{"name":"io.github.bvisible/mcp-ssh-manager","slug":"bvisible-mcp-ssh-manager","title":null,"description":"SSH server management for agents, with per-server read-only and allowlist security modes","url":"https://mcp.market/server/bvisible-mcp-ssh-manager","rating":null,"grade":"B","score":74,"certified":false,"status":"active","category":"security","tags":["security"],"presence":{"score":55,"stars":484,"forks":69,"downloads_week":617,"last_push_at":"2026-09-13T05:37:58.000Z","license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/bvisible/mcp-ssh-manager","website":null,"version":"3.8.5","remotes":[],"packages":[{"registryType":"npm","identifier":"mcp-ssh-manager","version":"3.8.5","transport":{"type":"stdio"},"environmentVariables":[{"description":"Path to a TOML file holding the server definitions. Defaults to ~/.codex/ssh-config.toml. Each server can set MODE to readonly or restricted to constrain what the agent may run.","format":"filepath","name":"SSH_CONFIG_PATH"},{"description":"Path to a .env file declaring servers as SSH_SERVER_<NAME>_HOST, _USER, _KEYPATH and friends. Defaults to a .env next to the package.","format":"filepath","name":"SSH_ENV_PATH"}]}],"tools":[],"scan":{"score":74,"grade":"B","scanned_at":"2026-09-21T05:08:28.248Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-21T05:08:28.295Z","components":{"code":{"score":13,"max":25,"notes":["46 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 8 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[{"id":"exec.shell-concat","severity":"high","component":"code","title":"Shell command built from a string (injection risk)","evidence":"src/ssh-key-manager.js: …/ Use ssh-keygen to remove the host execSync(`ssh-keygen -R \"${hostEntry}\"`, { stdio: 'ignore' }); …"}],"inputs":{"packages":[{"registryType":"npm","identifier":"mcp-ssh-manager","version":"3.8.5","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":5,"publishedAt":"2026-08-28T14:09:21.902Z","repositoryUrl":"git+https://github.com/bvisible/mcp-ssh-manager.git","weeklyDownloads":617}],"repo":{"found":true,"owner":"bvisible","repo":"mcp-ssh-manager","archived":false,"pushedAt":"2026-09-13T05:37:58Z","stars":484,"forks":69,"openIssues":13,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/26769160?v=4","ownerCreatedAt":"2017-03-29T13:34:06Z","license":"MIT"},"icon":{"url":"https://avatars.githubusercontent.com/u/26769160?v=4&s=128","source":"github"},"presence":{"stars":484,"forks":69,"downloadsWeek":617,"license":"MIT","lastPushAt":"2026-09-13T05:37:58.000Z","score":55}}}},"grade_history":[],"reviews":[]}