SSH-based MCP server for remote command execution and file transfer. Credentials stay local.
基于 SSH 的 MCP (Model Context Protocol) 服务器,Go 实现。让 AI 助手通过 MCP 协议远程执行命令、传输文件,SSH 凭据完全留在本地,不暴露给模型。
本项目参考了 classfang/ssh-mcp-server(TypeScript 版)的设计与实现,在其基础上用 Go 重写,并将文件操作整合为单个工具、支持进度通知。感谢原作者的开源贡献。
AI 助手只看到四个 MCP 工具;本机进程负责 SSH,凭据不会进入模型上下文。
| 读者 | 文档 | 说明 |
|---|---|---|
| 🤖 AI Agent | docs/AGENT_GUIDE.md | 省 token 版:工具参数、配置、安全模式、部署命令速查 |
| 👤 人类用户 | docs/HUMAN_GUIDE.md | 易读版:安全配置、快速开始、工具说明、参数速查、发布流程 |
| 🔍 特性详情 | docs/FEATURES.md | 完整特性列表与已知限制(英文版 .en.md) |
| 🛠 开发与发布 | docs/DEVELOPMENT.md | 项目结构、构建测试、Release 与 MCP Registry 发布流程 |
| 🔐 安全 | SECURITY.md | 威胁模型、审批闸门、审计落盘策略与分级加固建议 |
各文档均为中文默认,同名 .en.md 为英文版。
list-servers / execute-command / session / file-transfer;后台长任务是 execute-command 的 background: true 特殊模式,不是第五个工具.ssh-mcp-out/),Agent 用 Read/Grep 查全文,不远程重跑approvalMode: "ask-destructive" 经 MCP elicitation 弹窗确认,内置分类器 + 用户扩展/豁免,灰色地带用户自定;客户端不支持时 fail-openaudit-verify);落盘策略批量/写穿可调 → 审计日志via(OpenSSH ProxyJump)经跳板 direct-tcpip 连内网,各跳独立认证、不转发 agent,exec/shell/SFTP 行为与直连一致 → 跳板机完整特性列表见 docs/FEATURES.md。
# 构建
go build -o 2native-ssh-mcp.exe .
# stdio 模式(MCP 客户端拉起,凭据放 config.json 或环境变量)
2native-ssh-mcp.exe --config-file config.json
# HTTP 常驻服务
2native-ssh-mcp.exe start --config-file config.json --http-addr 127.0.0.1:8338
详细配置与部署步骤见上方两份指南。
ISC License(与上游一致,保留上游版权声明,见 LICENSE)
This listing does not have a supported local package template. Use the maintainer’s documentation for its hosted endpoint, authentication, and client-specific setup. No install command has been inferred.
https://github.com/daidaiJ/2native-ssh-mcp/releases/download/v1.7.0/2native-ssh-mcp-darwin-amd64.mcpbother2native SSH MCP Server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.