Lightweight SSH toolkit with optional MCP(stdio) JSON-RPC adapter
Project description
SSHOC
English | 简体中文
A lightweight, config-driven SSH toolkit (CLI + optional MCP stdio adapter).
- CLI:
sshoc(list/run/upload/download/hostkey/..., plus prefix modesshoc <profile>: <command...>) - MCP (stdio):
sshoc-mcp(line-delimited JSON-RPC, exposesssh.*tools to MCP clients) - Dependency:
paramiko(SSH/SFTP)
Goal: strict, predictable, easy to embed (especially for automation / AI workflows).
Quick start (pip users)
- Install:
python -m pip install -U sshoc
Windows note: if
sshocis still “not recognized” after install, your Python scripts directory (wheresshoc.exeis generated) is likely not onPATH. Print the scripts directory and add it toPATH, then reopen your terminal:python -c "import sysconfig; print(sysconfig.get_path('scripts'))"
- Initialize config (recommended: per-user config directory):
# Password auth (recommended: store password in an env var)
sshoc init demo --ssh "ssh -p 22 user@host" --password-env SSHOC_DEMO_PASSWORD
# Or: key auth
sshoc init demo --ssh "ssh -p 22 user@host" --key-path ~/.ssh/id_ed25519
- Set the password env var (only needed for
password_env):
$env:SSHOC_DEMO_PASSWORD="your_password"
export SSHOC_DEMO_PASSWORD="your_password"
- First connection (known_hosts):
Default known_hosts_policy=strict. If the host key is not present in your local known_hosts, the first connection will fail. Recommended: write the host key first (optionally verify a trusted fingerprint):
sshoc hostkey ensure demo
# Strongly recommended (if you can get a trusted fingerprint from your provider/admin):
# sshoc hostkey ensure demo --expected-fingerprint "SHA256:..."
- Run a command:
sshoc demo: uname -a
# Or
sshoc run demo --cmd "uname -a"
Installation (development)
Install from source (recommended: create a venv in this directory):
cd "SSH_Operation_Component (MCP)"
python -m venv .venv
.venv\\Scripts\\activate
python -m pip install -U pip
python -m pip install -e .
Configuration
Where is the config file (and which one is in use)?
sshoc config path
Practical tip: pin the config path with SSHOC_CONFIG
$env:SSHOC_CONFIG="C:\\path\\to\\sshoc.config.json"
export SSHOC_CONFIG="/path/to/sshoc.config.json"
Key fields (cheatsheet)
servers.<profile>: profile name (recommended:A-Za-z0-9_-)servers.<profile>.ssh_command: common formssh -p <port> user@hostauth.type:password:passwordorpassword_envkey:private_key_path(optionalprivate_key_passphrase_env)
known_hosts_policy:strict: default; unknown host keys fail fast (safer)accept_new: auto-write toknown_hosts_pathon first connect (TOFU)
known_hosts_path: OpenSSHknown_hostspath (template default:~/.ssh/known_hosts)default_shell: defaultbash -lc(set tonullif the remote has no bash)
CLI
Common commands
sshoc list
sshoc demo: "ls -la /root"
sshoc run demo --cmd "python -V"
sshoc upload demo --local ./local.txt --remote /tmp/local.txt --overwrite
sshoc download demo --remote /tmp/local.txt --local ./downloaded.txt --overwrite
Host key / known_hosts
These commands print JSON (friendly for scripts/CI/automation).
# Scan the remote host key (no auth)
sshoc hostkey scan demo
# Check whether the host is present in known_hosts
sshoc hostkey is-known demo
# Scan + write into known_hosts (optional fingerprint verification)
sshoc hostkey ensure demo
sshoc hostkey ensure demo --expected-fingerprint "SHA256:..."
# Manually add a key (if you already have key_type + base64)
sshoc hostkey add demo --key-type ssh-ed25519 --public-key-base64 "<BASE64>"
# Precise removal: remove one key type, or remove all key types for the host
sshoc hostkey remove demo --key-type ssh-ed25519
sshoc hostkey remove demo --all-types
MCP (stdio) server
Start:
sshoc-mcp
Tools:
ssh.init_config— createsshoc.config.json(call this first if no config exists; the AI can self-configure)ssh.list_profilesssh.scan_host_keyssh.is_known_hostssh.add_known_hostssh.ensure_known_hostssh.runssh.uploadssh.download
Zero-config startup:
sshoc-mcpstarts even without a config file. Tools that need a config will return aCONFIG_NOT_FOUNDerror with a suggestion to callssh.init_config. This lets MCP clients (e.g. AI assistants) discover the tools first, then create the config on demand.
Generic stdio config blueprint (for MCP clients)
Different MCP clients may use different config formats, but the essentials are usually: command / args / env / cwd. Below is a generic blueprint (field names are for reference—adapt to your client):
{
"mcpServers": {
"sshoc": {
"command": "sshoc-mcp",
// args/env are optional; the AI can call ssh.init_config to create the config.
// If you prefer to pin a config file, use:
// "args": ["--config", "<ABS_CONFIG_PATH>"],
"env": {
"SSHOC_DEMO_PASSWORD": "your_password",
"SSHOC_DEBUG": "0"
}
}
}
}
Security notes (strongly recommended)
- Never commit plaintext passwords; prefer
password_env accept_newis TOFU (trust on first use); safer: verify with--expected-fingerprint- This tool effectively gives automation/AI a remote execution entry point—use it only in environments you trust
License
Apache-2.0 (see LICENSE)
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file sshoc-0.1.6.tar.gz.
File metadata
- Download URL: sshoc-0.1.6.tar.gz
- Upload date:
- Size: 37.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.11
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
53964bdeb090f32ec893288dac94679569da81cafa0226c11bb22f7b3d28b584
|
|
| MD5 |
6bf9e210cbc0b436cbc8d5ce7945b33b
|
|
| BLAKE2b-256 |
4917204215a7e4f5d16421387467d5ba50484b2e2018f1c20cff19365e10399e
|
File details
Details for the file sshoc-0.1.6-py3-none-any.whl.
File metadata
- Download URL: sshoc-0.1.6-py3-none-any.whl
- Upload date:
- Size: 37.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.11
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5a3fd0f7d7ce16fc1ccf4d3c5452042c284f16a0ce389216175b1610ef1858b3
|
|
| MD5 |
d86796c77d6d8e703170ec12d8a218de
|
|
| BLAKE2b-256 |
735eb60083530c1e1fd1cf760e0c25ea065b025154931d6ba6c02097345fee58
|