sshm

module
v0.7.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 9, 2026 License: MIT

README

sshm

A pretty, AI-friendly SSH connection manager.

Single binary on Win/Mac/Linux. Pretty ls with live status. Wizard add. Built-in MCP server for AI assistants (Claude Code, Cursor, Codex, Gemini CLI).

Install

Platform Command
macOS / Linux (Homebrew) brew install michael-ltm/tap/sshm
Windows (Scoop) scoop bucket add michael-ltm https://github.com/michael-ltm/scoop-bucket && scoop install sshm
Anywhere (Go) go install github.com/michael-ltm/sshm/cmd/sshm@latest
Direct download GitHub Releases — tar.gz / zip per OS+arch

Quickstart

sshm pair              # guided: alias, address, platform, description, tags
# Paste the printed one-line command on the target; sshm detects the user and verifies SSH.
sshm add               # choose automatic pairing or advanced manual entry
sshm                   # terminal workspace (when run in a terminal)
sshm list              # searchable inventory + details + safe action menu
sshm ls --plain        # script-friendly server table
sshm c my-host         # interactive shell
sshm exec my-host 'uptime'
sshm test --all        # parallel direct-TCP reachability check
sshm cleanup           # guided review of unused server records
sshm download my-host /tmp/app.zip ./app.zip --resume --sha256 <hash>

Optional encrypted cloud sync (preview)

SSHM Cloud adds accounts, device presence, groups/tags, and a browser console. SSH server metadata, private keys and saved passwords are end-to-end encrypted. Existing local commands and MCP keep using local configuration.

sshm cloud register --username your-name --import-local
# On another device:
sshm cloud login --username your-name --import-local
sshm cloud watch

Use the cloud preview client from the console; the existing stable package does not include these commands. Use sshm update for signed, confirmed updates and sshm integrations install --app all --mcp for optional AI setup. See cloud setup, recovery and limitations.

Features

  • TOML config at ~/.config/sshm/config.toml (XDG) or %APPDATA%\sshm\config.toml (Windows)
  • Interactive list/ls: arrow-key server picker with connect, reachability, pairing/repair, description editing, remote password change, cleanup protection, default selection, and guarded delete. The workspace shows last SSH use and on-demand TCP latency (p); see terminal UI.
  • First-class descriptions, groups, and tags for human browsing and AI intent lookup
  • Plain pair guides you through alias, address, Windows/Linux/macOS platform, with optional custom port, description, tags, and group. Windows guided setup produces a readable script plus a launcher; other targets get a one-time command. It installs or starts OpenSSH when needed, detects the target user, installs a new key, and saves only after a real key-authenticated SSH command succeeds. Windows uses the built-in capability by default, then a pinned/hash-verified official ZIP fallback; setting offline SSHM_OPENSSH_ZIP bypasses the online attempt. See Windows file setup and read-only checks.
  • SSHM-observed successful SSH authentication records last use separately from reachability checks (sessions opened by other clients are not visible). cleanup safely reviews idle records, protects referenced hosts, and creates a private backup (0600 on POSIX, current-user/LocalSystem ACL on Windows) before removing selected config entries
  • add (huh wizard) / edit / rm / show; exact-alias confirmation for destructive removal
  • connect (interactive shell) / exec (one-off) / test (single + --all)
  • status (remote resource snapshot) / init (baseline hardening)
  • gen-key (ed25519) / copy-id (one-shot password, never stored)
  • upload / download (single-file SFTP with .part, resume, SHA-256)
  • mcp — built-in MCP server so AI assistants (Claude Code, Cursor, Codex, Gemini CLI) can manage your servers — including layered SSH checks, intent-based find_servers discovery, background file transfer (transfer_start/transfer_status) and host-key verification (TOFU). See docs/ai-integration.md.
  • --json on supported non-streaming commands for scripting and AI integration
  • --redacted masks secrets, IPs, and sensitive paths before JSON is shared
  • Pretty list with unicode/ascii icons (auto-detected)
  • Proxy/jump-host connections: per-host SOCKS5 (proxy), ProxyJump (proxy_jump), ProxyCommand (proxy_command); SOCKS5 auto-detected from ALL_PROXY/HTTPS_PROXY env vars (zero-config); failed proxy attempts fall back to direct

AI integration

claude plugins marketplace add michael-ltm/sshm
claude plugins install sshm-skill@sshm

Then ask your assistant to "check the status of my prod server" or "deploy the latest code to staging". sshm's MCP tools are audited, mask secrets, and block dangerous commands. See docs/ai-integration.md and docs/security.md.

Roadmap

  • v0.3 ✓ — Host-key TOFU verification (strict known_hosts still v1.0), parallel exec_multi, upload/download single files, exec timeout + detach — shipped
  • v0.4 ✓ — Proxy/VPN-aware dialing: SOCKS5 (proxy), ProxyJump, ProxyCommand; SOCKS5 auto-detected from env; automatic direct fallback — shipped
  • v0.5 ✓ — Secure key provisioning, encrypted key support, large-transfer-safe MCP/CLI file transfer — shipped
  • v0.6 ✓ — Deterministic project profiles, safe project-scoped execution, cross-platform detached logs, token-efficient AI skill — shipped
  • v0.7 ✓ — Interactive inventory manager, server descriptions, ranked AI host discovery, guarded password/removal workflows, remote reverse-lab guidance — shipped
  • v0.8 — One-line cross-platform pairing, responsive inventory picker, import/export ~/.ssh/config, tag/group filtering
  • v1.0 — Port forwarding, SFTP browse, signed release artifacts, strict known_hosts enforcement

See docs/specs/2026-05-13-sshm-design.md for the full design.

Release Process (maintainers)

Releases are automated by GoReleaser on tag push:

git tag v0.1.0 && git push origin v0.1.0

Required repo secrets: HOMEBREW_TAP_TOKEN, SCOOP_BUCKET_TOKEN — PATs with contents:write on homebrew-tap and scoop-bucket.

License

MIT — see LICENSE.

Directories

Path Synopsis
cmd
sshm command
internal
bootstrap
Package bootstrap runs an embedded baseline-hardening script on a remote server: it installs jq/curl/fail2ban, enables fail2ban, and reports the sshd auth configuration.
Package bootstrap runs an embedded baseline-hardening script on a remote server: it installs jq/curl/fail2ban, enables fail2ban, and reports the sshd auth configuration.
cleanup
Package cleanup classifies inventory entries for safe, human-reviewed cleanup.
Package cleanup classifies inventory entries for safe, human-reviewed cleanup.
cloudagent
Package cloudagent runs an explicitly enabled outbound encrypted terminal.
Package cloudagent runs an explicitly enabled outbound encrypted terminal.
cloudsync
Package cloudsync implements a client-encrypted, opt-in SSHM vault.
Package cloudsync implements a client-encrypted, opt-in SSHM vault.
commands
Package commands wires every CLI subcommand to the cobra root.
Package commands wires every CLI subcommand to the cobra root.
config
Package config holds the persistent configuration model for sshm.
Package config holds the persistent configuration model for sshm.
desktopsession
Package desktopsession runs opt-in commands in the same macOS user's GUI login session.
Package desktopsession runs opt-in commands in the same macOS user's GUI login session.
inventory
Package inventory collects bounded, read-only hardware observations.
Package inventory collects bounded, read-only hardware observations.
keys
Package keys manages SSH keypair generation and remote installation.
Package keys manages SSH keypair generation and remote installation.
mcp
Package mcp exposes sshm's functionality as Model Context Protocol tools over stdio so AI assistants can manage servers.
Package mcp exposes sshm's functionality as Model Context Protocol tools over stdio so AI assistants can manage servers.
pair
Package pair implements one-time, local-network SSH enrollment.
Package pair implements one-time, local-network SSH enrollment.
safety
Package safety gates dangerous remote commands, masks sensitive data in output, and records an audit trail.
Package safety gates dangerous remote commands, masks sensitive data in output, and records an audit trail.
ssh
Package ssh wraps golang.org/x/crypto/ssh with sshm-specific construction helpers and a small Client that owns one connection.
Package ssh wraps golang.org/x/crypto/ssh with sshm-specific construction helpers and a small Client that owns one connection.
status
Package status provides cheap reachability probes for the server list.
Package status provides cheap reachability probes for the server list.
ui
Package ui holds rendering primitives — icons, color styles, and table formatting — used by CLI commands.
Package ui holds rendering primitives — icons, color styles, and table formatting — used by CLI commands.
updater
Package updater authenticates releases before replacing a standalone binary.
Package updater authenticates releases before replacing a standalone binary.
wizard
Package wizard implements interactive forms for sshm add/edit.
Package wizard implements interactive forms for sshm add/edit.
plugins
sshm-skill
Package sshmassets bundles the same skill documents shipped by the plugin.
Package sshmassets bundles the same skill documents shipped by the plugin.
scripts
sign-cloud-release command
Sign only locally built artifacts; private key bytes never reach stdout.
Sign only locally built artifacts; private key bytes never reach stdout.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL