K8s Agent Sandbox MCP
kubernetes-sigs/agent-sandbox
An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.
How to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install bvisible/mcp-ssh-manager ssh-manager --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/bvisible/mcp-ssh-manager.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ssh-manager .claude/skills/ssh-manager && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ssh-manager" agent skill from https://github.com/bvisible/mcp-ssh-manager/tree/main/skills/ssh-manager into .claude/skills/ssh-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssh-manager", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/bvisible/mcp-ssh-manager/tree/main/skills/ssh-managerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install bvisible/mcp-ssh-manager ssh-manager --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bvisible/mcp-ssh-manager.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ssh-manager .agents/skills/ssh-manager && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ssh-manager" agent skill from https://github.com/bvisible/mcp-ssh-manager/tree/main/skills/ssh-manager into .agents/skills/ssh-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssh-manager", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install bvisible/mcp-ssh-manager ssh-manager --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bvisible/mcp-ssh-manager.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ssh-manager .cursor/skills/ssh-manager && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ssh-manager" agent skill from https://github.com/bvisible/mcp-ssh-manager/tree/main/skills/ssh-manager into .cursor/skills/ssh-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssh-manager", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/bvisible/mcp-ssh-manager.git --path skills/ssh-manager--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install bvisible/mcp-ssh-manager ssh-manager --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bvisible/mcp-ssh-manager.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ssh-manager .gemini/skills/ssh-manager && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ssh-manager" agent skill from https://github.com/bvisible/mcp-ssh-manager/tree/main/skills/ssh-manager into .gemini/skills/ssh-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssh-manager", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install bvisible/mcp-ssh-manager ssh-managerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/bvisible/mcp-ssh-manager.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ssh-manager .github/skills/ssh-manager && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ssh-manager" agent skill from https://github.com/bvisible/mcp-ssh-manager/tree/main/skills/ssh-manager into .github/skills/ssh-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssh-manager", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install bvisible/mcp-ssh-manager ssh-manager --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bvisible/mcp-ssh-manager.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ssh-manager .opencode/skills/ssh-manager && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ssh-manager" agent skill from https://github.com/bvisible/mcp-ssh-manager/tree/main/skills/ssh-manager into .opencode/skills/ssh-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssh-manager", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ssh-managerHow to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file…
Ssh Manager is an agent skill from bvisible/mcp-ssh-manager. How to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file transfer pitfalls, security modes, host keys. Use it whenever a task runs a command or moves a file on a remote machine through these tools.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups, database operations, health monitoring. The licence is MIT.
Read from SKILL.md and the folder at commit 1611383. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ssh Manager loads about 1.2k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 681 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
- The configuration file (`~/.ssh-manager/.env`) holds passwords and key paths: never print itAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from bvisible/mcp-ssh-manager at commit 1611383, republished under its MIT licence (© bvisible). 681 words, ~1,191 tokens.
.claude/skills/ssh-manager/SKILL.md (or your agent's skills folder).This skill covers the five core tools, the ones exposed in the default minimal mode. If
more groups are enabled (ssh-manager tools list), prefer the specific tool over a raw command.
| Tool | What it does | Changes the server? |
|---|---|---|
ssh_list_servers | Lists configured servers: name, host, user, port, auth type, default directory, group. Never returns secrets. | no |
ssh_execute | Runs one command line, returns stdout, stderr, code. | depends on the command |
ssh_upload | Copies ONE local file over SFTP, overwriting the target. No backup, no sudo. | yes |
ssh_download | Copies ONE remote file to a local path (overwrites the local file). | no |
ssh_sync | rsync over SSH. One side local:, the other remote:. dryRun previews, delete removes extras at the destination. | yes |
ssh_list_servers once and use the exact names. A name is lowercase and every character
that is not a letter or a digit became _ (my-site.ch → my_site_ch). Several names can
share one host with different users: take the user with the rights you need and no more.ssh_execute runs cd -- '<cwd, or the server's default directory>' && <your command>.
Pass cwd when the default is wrong. A missing directory fails the whole call.readonly mode (destructive commands and uploads refused) or restricted
mode (only commands matching its patterns). A refusal is the configuration working: do not
look for a way around it, ask whoever owns the server.sh/dash, not bash: no <(…), no [[ … ]], no arrays, no
{a,b}, no $'…'. A syntax error aborts the whole line before any part of it ran. Pipe
instead, or wrap in bash -c '…'.<<'EOF'). Quote the delimiter so nothing is expanded by the remote shell.&& when step two must not run after a failure.pgrep -f and pkill -f match every command line, including the shell that carries your
command. Bracket one letter (pgrep -f '[n]ginx -g') and kill in one call, relaunch in the next.timeout, in ms). In practice a call can be cut after
about three minutes. A command killed halfway leaves its work half done.setsid nohup <command> > ~/job.log 2>&1 & then tail -n 20 ~/job.log.
Never run a service restart straight inside ssh_execute: if the call is cut, the restart stops
halfway and workers stay stopped.ssh_sync has its own timeout, 30 s by default: raise it for a big tree.ssh_upload replaces the target completely. On a directory other people edit (a shared git tree),
never upload a whole file over an existing one: you silently revert what changed in it since
your copy. Apply a targeted edit on the remote, or upload to your own directory.ssh_sync with dryRun: true first and read the list. Never delete: true
without having read it.ssh_download it instead of cat inside ssh_execute.known_hosts: a changed key is refused. A rebuilt server legitimately
changes its key, but never accept it blindly: compare the new key seen from two machines
(ssh-keyscan from yours and from another trusted host), then replace the old line.sshpass locally for ssh_sync.~/.ssh-manager/.env) holds passwords and key paths: never print it
and never paste it in a message.ls -la, git status, systemctl status) and use read-only calls to find
out what is wrong before restarting anything.© bvisible, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/ssh-manager of bvisible/mcp-ssh-manager.
Open the folder on GitHubat commit 1611383
Ssh Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ssh Manager this skillbvisible/mcp-ssh-manager | 502 | — | ~1.2k | Automated safety check: Warn | MIT | |
| K8s Agent Sandbox MCPkubernetes-sigs/agent-sandbox | 4.2k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Unraiddinglebear-ai/unraid | 135 | — | ~5.4k | Automated safety check: Notes | MIT | |
| Devsydevsy-org/devsy | 113 | — | ~1.7k | Automated safety check: Pass | MPL-2.0 | |
| Openai Docsaafqaq/codex-lb-enhanced | 103 | 2 repos | ~861 | Automated safety check: Pass | Apache-2.0 | |
| Unifienuno/unifi-mcp-server | 284 | — | ~1k | Automated safety check: Pass | Apache-2.0 |
kubernetes-sigs/agent-sandbox
An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.
dinglebear-ai/unraid
This skill should be used when the user mentions Unraid, asks to check server health, monitor array or disk status, list or restart Docker containers, start or stop VMs, read system logs, check…
devsy-org/devsy
Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.
aafqaq/codex-lb-enhanced
A skill your agent uses when the user asks how to build with OpenAI products or APIs and needs up-to-date official documentation with citations (for example: Codex, Responses API, Chat Completions…
enuno/unifi-mcp-server
Manage UniFi network infrastructure via the UniFi MCP Server.
VeriTeknik/pluggedin-app
A skill your agent uses when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when…
Works with
Categories
How to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file…. Ssh Manager is an agent skill from bvisible/mcp-ssh-manager. How to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file transfer pitfalls, security modes, host keys.
Ssh Manager fits situations like: A task runs a command; moves a file on a remote machine through these tools.
Run `npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a claude-code`. Or copy the skill folder (skills/ssh-manager in bvisible/mcp-ssh-manager) into .claude/skills/ssh-manager in your project. Claude Code loads it when a task matches its description.
Run `npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a codex`. Or copy the skill folder (skills/ssh-manager in bvisible/mcp-ssh-manager) into .agents/skills/ssh-manager in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ssh-manager, .gemini/skills/ssh-manager, .github/skills/ssh-manager and .opencode/skills/ssh-manager in your project.
Going by SKILL.md and its folder, Ssh Manager needs the command-line tools its instructions call (bash and git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Ssh Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ssh Manager: K8s Agent Sandbox MCP (kubernetes-sigs/agent-sandbox, 4.2k stars), Unraid (dinglebear-ai/unraid, 135 stars), Devsy (devsy-org/devsy, 113 stars) and Openai Docs (aafqaq/codex-lb-enhanced, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
bvisible (a GitHub user) maintains it in bvisible/mcp-ssh-manager, which has 502 GitHub stars. The repository was last updated on October 9, 2026.
Source: bvisible/mcp-ssh-manager on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.