Agent skill

Ssh Manager

by bvisible in bvisible/mcp-ssh-manager

How to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file…

MITAuto-check: warningsDevOps & Cloud

Install Ssh Manager

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bvisible/mcp-ssh-manager ssh-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bvisible/mcp-ssh-manager.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ssh-manager .claude/skills/ssh-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ssh-manager
GitHub stars
502
Token cost
~1.2k tokens
SKILL.md length
681 words
Files
1
Repo updated
First seen
Licence
MIT

At a glance

How to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file…

  • A task runs a command
  • SKILL.md covers Before the first command, Writing the command, Time limits and long commands and Moving files, plus 2 more sections
  • Calls bash and git
  • Moves a file on a remote machine through these tools

What it does

Ssh Manager is an agent skill from bvisible/mcp-ssh-manager. How to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file transfer pitfalls, security modes, host keys. Use it whenever a task runs a command or moves a file on a remote machine through these tools.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups, database operations, health monitoring. The licence is MIT.

When your agent uses it

  • A task runs a command
  • Moves a file on a remote machine through these tools

Example prompts

  • “/ssh-manager”

What it can do on your machine

Read from SKILL.md and the folder at commit 1611383. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ssh Manager loads about 1.2k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 681 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:72
    - The configuration file (`~/.ssh-manager/.env`) holds passwords and key paths: never print it

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bvisible/mcp-ssh-manager at commit 1611383, republished under its MIT licence (© bvisible). 681 words, ~1,191 tokens.

Download SKILL.mdSave it as .claude/skills/ssh-manager/SKILL.md (or your agent's skills folder).
name
ssh-manager
description
How to use the MCP SSH Manager core tools (ssh_list_servers, ssh_execute, ssh_upload, ssh_download, ssh_sync) without breaking a server: server names, the remote shell, time limits and long commands, file transfer pitfalls, security modes, host keys. Use it whenever a task runs a command or moves a file on a remote machine through these tools.

Using the SSH Manager tools

This skill covers the five core tools, the ones exposed in the default minimal mode. If more groups are enabled (ssh-manager tools list), prefer the specific tool over a raw command.

ToolWhat it doesChanges the server?
ssh_list_serversLists configured servers: name, host, user, port, auth type, default directory, group. Never returns secrets.no
ssh_executeRuns one command line, returns stdout, stderr, code.depends on the command
ssh_uploadCopies ONE local file over SFTP, overwriting the target. No backup, no sudo.yes
ssh_downloadCopies ONE remote file to a local path (overwrites the local file).no
ssh_syncrsync over SSH. One side local:, the other remote:. dryRun previews, delete removes extras at the destination.yes

Before the first command

  • Call ssh_list_servers once and use the exact names. A name is lowercase and every character that is not a letter or a digit became _ (my-site.ch → my_site_ch). Several names can share one host with different users: take the user with the rights you need and no more.
  • ssh_execute runs cd -- '<cwd, or the server's default directory>' && <your command>. Pass cwd when the default is wrong. A missing directory fails the whole call.
  • A server can be in readonly mode (destructive commands and uploads refused) or restricted mode (only commands matching its patterns). A refusal is the configuration working: do not look for a way around it, ask whoever owns the server.

Writing the command

  • Assume the remote shell is sh/dash, not bash: no <(…), no [[ … ]], no arrays, no {a,b}, no $'…'. A syntax error aborts the whole line before any part of it ran. Pipe instead, or wrap in bash -c '…'.
  • Heredocs work (<<'EOF'). Quote the delimiter so nothing is expanded by the remote shell.
  • Chain with && when step two must not run after a failure.
  • pgrep -f and pkill -f match every command line, including the shell that carries your command. Bracket one letter (pgrep -f '[n]ginx -g') and kill in one call, relaunch in the next.
  • Never put a password or token in the command line: it ends up in the remote process list and in logs. Use a file with mode 600 or an environment variable set on the remote side.
Show full SKILL.md (315 more words)Show less

Time limits and long commands

  • Default timeout 120 s, maximum 300 s (timeout, in ms). In practice a call can be cut after about three minutes. A command killed halfway leaves its work half done.
  • Anything long or that restarts a service (builds, migrations, big copies, restarts): start it detached and poll with short calls. setsid nohup <command> > ~/job.log 2>&1 & then tail -n 20 ~/job.log. Never run a service restart straight inside ssh_execute: if the call is cut, the restart stops halfway and workers stay stopped.
  • ssh_sync has its own timeout, 30 s by default: raise it for a big tree.

Moving files

  • ssh_upload replaces the target completely. On a directory other people edit (a shared git tree), never upload a whole file over an existing one: you silently revert what changed in it since your copy. Apply a targeted edit on the remote, or upload to your own directory.
  • For trees, run ssh_sync with dryRun: true first and read the list. Never delete: true without having read it.
  • To read a big file (a log, a dump), ssh_download it instead of cat inside ssh_execute.

Host keys and secrets

  • Hosts are checked against known_hosts: a changed key is refused. A rebuilt server legitimately changes its key, but never accept it blindly: compare the new key seen from two machines (ssh-keyscan from yours and from another trusted host), then replace the old line.
  • Prefer key authentication. Password servers need sshpass locally for ssh_sync.
  • The configuration file (~/.ssh-manager/.env) holds passwords and key paths: never print it and never paste it in a message.

Good habits

  • Look before you change (ls -la, git status, systemctl status) and use read-only calls to find out what is wrong before restarting anything.
  • Do not retry a destructive command that failed until you know why it failed.
  • When you report back, name the servers you touched and the commands that changed something.

© bvisible, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ssh-manager of bvisible/mcp-ssh-manager.

Open the folder on GitHubat commit 1611383

Compare with similar skills

Ssh Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ssh Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ssh Manager this skillbvisible/mcp-ssh-manager502—~1.2kAutomated safety check: WarnMIT
K8s Agent Sandbox MCPkubernetes-sigs/agent-sandbox4.2k—~1.3kAutomated safety check: PassApache-2.0
Unraiddinglebear-ai/unraid135—~5.4kAutomated safety check: NotesMIT
Devsydevsy-org/devsy113—~1.7kAutomated safety check: PassMPL-2.0
Openai Docsaafqaq/codex-lb-enhanced1032 repos~861Automated safety check: PassApache-2.0
Unifienuno/unifi-mcp-server284—~1kAutomated safety check: PassApache-2.0

Similar skills

  • K8s Agent Sandbox MCP

    kubernetes-sigs/agent-sandbox

    Official

    An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.

    4.2k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Unraid

    dinglebear-ai/unraid

    This skill should be used when the user mentions Unraid, asks to check server health, monitor array or disk status, list or restart Docker containers, start or stop VMs, read system logs, check…

    135 GitHub stars~5.4k tokensUpdated 7 days ago
    DevOps & CloudAuto-check: notes
  • Devsy

    devsy-org/devsy

    Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.

    113 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Openai Docs

    aafqaq/codex-lb-enhanced

    A skill your agent uses when the user asks how to build with OpenAI products or APIs and needs up-to-date official documentation with citations (for example: Codex, Responses API, Chat Completions…

    103 GitHub starsUsed in 2 repos~861 tokens
    DevOps & CloudAuto-check passed
  • Unifi

    enuno/unifi-mcp-server

    Manage UniFi network infrastructure via the UniFi MCP Server.

    284 GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Pluggedin Stack Ops

    VeriTeknik/pluggedin-app

    A skill your agent uses when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when…

    103 GitHub stars~1.3k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes

Questions about Ssh Manager

What does Ssh Manager do?

How to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file…. Ssh Manager is an agent skill from bvisible/mcp-ssh-manager. How to use the MCP SSH Manager core tools (sshlistservers, sshexecute, sshupload, sshdownload, sshsync) without breaking a server: server names, the remote shell, time limits and long commands, file transfer pitfalls, security modes, host keys.

When should I use Ssh Manager?

Ssh Manager fits situations like: A task runs a command; moves a file on a remote machine through these tools.

How do I install Ssh Manager in Claude Code?

Run `npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a claude-code`. Or copy the skill folder (skills/ssh-manager in bvisible/mcp-ssh-manager) into .claude/skills/ssh-manager in your project. Claude Code loads it when a task matches its description.

How do I install Ssh Manager in Codex?

Run `npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a codex`. Or copy the skill folder (skills/ssh-manager in bvisible/mcp-ssh-manager) into .agents/skills/ssh-manager in your project. Codex loads it when a task matches its description.

Can I use Ssh Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bvisible/mcp-ssh-manager --skill ssh-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ssh-manager, .gemini/skills/ssh-manager, .github/skills/ssh-manager and .opencode/skills/ssh-manager in your project.

What does Ssh Manager need to run?

Going by SKILL.md and its folder, Ssh Manager needs the command-line tools its instructions call (bash and git).

Does Ssh Manager access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ssh Manager safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Ssh Manager use?

Ssh Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ssh Manager use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ssh Manager?

Skills that share tags, products or a category with Ssh Manager: K8s Agent Sandbox MCP (kubernetes-sigs/agent-sandbox, 4.2k stars), Unraid (dinglebear-ai/unraid, 135 stars), Devsy (devsy-org/devsy, 113 stars) and Openai Docs (aafqaq/codex-lb-enhanced, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ssh Manager?

bvisible (a GitHub user) maintains it in bvisible/mcp-ssh-manager, which has 502 GitHub stars. The repository was last updated on October 9, 2026.

Source: bvisible/mcp-ssh-manager on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.