Skip to main content

🔗 RemoteShell MCP

A Model Context Protocol (MCP) server that enables LLMs to securely manage and execute commands on remote SSH servers.

✨ Features

  • 🔐 Secure credential management - Save SSH server profiles once, no need to retype credentials
  • 💻 Remote command execution - Execute non-interactive shell commands remotely
  • 📁 File operations - Upload/download files via SFTP
  • 🤖 LLM-powered - Built with FastMCP and Paramiko

🚀 Installation

RemoteShell is a stdio MCP server distributed on PyPI. Run it directly with uvx — no install step required. Then register the server with your AI coding agent:

Claude Code

claude mcp add remoteshell --scope user -- uvx remoteshell-mcp

Codex

codex mcp add remoteshell -- uvx remoteshell-mcp

Other agents — click yours to expand 👇

Cursor
cursor mcp add remoteshell -- uvx remoteshell-mcp
Antigravity

Edit ~/.gemini/config/mcp_config.json (global) or .agents/mcp_config.json (project):

{
  "mcpServers": {
    "remoteshell": {
      "command": "uvx",
      "args": ["remoteshell-mcp"]
    }
  }
}

Or open the MCP Servers view in the Antigravity TUI and run the /mcp command.

OpenCode
opencode mcp add

Choose local, then enter uvx remoteshell-mcp.

Hermes Agent (NousResearch)

Edit ~/.hermes/config.yaml:

mcp_servers:
  remoteshell:
    command: "uvx"
    args: ["remoteshell-mcp"]

Run /reload-mcp in the Hermes TUI to pick up the new server.

OpenClaw

Edit ~/.openclaw/openclaw.json:

{
  "mcp": {
    "servers": {
      "remoteshell": {
        "command": "uvx",
        "args": ["remoteshell-mcp"]
      }
    }
  }
}

Or run openclaw configure to add it via the interactive wizard.

Other MCP clients

Add this to your MCP client configuration:

{
  "mcpServers": {
    "remoteshell": {
      "command": "uvx",
      "args": ["remoteshell-mcp"]
    }
  }
}

📖 Usage

Getting started is easy! You can either:

  1. 🤖 Let the LLM configure for you - Simply tell the LLM your host, username, password, etc., and ask it to set up the server configuration
  2. ⚙️ Manual configuration - Directly edit the configuration file at ~/.config/remoteshell/hosts.json

💾 Configuration & Storage

RemoteShell securely stores your server configurations in:

~/.config/remoteshell/hosts.json

🔧 Configuration Management

  • LLM-managed: The LLM automatically manages this file using save_server and remove_server tools
  • Manual editing: You can also directly edit the JSON file for advanced configurations

📋 Example Configuration

{
  "version": 1,
  "servers": {
    "production-server": {
      "host": "1.2.3.4",
      "user": "root",
      "port": 22,
      "auth_type": "password",
      "password": "your_secure_password",
      "last_connected": null
    },
    "staging-server": {
      "host": "staging.example.com",
      "user": "ubuntu",
      "port": 22,
      "auth_type": "private_key",
      "private_key": "~/.ssh/id_rsa",
      "last_connected": "2025-01-01T00:00:00+00:00"
    }
  }
}

🔒 Security Note

On POSIX systems, protect your configuration file:

chmod 600 ~/.config/remoteshell/hosts.json

🛠️ Available Tools

RemoteShell provides the following MCP tools for remote server management:

📋 list_servers()

Purpose: Display all saved server profiles with their connection status and last activity.

When to use:

  • User asks to "connect to server" or "show machines"
  • No specific connection_id is provided
  • Need to see available servers

Example: "Show me which servers I have configured" → Returns list of all saved servers with online status

💾 save_server(connection_id, host, user, auth_type, credential, port)

Purpose: Create or update a server profile with authentication credentials.

Parameters:

  • connection_id: Unique identifier for the server (e.g., "production", "staging")
  • host: Server hostname or IP address
  • user: SSH username
  • auth_type: "password" or "private_key"
  • credential:
    • For password: Plain text password string
    • For private_key: File path (e.g., ~/.ssh/id_rsa) or PEM key content
  • port: SSH port (optional; defaults to 22 and keeps the existing saved port if omitted)

When to use:

  • Adding a new server configuration
  • Updating credentials after authentication failure
  • Changing server connection details

🗑️ remove_server(connection_id)

Purpose: Permanently delete a server profile from storage.

When to use:

  • User explicitly requests to remove or forget a server
  • Server is no longer accessible or needed

⚠️ Warning: This action cannot be undone

⚡ execute_command(connection_id, command)

Purpose: Execute non-interactive shell commands remotely and return results.

Returns: stdout, stderr, and exit_code

When to use:

  • Running system commands, scripts, or utilities
  • Checking server status, disk usage, process lists
  • File operations, package management, etc.

When NOT to use:

  • Interactive programs (vim, htop, top)
  • Commands requiring manual input ([Y/n] prompts) - unless using flags like -y

Example: execute_command(connection_id="production", command="df -h")

📤 upload_file(connection_id, local_path, remote_path)

Purpose: Upload files from your local machine to a remote server via SFTP.

Parameters:

  • local_path: Path to the file on your local machine
  • remote_path: Destination path on the remote server

Notes:

  • If remote_path is a directory, the original filename is preserved
  • If local_path is omitted, server selects a default and returns it in response

📥 download_file(connection_id, remote_path, local_path)

Purpose: Download files from a remote server to your local machine via SFTP.

Parameters:

  • remote_path: Path to the file on the remote server
  • local_path: Destination path on your local machine

Notes:

  • If local_path is omitted, defaults to: ~/.config/remoteshell/downloads/<connection_id>/<basename>

🧪 Development

Local Development Setup

For local development, use this MCP configuration:

{
  "mcpServers": {
    "remoteshell": {
      "command": "uv",
      "args": ["--directory", "/absolute/path/to/remoteShell-mcp", "run", "remoteshell-mcp"]
    }
  }
}

Running Tests

uv run pytest

Metadata

Release files for remoteshell-mcp 1.1.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for remoteshell-mcp 1.1.3
File Size Uploaded
remoteshell_mcp-1.1.3.tar.gz 94.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for remoteshell-mcp 1.1.3
File Interpreter ABI Platform
remoteshell_mcp-1.1.3-py3-none-any.whl Python 3 none any Details

Total release size: 112.8 kB

Release files / remoteshell_mcp-1.1.3.tar.gz

Download URL remoteshell_mcp-1.1.3.tar.gz
Size 94.8 kB
Tags Source
SHA-256 checksum
How to use checksums
f6f4e1ccdc8f9a67b8f881244b7ab10aa1ac3dccae7d688b61588c235f225f5c
BLAKE2b-256 checksum
How to use checksums
3c4bff5a394253288b60189787697de807fd20dc9e51b7e7727255a80124ee0d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / remoteshell_mcp-1.1.3-py3-none-any.whl

Download URL remoteshell_mcp-1.1.3-py3-none-any.whl
Size 18.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a8827670cd18b643c164d3ad1a9b0c3e3c497e4fd9afe557e74131bbdd8d1ca8
BLAKE2b-256 checksum
How to use checksums
791ba42a49e27d9324e99842bca90bb4fad35a3546db3d97dc673ede520db890
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release history Release notifications | RSS feed

1.1.4

2 release files

This release

1.1.3 This release

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page