Lightweight SSH toolkit with optional MCP(stdio) JSON-RPC adapter
Project description
SSHOC
English | 简体中文
A lightweight, config-driven SSH toolkit (CLI + optional MCP stdio adapter). Configure multiple servers in json, then use:
- CLI prefix command:
sshoc <profile>: <command...>(quickly run remote commands) - MCP (stdio) server: Exposes
tools/list/tools/callso MCP clients can callssh.run/ssh.upload/ssh.download
Dependency:
paramiko(SSH/SFTP).
Quick start (pip users)
- Install:
python -m pip install -U sshoc
- Initialize config (write to the per-user config directory, recommended):
# Password auth (recommended: store password in an env var)
sshoc init demo --ssh "ssh -p 22 user@host" --password-env SSHOC_DEMO_PASSWORD
# Or: key auth
sshoc init demo --ssh "ssh -p 22 user@host" --key-path ~/.ssh/id_ed25519
- Set the password environment variable (only needed for
password_env):
$env:SSHOC_DEMO_PASSWORD="your_password"
export SSHOC_DEMO_PASSWORD="your_password"
- Use:
sshoc list
sshoc demo: uname -a
Installation
Option A: Install from PyPI (recommended)
python -m pip install -U sshoc
Option B: Install from source (development)
Recommended: create a virtual environment in this directory (or use your preferred workflow):
cd "SSH_Operation_Component (MCP)"
python -m venv .venv
.venv\\Scripts\\activate
python -m pip install -U pip
python -m pip install -e .
Configuration
1) Generate config (sshoc init)
# Write to the per-user config directory (recommended)
sshoc init
# Or write to ./sshoc.config.json in the current directory
sshoc init --local
# Or write to an arbitrary path
sshoc init --output /path/to/sshoc.config.json
Notes:
sshoc init(without<profile>) writes the full template (including the demo profile).sshoc init <profile> --ssh ... --password-env/--password/--key-path ...writes a single-profile config (better for a quick start with pip).
2) Where is the config file (and which one is currently in use)?
Use this command to see which config file is being used:
sshoc config path
It prints:
path: config file pathsource: where it comes from (cli|env|cwd|user|package)exists: whether the path exists
Default per-user config locations:
- Windows:
%APPDATA%\\sshoc\\sshoc.config.json - macOS:
~/Library/Application Support/sshoc/sshoc.config.json - Linux:
~/.config/sshoc/sshoc.config.json(or$XDG_CONFIG_HOME/sshoc/sshoc.config.json)
3) Practical tip: pin the config path with SSHOC_CONFIG
If you want the same config to be used no matter which directory you run from, set SSHOC_CONFIG:
$env:SSHOC_CONFIG="C:\\path\\to\\sshoc.config.json"
export SSHOC_CONFIG="/path/to/sshoc.config.json"
4) (Optional) Repo development: copy the template file
If you're developing in this repo, you can also copy the template to sshoc.config.json (it includes $schema pointing to sshoc.config.schema.json for IDE hints; the parser also allows this field):
# macOS / Linux
cp sshoc.config.template.json sshoc.config.json
# Windows PowerShell / CMD
copy sshoc.config.template.json sshoc.config.json
# Or:
Copy-Item sshoc.config.template.json sshoc.config.json
Then set the password (recommended: use env vars and avoid committing plaintext passwords):
$env:SSHOC_DEMO_PASSWORD="your_password"
Key config fields
servers.<profile>: your profile name (recommended:a-zA-Z0-9_-)servers.<profile>.ssh_command: supports common forms likessh -p <port> user@host(for advanced ssh options, prefer explicit fields / feature extensions)auth.type:password: supportspasswordorpassword_envkey: supportsprivate_key_path(optionalprivate_key_passphrase_env)
known_hosts_policy:strict: default; unknown host keys fail fast (safer)accept_new: on first connect, automatically writes toknown_hosts_path
default_shell: optional; commonlybash -lc(closer to an interactive environment). Set tonullif the remote has no bash
CLI usage (prefix command)
List all configured profiles:
sshoc list
Profile management (edit the config file)
These commands modify the currently effective config file in place. Use
sshoc config pathto confirm the path first, or specify it explicitly with--config <path>.
# Remove a profile
sshoc profile remove demo
# Clear all profiles (set `servers` to an empty object)
sshoc profile clear
Run a remote command (recommended prefix form):
sshoc demo: uname -a
sshoc demo: "ls -la /root"
Explicit subcommands (easier to parameterize):
sshoc run demo --cmd "python -V"
sshoc upload demo --local ./local.txt --remote /tmp/local.txt --overwrite
sshoc download demo --remote /tmp/local.txt --local ./downloaded.txt --overwrite
Default config resolution order:
--config <path>- Environment variable
SSHOC_CONFIG - Current directory
./sshoc.config.json - Per-user config directory (Windows:
%APPDATA%\\sshoc\\sshoc.config.json; Linux:~/.config/sshoc/sshoc.config.json) sshoc.config.jsoninside the package/source directory (dev fallback)
MCP (stdio) server usage
Start:
sshoc-mcp
It communicates over stdin/stdout using line-delimited JSON (JSON-RPC), matching MCP's common stdio transport pattern.
Tools provided:
ssh.list_profilesssh.runssh.uploadssh.download
Generic stdio config blueprint (for MCP clients)
Different MCP clients may use different config file formats, but the essentials are usually: command / args / env / cwd. Below is a generic blueprint (field names are for reference—adapt to your client):
{
"mcpServers": {
"sshoc": {
"command": "sshoc-mcp",
"args": ["--config", "<ABS_CONFIG_PATH>"],
"env": {
"SSHOC_DEMO_PASSWORD": "your_password",
"SSHOC_DEBUG": "0"
},
"cwd": "<OPTIONAL_WORKDIR>"
}
}
}
// Examples for <ABS_CONFIG_PATH>:
// - macOS/Linux: /path/to/sshoc.config.json
// - Windows: C:\\path\\to\\sshoc.config.json
Two common variants (choose what fits your client):
- If your client can't easily pass
args: pin the config path viaSSHOC_CONFIG(and still inject the password env var required bypassword_envviaenv). - If
sshoc-mcpis not onPATH: start it via your venv withpython -m sshoc.mcp_server --config <ABS_CONFIG_PATH>.
Security notes (strongly recommended)
- Never commit plaintext server passwords. Prefer
password_env. - This tool effectively gives AI a remote execution entry point—use it only in environments you trust.
License
Apache-2.0 (see LICENSE).
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file sshoc-0.1.1.tar.gz.
File metadata
- Download URL: sshoc-0.1.1.tar.gz
- Upload date:
- Size: 25.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.8
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5946f9255d5fca4db4fba49dc98376afe028e1a9e7d23053102aa68ae479b94c
|
|
| MD5 |
bf43c0e0a0c6de7c1b70b3bc81061eb3
|
|
| BLAKE2b-256 |
104f8a6d9f1716fad2f92b398ecb27746ab299699394e27ca7ef3f5c8018f1e7
|
File details
Details for the file sshoc-0.1.1-py3-none-any.whl.
File metadata
- Download URL: sshoc-0.1.1-py3-none-any.whl
- Upload date:
- Size: 26.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.8
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b9801bcc5966a18d70ae0620031466aba7adddc0a2b6106f2adf8074daa13f7b
|
|
| MD5 |
b5fb3ac4114a10ba63440590ad1b19ec
|
|
| BLAKE2b-256 |
cc024b1c090caf93dece677c94e26dc5a8a8cb2145fee826d2242cd2faf64b3c
|