ssh-mcp-pro (oaslananka/ssh-mcp-pro) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.
ssh-mcp-pro is a secure Model Context Protocol (MCP) server for SSH automation, enabling clients to open SSH sessions, run commands, manage files, transfer artifacts, create tunnels, and perform package/service operations under policy control.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
oaslananka
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
ACCESS_TOKEN_TTL_SECONDSAGENT_WS_HEARTBEAT_INTERVAL_MSAGENT_WS_HELLO_TIMEOUT_MSAGENT_WS_IDLE_TIMEOUT_MSAGENT_WS_MAX_CONNECTIONSAGENT_WS_MAX_CONNECTIONS_PER_AGENTAGENT_WS_PATHAUTH_ALLOWED_GITHUB_IDSAUTH_ALLOWED_GITHUB_LOGINSAUTH_ALLOW_ALL_USERSAUTH_CODE_TTL_SECONDSCOMMIT_RANGECONTROL_PLANE_SIGNING_KEY_PATHComSpecENROLLMENT_TOKEN_TTL_SECONDSGITHUB_CALLBACK_URLGITHUB_CLIENT_IDGITHUB_CLIENT_SECRETGITHUB_PR_TITLEGITHUB_STEP_SUMMARYJWT_SIGNING_KEY_PATHKNOWN_HOSTS_PATHThe parser also accepts non-SSH_MCP_ compatibility aliases PORT, , and STRICT_HOST_KEY_CHECKING.LOG_FORMATLOG_LEVELMAX_ACTION_TIMEOUT_SECONDSMAX_OUTPUT_BYTESMCP_RESOURCE_URLOAUTH_DCR_MAX_CLIENTSPR_TITLEPUBLIC_BASE_URLRUN_SSH_E2ERUN_SSH_INTEGRATIONSSHAUTOMATOR_AGENT_CONFIGSSHAUTOMATOR_DATABASE_URLSSHAUTOMATOR_GITHUB_CALLBACK_URLSSHAUTOMATOR_MCP_RESOURCE_URLSSHAUTOMATOR_PUBLIC_BASE_URLSSHAUTOMATOR_REMOTE_AGENT_CONTROL_PLANESSHAUTOMATOR_TEST_GITHUB_IDSSHAUTOMATOR_TEST_GITHUB_LOGINSSH_AUTH_SOCKSSH_DEFAULT_KEY_DIRSSH_FIXTURE_TIMEOUT_MSSSH_FIXTURE_UP_ATTEMPTSSSH_FIXTURE_UP_RETRY_DELAY_MSSSH_MCP_ALLOWED_CIPHERSempty Optional SSH cipher allowlist.SSH_MCP_ALLOWED_HOSTSempty Host allowlist for policy and remote connector safety checks.SSH_MCP_ALLOW_DESTRUCTIVE_COMMANDSfalse Allows commands matching destructive command policy.SSH_MCP_ALLOW_DESTRUCTIVE_FSfalse Allows destructive filesystem operations such as fs_rmrf.SSH_MCP_ALLOW_RAW_SUDOfalse Allows raw proc_sudo; prefer ensure_ tools.SSH_MCP_ALLOW_ROOT_LOGINfalse Allows SSH login as root and mirrors into policy.SSH_MCP_CHATGPT_EXTRA_TOOLSSSH_MCP_CLAUDE_EXTRA_TOOLSSSH_MCP_COMMAND_ALLOWempty Command allow patterns.SSH_MCP_COMMAND_DENYempty Command deny patterns.SSH_MCP_COMMAND_TIMEOUT30000 Default remote command timeout in milliseconds.SSH_MCP_CONNECTOR_CREDENTIAL_COMMANDunset External credential command when provider is command.SSH_MCP_CONNECTOR_CREDENTIAL_COMMAND_ARGSempty Arguments passed to the external credential command.SSH_MCP_CONNECTOR_CREDENTIAL_COMMAND_TIMEOUT_MS5000 Credential command timeout in milliseconds.SSH_MCP_CONNECTOR_CREDENTIAL_PROVIDERnone Credential provider: none, agent, or command.SSH_MCP_CONNECTOR_DEFAULT_USERNAMEunset Default username for connector broker flows.SSH_MCP_CONNECTOR_PROFILEfull Alias for SSH_MCP_TOOL_PROFILE.SSH_MCP_DAEMONSSH_MCP_DEBUGfalse Enables debug-oriented configuration behavior.SSH_MCP_ENABLE_LEGACY_SSEfalse Enables legacy SSE compatibility.SSH_MCP_HOST_KEY_POLICYstrict Host-key mode: strict, accept-new, or insecure.SSH_MCP_HTTP_ALLOWED_ORIGINSSSH_MCP_HTTP_AUTH_MODEbearer HTTP auth mode: bearer or oauth.SSH_MCP_HTTP_BEARER_TOKENSSH_MCP_HTTP_BEARER_TOKEN_FILEunset Bearer token file for HTTP transport. Required for non-loopback bearer deployments.SSH_MCP_HTTP_HOST127.0.0.1 Streamable HTTP bind host.SSH_MCP_HTTP_MAX_REQUEST_BODY_BYTES1048576 Maximum HTTP request body size.SSH_MCP_HTTP_MAX_SESSIONSSSH_MCP_HTTP_PORT3000 Streamable HTTP bind port.SSH_MCP_HTTP_PUBLIC_URLunset Stable public HTTPS MCP URL for protected resource metadata.SSH_MCP_HTTP_SESSION_IDLE_TTL_MS900000 HTTP MCP session idle timeout in milliseconds. Use 300000 for ChatGPT/Cloudflare production deployments where clients may abandon sessions without DELETE.SSH_MCP_HTTP_TRUST_PROXYfalse Trust reverse proxy forwarded headers.SSH_MCP_KNOWN_HOSTS_PATH~/.ssh/known_hosts Known hosts file used for strict host-key verification.SSH_MCP_LOCAL_PATH_ALLOW_PREFIXESOS temp directory Local paths allowed for transfer operations.SSH_MCP_LOCAL_PATH_DENY_PREFIXESempty Local paths denied for transfer operations.SSH_MCP_MAX_COMMAND_OUTPUT_BYTES1048576 Maximum buffered stdout/stderr bytes per command result.SSH_MCP_MAX_FILE_SIZE10485760 Maximum bytes returned by text-focused file reads.SSH_MCP_MAX_FILE_WRITE_BYTES10485760 Maximum accepted write payload before buffering.SSH_MCP_MAX_SESSIONS20 Maximum concurrent SSH sessions.SSH_MCP_MAX_STREAM_CHUNKS4096 Maximum retained streaming chunks.SSH_MCP_MAX_TRANSFER_BYTES52428800 Maximum upload or download transfer size.SSH_MCP_OAUTH_ALLOWED_ALGORITHMSunset Optional comma-separated JWT algorithm allowlist, for example RS256,ES256. When unset, the built-in OAuth verifier defaults are used.SSH_MCP_OAUTH_AUDIENCEunset Expected OAuth audience.SSH_MCP_OAUTH_ISSUERunset Expected OAuth issuer.SSH_MCP_OAUTH_JWKS_URLunset OAuth JWKS URL.SSH_MCP_OAUTH_REQUIRED_SCOPESssh-mcp-pro.read Required OAuth scopes.SSH_MCP_OAUTH_RESOURCEunset OAuth protected resource identifier.SSH_MCP_ONESHOTSSH_MCP_PATH_ALLOW_PREFIXES/tmp,/var/tmp,/home,/Users Remote path prefixes allowed by filesystem policy.SSH_MCP_PATH_DENY_PREFIXES/etc/sudoers,/etc/shadow,/etc/passwd,/boot,/dev,/proc Remote path prefixes denied by filesystem policy.SSH_MCP_POLICY_FILEunset JSON file containing partial policy overrides.SSH_MCP_POLICY_MODEenforce Policy decision mode: enforce or explain.SSH_MCP_RATE_LIMITtrue Enables the global MCP request rate limiter.SSH_MCP_RATE_LIMIT_MAX100 Maximum requests per rate-limit window.SSH_MCP_RATE_LIMIT_PER_SESSIONtrue Enables per-session MCP request rate limiting when tool arguments include sessionId.SSH_MCP_RATE_LIMIT_PER_SESSION_MAX50 Maximum requests per SSH session per rate-limit window.SSH_MCP_RATE_LIMIT_PER_SESSION_WINDOW_MS60000 Per-session rate-limit window in milliseconds.SSH_MCP_RATE_LIMIT_WINDOW_MS60000 Rate-limit window in milliseconds.SSH_MCP_REMOTE_AGENT_CONTROL_PLANESSH_MCP_REMOTE_AGENT_MCP_PASSTHROUGHunset When enabled with 1, true, yes, or on, lets /mcp requests bypass the remote control plane and reach the Streamable HTTP MCP handler. Use only for connector routing migrations.SSH_MCP_SESSION_TTL900000 Session time-to-live in milliseconds.SSH_MCP_STRICT_HOST_KEYunset Legacy boolean alias for strict vs insecure host-key checking.SSH_MCP_TOOL_PROFILEfull Active tool exposure profile.SSH_MCP_TUNNEL_ALLOW_BIND_HOSTS127.0.0.1,localhost,::1 Local bind hosts allowed for tunnels.SSH_MCP_TUNNEL_ALLOW_PORTSempty Optional tunnel port allowlist.SSH_MCP_TUNNEL_ALLOW_REMOTE_HOSTSempty Optional remote tunnel target host allowlist.SSH_MCP_TUNNEL_DENY_BIND_HOSTS0.0.0.0,:: Local bind hosts denied for tunnels.SSH_MCP_TUNNEL_DENY_PORTSempty Optional tunnel port denylist.SSH_MCP_TUNNEL_DENY_REMOTE_HOSTSempty Optional remote tunnel target host denylist.STRICT_HOST_KEY_CHECKINGThe parser also accepts non-SSH_MCP_ compatibility aliases PORT, KNOWN_HOSTS_PATH, and .DATABASE_URLPORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
46/46 tools missing one or more hints — connector_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); ssh_hosts_list (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); ssh_policy_explain (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +43 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 11/46 tools referenced in tests (24%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
13 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/oaslananka-ssh-mcp-pro-1lwwxm)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check