Surfaced while click-testing #102 on a multi-Claude-config setup.
The edge
ssh-mcp's sidecar is a single machine-global file (~/Library/Application Support/ssh-mcp/config.toml on macOS, %APPDATA%\ssh-mcp\config.toml, else ${XDG_CONFIG_HOME:-~/.config}/ssh-mcp/config.toml). Every ssh-mcp instance on the machine reads it — across every Claude config (Desktop, Code, each project .mcp.json). And because ssh-mcp ignores CLI args entirely once that file exists, creating a sidecar for one server silently flips every other ssh-mcp server on the machine to reading it — potentially breaking servers configured elsewhere. The #102 editor currently makes that global-side-effect file easy to create with no warning that it's global.
ssh-mcp's own separation mechanism is named profiles inside that one file (the [profile.x]-shaped sections the #11 credential-scoping check already inspects; each server selects a profile via an arg/env selector). So configs can be kept distinct — as profiles in one shared file, not file-per-config. BCC treats the file as flat today.
Two parts
Safety — warn it's machine-global. Before create/edit in the sidecar editor (and ideally in the #91 advisory), state plainly: "This file is shared by every ssh-mcp server on this machine, across all your Claude configs. Editing it affects all of them." This is the higher-priority half.
Scope to the profile. Detect which profile a given server targets (confirm the exact ssh-mcp selector — --profile/env — from the package source first) and scope both the advisory and the editor to that profile's section, instead of the whole file. Ties into the existing section picker (#102) and the #11 multi-profile check.
Notes
Not a correctness bug in #91/#102 — the "args inert when the file exists" advisory is true regardless of profile (ssh-mcp falls back to args only when the file is absent). This is about clarity + safety on a shared resource.
Research task embedded: confirm the per-server profile-selection mechanism from ssh-mcp before building part 2.
Part of epic #94. P1 for part 1 (safety), part 2 is an enhancement.
Surfaced while click-testing #102 on a multi-Claude-config setup.
## The edge
`ssh-mcp`'s sidecar is a **single machine-global file** (`~/Library/Application Support/ssh-mcp/config.toml` on macOS, `%APPDATA%\ssh-mcp\config.toml`, else `${XDG_CONFIG_HOME:-~/.config}/ssh-mcp/config.toml`). **Every** ssh-mcp instance on the machine reads it — across *every* Claude config (Desktop, Code, each project `.mcp.json`). And because ssh-mcp ignores CLI args entirely once that file exists, **creating a sidecar for one server silently flips every other ssh-mcp server on the machine to reading it** — potentially breaking servers configured elsewhere. The #102 editor currently makes that global-side-effect file easy to create with **no warning that it's global**.
ssh-mcp's own separation mechanism is **named profiles inside that one file** (the `[profile.x]`-shaped sections the #11 credential-scoping check already inspects; each server selects a profile via an arg/env selector). So configs *can* be kept distinct — as profiles in one shared file, not file-per-config. BCC treats the file as flat today.
## Two parts
1. **Safety — warn it's machine-global.** Before create/edit in the sidecar editor (and ideally in the #91 advisory), state plainly: *"This file is shared by every ssh-mcp server on this machine, across all your Claude configs. Editing it affects all of them."* This is the higher-priority half.
2. **Scope to the profile.** Detect which profile a given server targets (confirm the exact ssh-mcp selector — `--profile`/env — from the package source first) and scope both the advisory and the editor to *that* profile's section, instead of the whole file. Ties into the existing section picker (#102) and the #11 multi-profile check.
## Notes
- Not a correctness bug in #91/#102 — the "args inert when the file exists" advisory is true regardless of profile (ssh-mcp falls back to args only when the file is *absent*). This is about clarity + safety on a shared resource.
- Research task embedded: confirm the per-server profile-selection mechanism from ssh-mcp before building part 2.
Part of epic #94. P1 for part 1 (safety), part 2 is an enhancement.
the_og
added the P1 label 2026-08-13 00:55:43 -04:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Surfaced while click-testing #102 on a multi-Claude-config setup.
The edge
ssh-mcp's sidecar is a single machine-global file (~/Library/Application Support/ssh-mcp/config.tomlon macOS,%APPDATA%\ssh-mcp\config.toml, else${XDG_CONFIG_HOME:-~/.config}/ssh-mcp/config.toml). Every ssh-mcp instance on the machine reads it — across every Claude config (Desktop, Code, each project.mcp.json). And because ssh-mcp ignores CLI args entirely once that file exists, creating a sidecar for one server silently flips every other ssh-mcp server on the machine to reading it — potentially breaking servers configured elsewhere. The #102 editor currently makes that global-side-effect file easy to create with no warning that it's global.ssh-mcp's own separation mechanism is named profiles inside that one file (the
[profile.x]-shaped sections the #11 credential-scoping check already inspects; each server selects a profile via an arg/env selector). So configs can be kept distinct — as profiles in one shared file, not file-per-config. BCC treats the file as flat today.Two parts
--profile/env — from the package source first) and scope both the advisory and the editor to that profile's section, instead of the whole file. Ties into the existing section picker (#102) and the #11 multi-profile check.Notes
Part of epic #94. P1 for part 1 (safety), part 2 is an enhancement.