Skip to main content
Glama
smk-h

embedded-mcp-toolkit

by smk-h

ssh_shell_exec

Send a command to an SSH session, wait for it to finish, and retrieve the output—combining write and read with automatic completion detection.

Instructions

Send a command to an SSH shell session and wait for the output. Combines write + read in one call, with automatic completion detection (marker/prompt). IMPORTANT: Do NOT issue concurrent commands to the same session_id — the SSH shell is a single channel; concurrent calls will interleave output and corrupt results. Always wait for the previous command to finish before sending the next one. If you need parallel execution, open multiple sessions via ssh_shell_open.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
clearNoBuffer clear flag: 1 (default) = clear buffer before collecting, 0 = append to buffer
commandYesThe command to send to the shell
timeoutMsNoExecution cap in ms — MANDATORY on every call: estimate the command's expected runtime and pass it; omit it ONLY when the user explicitly says not to pass a timeout. Suggested estimates: basic instant commands (ls/pwd/echo/cat small files/ip addr/uname) 3000-5000, never above 10000; output-heavy commands (cat large files, dmesg/journalctl with long output, log dumps) 20000-30000; medium tasks (apt install, dd, service restart) 30000-120000; reboot/reset/power-cycle up to 120000; streaming/resident commands (ping/logcat/top, or sampling a fixed window of live output) 10000 (Ctrl+C auto-sent to stop). Do NOT pass 300000 — the 5-minute value is the internal safety-valve fallback only, not a suggested estimate; if a command genuinely needs longer than ~2min, pass an explicit larger value. If omitted, safety-valve defaults apply: resident commands 10000ms (sampling, Ctrl+C sent on timeout), other commands 300000ms (5min fallback, NO interrupt sent — the command may still be running, terminate via send_ctrl if needed). Timeout type is annotated in the returned output.
session_idYesThe session ID returned by ssh_shell_open

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv2.0.0
    • removedInput schema / properties / delay
      Removed value: -{
      -  "description": "Minimum polling duration in milliseconds (default: 1000), kept for backward compat",
      -  "type": "number"
      -}
    • removedInput schema / properties / maxDuration
      Removed value: -{
      -  "description": "Execution cap in ms — ALWAYS estimate and pass a timeout matching the command's expected runtime; do not omit it. Suggested ranges: instant info commands (ls/ip addr/cat/echo) 3000-5000; medium tasks (apt install, dd, service restart) 30000-120000; long builds/flashes (make, flash_image) up to 600000; streaming/resident commands (ping/logcat/top, or sampling a fixed window of live output) 10000 (Ctrl+C auto-sent to stop). If omitted, safety-valve defaults apply: resident commands 10000ms (sampling, Ctrl+C sent on timeout), other commands 300000ms (5min fallback, NO interrupt sent — the command may still be running, terminate via send_ctrl if needed). Timeout type is annotated in the returned output.",
      -  "type": "number"
      -}
    • addedInput schema / properties / timeoutMs
      Added value: +{
      +  "description": "Execution cap in ms — MANDATORY on every call: estimate the command's expected runtime and pass it; omit it ONLY when the user explicitly says not to pass a timeout. Suggested estimates: basic instant commands (ls/pwd/echo/cat small files/ip addr/uname) 3000-5000, never above 10000; output-heavy commands (cat large files, dmesg/journalctl with long output, log dumps) 20000-30000; medium tasks (apt install, dd, service restart) 30000-120000; reboot/reset/power-cycle up to 120000; streaming/resident commands (ping/logcat/top, or sampling a fixed window of live output) 10000 (Ctrl+C auto-sent to stop). Do NOT pass 300000 — the 5-minute value is the internal safety-valve fallback only, not a suggested estimate; if a command genuinely needs longer than ~2min, pass an explicit larger value. If omitted, safety-valve defaults apply: resident commands 10000ms (sampling, Ctrl+C sent on timeout), other commands 300000ms (5min fallback, NO interrupt sent — the command may still be running, terminate via send_ctrl if needed). Timeout type is annotated in the returned output.",
      +  "type": "number"
      +}
  2. Changed1 schema field changedv1.3.0
    • changedInput schema / properties / maxDuration / description
      Previous value: -"Override execution duration in ms. Default varies by command type: resident commands (ping/logcat/top/...) 10000 (sampling, Ctrl+C sent on timeout), normal commands 300000 (5min fallback, no interrupt sent). Action on timeout still follows resident classification regardless of this value."New value: +"Execution cap in ms — ALWAYS estimate and pass a timeout matching the command's expected runtime; do not omit it. Suggested ranges: instant info commands (ls/ip addr/cat/echo) 3000-5000; medium tasks (apt install, dd, service restart) 30000-120000; long builds/flashes (make, flash_image) up to 600000; streaming/resident commands (ping/logcat/top, or sampling a fixed window of live output) 10000 (Ctrl+C auto-sent to stop). If omitted, safety-valve defaults apply: resident commands 10000ms (sampling, Ctrl+C sent on timeout), other commands 300000ms (5min fallback, NO interrupt sent — the command may still be running, terminate via send_ctrl if needed). Timeout type is annotated in the returned output."
  3. Addedv1.0.3
  4. Removedv1.0.1
  5. First observedv0.2.2

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral burden and does so thoroughly. It discloses the single-channel nature, automatic completion detection, buffer-clearing behavior, and the risk of interleaved output, plus timeout fallback semantics and how to recover via send_ctrl.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The main description is two well-structured sentences: the purpose is front-loaded, followed by a critical concurrency warning. There is zero filler, and detailed timeout material is appropriately located in the schema rather than the prose.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers every operational concern needed to invoke the tool correctly: combined write/read behavior, completion detection, concurrency constraints, timeout estimates, fallback values, and interrupt semantics. Although there is no output schema, it still notes that timeout type is annotated in the returned output, providing sufficient context.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The main description body does not add extra meaning beyond the schema; the rich timeout guidance is already inside the parameter description, and the prose only implicitly references session_id. No additional parameter-level insight is provided in the main description.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('Send a command'), identifies the resource (SSH shell session), and states the expected result (wait for output). It explicitly says it combines write + read in one call, distinguishing it from sibling tools like ssh_shell_write and ssh_shell_read.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives explicit when-not guidance: do not issue concurrent commands to the same session_id, and always wait for the previous command to finish. It names the alternative for parallel execution (ssh_shell_open), giving the agent a clear routing decision.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.