← All Projects
Published

VSSH: Guarded SSH for Scripts and AI Agents

VSSH runs remote commands through native OpenSSH and adds what scripts and AI agents need: preflight guardrails, one-object JSON results, one-step file transfer and a privacy-safe audit trail.

Impact

  • Open source on npm as @light-merlin-dark/vssh, MIT licensed, released through npm trusted publishing with SLSA provenance. Documentation at vssh.io
  • Rebuilt as VSSH 2 in July 2026 around the native ssh and scp executables; the VSSH 1 MCP server, plugin runtime and credential store were removed to shrink the security surface
  • In daily use as the remote-operations path for the author's AI agents on production infrastructure
  • Install in one line: npm install -g @light-merlin-dark/vssh, then vssh --setup and vssh doctor

Key Features

  • Native transport: the same OpenSSH authentication, host verification, known_hosts and ssh-agent behavior, with no VSSH-specific remote language
  • Preflight guardrails: recognizable root deletion, raw disk writes, destructive volume cleanup, firewall flushes and shutdowns are blocked before connecting
  • Structured results: --json returns one bounded object with stdout, stderr, exit code, duration and timeout state
  • Transfer with permissions: upload --mode 600 copies a file and sets its mode as one reported operation
  • Diagnosis: vssh doctor checks binaries, configuration, identity and a real connection
  • Privacy-safe audit: owner-only outcome metadata and a command hash, never command text, output or credentials
  • Agent discovery: commands --json exposes a versioned, machine-readable command contract
Continue reading
*
^
|
*
^
|
^
*
|
^
*
^
|
*
^
|
^
*
|
^
. . .

AI Systems Architect and Top 5% Technology Consultant with 25+ years of experience building innovative software solutions.

You're welcome to contact me if you would like.

Engage
© 2026 Robert E. Beckner III. All rights reserved.