MCP server for SSH remote server management
SaferSkills independently audited cygnus-ssh-mcp (MCP Server) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<div align="center">
<img src="https://raw.githubusercontent.com/cygnussystems/cygnus-ssh-mcp/master/assets/banner.png" alt="cygnus-ssh-mcp" width="400">
The most powerful SSH MCP server for AI assistants
Give Claude full control of your Linux, macOS, and Windows servers with 43 specialized tools
Installation · Quick Start · Features · Documentation
</div>
Most SSH MCP servers let you run commands. cygnus-ssh-mcp lets you manage servers.
| What you get | Basic SSH MCP | cygnus-ssh-mcp |
|---|---|---|
| Run commands | ✅ | ✅ |
| Pre-configured hosts with aliases | ❌ | ✅ |
| Sudo support (Linux/macOS) | Limited | ✅ |
| Windows Server support | ❌ | ✅ |
| Background task management | ❌ | ✅ |
| Line-level file editing | ❌ | ✅ |
| Command history with output | ❌ | ✅ |
| Recursive directory operations | ❌ | ✅ |
| Archive create/extract | ❌ | ✅ |
| Full Unicode support | ? | ✅ |
pip install cygnus-ssh-mcpOr run without installing using uvx:
uvx cygnus-ssh-mcpCreate ~/.mcp_ssh_hosts.toml:
# Minimal (password auth) - only required fields
["[email protected]"]
password = "your_password"
port = 22
# With alias and sudo (most common setup)
["[email protected]"]
password = "your_password"
port = 22
sudo_password = "sudo_pass" # optional: for use_sudo operations
alias = "prod" # optional: connect by alias
description = "Production server" # optional: for documentation
# SSH key authentication
["[email protected]"]
keyfile = "~/.ssh/id_ed25519"
port = 22
alias = "staging"
# Windows Server (requires OpenSSH)
["[email protected]"]
password = "your_password"
port = 22
alias = "win-prod"Required fields: port + (password OR keyfile) Optional fields: alias, description, sudo_password, key_passphrase
Host file locations: Default is~/.mcp_ssh_hosts.toml. Falls back to./mcp_ssh_hosts.tomlif not found. Use--config /path/to/hosts.tomlfor a custom location.
Edit your claude_desktop_config.json:
{
"mcpServers": {
"ssh": {
"command": "cygnus-ssh-mcp"
}
}
}Or with a custom hosts file location:
{
"mcpServers": {
"ssh": {
"command": "cygnus-ssh-mcp",
"args": ["--config", "/path/to/my_hosts.toml"]
}
}
}In Claude, just say:
"Connect to prod and show me the disk usage"
"Edit /etc/nginx/nginx.conf and change worker_connections to 2048"
"Find all .log files larger than 100MB in /var/log"
cygnus-ssh-mcp works from any client (Windows, Linux, macOS) to any target server:
<div align="center"> <img src="https://raw.githubusercontent.com/cygnussystems/cygnus-ssh-mcp/master/assets/ssh_mcp_platforms.png" alt="Platform Support" width="600"> </div>
| From (Client) | To (Target) | Status |
|---|---|---|
| Windows | Linux | ✅ Tested |
| Windows | Windows | ✅ Tested |
| Linux | Linux | ✅ Tested |
| Linux | Windows | ✅ Tested |
| macOS | Any | ✅ Supported |
Windows targets require OpenSSH Server installed and running.
Stop typing credentials. Connect by alias.
["[email protected]"]
password = "secret"
port = 22
alias = "web"Then just: "Connect to web"
Supports password, SSH key, and encrypted keys with passphrase.
Edit config files with surgical precision—no download/upload needed.
# Replace a single line
ssh_file_replace_line(
file_path="/etc/nginx/nginx.conf",
match_line="worker_connections 1024;",
new_line="worker_connections 4096;"
)
# Insert lines after a match
ssh_file_insert_lines_after_match(
file_path="/etc/hosts",
match_line="# Custom entries",
lines_to_insert=["192.168.1.10 app.local", "192.168.1.11 db.local"]
)Safety built-in: Operations fail if the match isn't unique—no accidental mass edits.
Launch long-running processes and check back later.
# Start a backup (returns immediately)
ssh_task_launch(command="./backup.sh", stdout_log="/var/log/backup.log")
# Check status anytime
ssh_task_status(pid=12345) # → 'running' or 'exited'
# Kill if needed
ssh_task_kill(pid=12345, force=True)Every tool supports use_sudo. Password is handled automatically.
ssh_file_write(path="/etc/app/config.yaml", content="...", use_sudo=True)
ssh_dir_mkdir(path="/opt/myapp", use_sudo=True)
ssh_archive_extract(archive="/backup.tar.gz", dest="/", use_sudo=True)Never get stuck on a hanging command.
ssh_cmd_run(
command="./long_script.sh",
io_timeout=60.0, # Kill if no output for 60s
runtime_timeout=3600.0 # Kill if total time exceeds 1 hour
)Write and read files with emojis, international text, and special characters—on all platforms.
✅ ❌ 🎉 • → ≥ ∞ │ ┌ ─ 你好 مرحبا Привет café naïveHow it works: ssh_file_read and ssh_file_write use SFTP for direct binary transfer, completely bypassing shell encoding issues. This means Unicode works perfectly even on Windows targets where PowerShell's console encoding would normally corrupt special characters.
Full support for Windows targets with OpenSSH Server:
Note: use_sudo is ignored on Windows (no sudo equivalent). For elevated operations, connect with an Administrator account.
| Tool | Description |
|---|---|
ssh_conn_connect | Connect using pre-configured host (by key or alias) |
ssh_conn_is_connected | Check if SSH connection is active |
ssh_conn_status | Get connection status (user, host, OS, cwd) |
ssh_conn_host_info | Get detailed system information |
ssh_conn_verify_sudo | Verify sudo access |
ssh_conn_add_host | Add new host to configuration |
ssh_host_list | List all configured hosts |
ssh_host_remove | Remove host from configuration |
ssh_host_disconnect | Disconnect current session |
list_tools | List all available tools |
| Tool | Description |
|---|---|
ssh_cmd_run | Execute command with I/O and runtime timeouts |
ssh_cmd_kill | Terminate running command |
ssh_cmd_check_status | Check command status |
ssh_cmd_output | Retrieve output from command |
ssh_cmd_history | Get command history with filtering |
ssh_cmd_clear_history | Clear command history |
| Tool | Description |
|---|---|
ssh_task_launch | Launch command in background |
ssh_task_status | Check if task is running |
ssh_task_kill | Send signal to task |
| Tool | Description |
|---|---|
ssh_file_stat | Get file metadata |
ssh_file_read | Read file contents via SFTP (Unicode-safe) |
ssh_file_write | Create/overwrite/append file |
ssh_file_copy | Copy file |
ssh_file_move | Move or rename file |
ssh_file_transfer | Upload or download files |
ssh_file_find_lines_with_pattern | Search for pattern in file |
ssh_file_get_context_around_line | Get context around match |
ssh_file_replace_line | Replace single line |
ssh_file_replace_line_multi | Replace with multiple lines |
ssh_file_insert_lines_after_match | Insert lines after match |
ssh_file_delete_line_by_content | Delete line by content |
| Tool | Description |
|---|---|
ssh_dir_mkdir | Create directory |
ssh_dir_remove | Remove directory |
ssh_dir_list_files_basic | Basic directory listing |
ssh_dir_list_advanced | Recursive listing with metadata |
ssh_dir_search_glob | Search files by pattern |
ssh_dir_search_files_content | Search text in files |
ssh_dir_calc_size | Calculate directory size |
ssh_dir_delete | Delete with dry-run support |
ssh_dir_batch_delete_files | Batch delete by pattern |
ssh_dir_copy | Copy directory recursively |
| Tool | Description |
|---|---|
ssh_archive_create | Create tar.gz archive |
ssh_archive_extract | Extract archive |
Detailed guides available in docs/:
GPL-3.0 — Free and open source.
<div align="center">
Built by [Cygnus Systems](https://github.com/cygnussystems)
Star this repo if you find it useful!
</div>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.