cases.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ubuntu_ufw_firewallC
Manage Ubuntu Uncomplicated Firewall (UFW)
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection | |
| action | Yes | Action to perform (enable, disable, status, allow, deny, delete, reset) | |
| port | No | Port number or service name (e.g., 80, 443, ssh, http) | |
| protocol | No | Protocol (tcp, udp) | |
| from | No | Source IP address or network | |
| sudo | No | Whether to run the command with sudo (default: true) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations to rely on, the description fails to disclose important behavioral traits: actions are mutating and high-risk (e.g., deny could lock out the SSH session), sudo may be required (though a sudo parameter exists), and firewall state changes persist. The word 'manage' does not convey the potential for disruption.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence with no filler. It efficiently communicates the tool's general purpose, though it is minimal. It earns its place without being verbose, but could be slightly more informative without sacrificing concision.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (multiple actions, unclear safety implications, no output schema, no annotations), the description is far from complete. It lacks guidance on rule syntax, what 'delete' or 'reset' entails, and any warnings. The schema covers parameters but not operational context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description adds no parameter meaning, but the schema provides comprehensive descriptions for all 6 properties (100% coverage). The action field enumerates possible values, and port/protocol descriptions are clear, so the description's lack of parameter detail is not a major gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the resource (Ubuntu UFW) and a managing action. It distinguishes from siblings like ssh_exec or nginx_control, though 'manage' is somewhat broad. The schema's action parameter grounds the specific operations, making the purpose unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives like ssh_exec, nor does it note prerequisites such as an active SSH connection (connectionId required). It neither mentions when to use it nor when not to, leaving the agent without decision context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ubuntu_update_packagesC
Update system packages on Ubuntu
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection | |
| securityOnly | No | Whether to update only security packages (default: false) | |
| upgrade | No | Whether to upgrade packages after update (default: true) | |
| autoremove | No | Whether to remove unused packages after update (default: false) | |
| sudo | No | Whether to run the command with sudo (default: true) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure. It states 'update system packages' but does not explain that this likely runs apt-get update/upgrade, may require sudo, or could modify the system and reboot services. Side effects are undisclosed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence with no wasted words. However, it is extremely brief and omits useful context that could be included without bloating the text.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has 5 parameters, no output schema, and no annotations, the description is under-specified. It does not explain what 'update' entails, the role of connectionId, or what the tool returns (e.g., command output). The schema provides parameter details, but overall context is lacking.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema provides descriptions for 100% of the 5 parameters, including sudo, upgrade, autoremove, connectionId, and securityOnly. The description adds no additional parameter semantics beyond what the schema already conveys, so the baseline of 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a clear action ('Update') and resource ('system packages') with a platform qualifier ('on Ubuntu'). It distinguishes itself from sibling tools like nginx_control or ssh_exec, though it relies on the name for full distinction.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided about when to use this tool versus alternatives such as ssh_exec for running apt commands manually. There is no mention of prerequisites, context, or exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ubuntu_website_deploymentC
Deploy website files and create backups on Ubuntu
| Name | Required | Description | Default |
|---|---|---|---|
| connectionId | Yes | ID of an active SSH connection | |
| action | Yes | Action to perform (deploy, backup, restore) | |
| localPath | No | Local path to the website files for deployment | |
| remotePath | No | Remote path where the website is located (default: /var/www/html) | |
| backupPath | No | Path to store backups (default: /var/backups/websites) | |
| createBackup | No | Whether to create a backup before deployment (default: true) | |
| sudo | No | Whether to run the command with sudo (default: true) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
There are no annotations, so the description carries full responsibility for disclosing behavioral traits. It fails to mention that the tool may overwrite remote files, run with sudo, require an active connection, or that 'restore' modifies existing site state. It also does not explain the backup behavior or implications of the 'createBackup' default. This is a significant transparency gap for a tool with mutating actions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence with no fluff, but it is under-specified for a tool with 7 parameters and 3 distinct actions. It is concise in the sense of being short, but it omits required function details, so it is not appropriately sized for the tool's complexity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (7 parameters, 3 actions, no output schema, no annotations), the description is severely incomplete. It only mentions deploy and backup, omits restore, connection requirements, default paths, and behavior. An agent would have to rely on parameter descriptions alone to understand how to use this tool effectively.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so every parameter already has a description. The tool description adds minimal extra meaning by mentioning 'deploy' and 'backups', which loosely maps to the action and createBackup parameters, but it does not clarify the meaning of 'restore' or the roles of path parameters. Baseline 3 is appropriate because the schema already does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a clear verb and resource: 'Deploy website files and create backups on Ubuntu'. This differentiates it from generic SSH file tools, though it omits the 'restore' action available in the schema. The name and description together make the tool's primary purpose evident.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is given for when to use this tool vs. alternatives like ssh_upload_file, ssh_exec, or other ubuntu_* tools. There are no prerequisites mentioned (e.g., active SSH connection) or exclusions, leaving the agent to infer usage from the name alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
11 tool updates
- First observed
ssh_connect - First observed
ssh_disconnect - First observed
ssh_download_file - First observed
ssh_exec - First observed
ssh_list_files - First observed
ssh_upload_file - First observed
ubuntu_nginx_control - First observed
ubuntu_ssl_certificate - First observed
ubuntu_ufw_firewall - First observed
ubuntu_update_packages - First observed
ubuntu_website_deployment
TDQS
Scored across 11 tools
The SSH tools (ssh_connect, ssh_disconnect, ssh_exec, ssh_list_files, ssh_upload_file, ssh_download_file) are clearly distinct and cover basic SSH operations well. However, the Ubuntu-specific tools (ubuntu_nginx_control, ubuntu_ssl_certificate, ubuntu_ufw_firewall, ubuntu_update_packages, ubuntu_website_deployment) overlap conceptually with the SSH tools since they also involve remote server management, creating some ambiguity about when to use which set. The descriptions help differentiate, but the boundary between general SSH operations and Ubuntu-specific administration is not perfectly clear.
The naming is mostly consistent with a verb_noun pattern (e.g., ssh_connect, ssh_exec, ubuntu_update_packages), which is predictable and readable. However, there is a minor deviation: 'ssh_download_file' and 'ssh_upload_file' use 'download' and 'upload' as verbs, while others like 'ssh_list_files' use 'list'—this is still consistent in style but slightly varies in verb choice. Overall, the naming follows a clear convention with only small inconsistencies.
With 11 tools, the count is reasonable for a server focused on SSH and Ubuntu server management. It covers a broad scope without being excessive. However, the split between general SSH tools (6 tools) and Ubuntu-specific tools (5 tools) might feel slightly fragmented, making it borderline heavy for a pure SSH server but still well-scoped for the combined purpose. It earns its place but could be optimized for clarity.
For SSH operations, the toolset is quite complete, covering connection management, file transfer, command execution, and directory listing—no major gaps. For Ubuntu server management, it includes key areas like web server control, SSL, firewall, updates, and deployment, which is comprehensive. A minor gap is the lack of tools for non-Ubuntu systems or more advanced SSH features (e.g., port forwarding), but agents can work around this with the existing tools for core workflows.
Maintenance
Related MCP Connectors
Run commands and read/write files on your servers over Termalin's keyless tunnels (hosted MCP).
Scoped, audited SSH exec, sessions, and SFTP on your saved servers without exposing credentials
Secure tunneling, reverse proxy and remote access for local applications.
Research honeypot. Logs connections and tool arguments; injects instructions. Read README first.
Related MCP Servers
- FlicenseBqualityDmaintenanceEnables SSH operations including connecting to remote servers, executing commands, and transferring files between local and remote systems. Supports multiple SSH connections with both password and private key authentication methods.18-
- AlicenseAqualityDmaintenanceEnables secure SSH connections to multiple remote servers with support for command execution, file transfers (SFTP), directory listing, and both password and key-based authentication.7MIT
- AlicenseAqualityAmaintenanceSSH automation MCP server that enables Claude and ChatGPT to execute commands, manage files, install packages, and control services on remote servers over SSH — supporting password, key, and agent authentication.331,267 npm4MIT
- AlicenseBqualityDmaintenanceA Model Context Protocol (MCP) SSH client server that provides autonomous SSH operations for GitHub Copilot and VS Code. Enable natural language SSH automation without manual prompts or GUI interactions.202MIT