Sidecar is machine-global: warn before create/edit, and scope advisory + editor to the server's profile #106

Open
opened 2026-08-13 00:55:43 -04:00 by the_og · 0 comments
Owner

Surfaced while click-testing #102 on a multi-Claude-config setup.

The edge

ssh-mcp's sidecar is a single machine-global file (~/Library/Application Support/ssh-mcp/config.toml on macOS, %APPDATA%\ssh-mcp\config.toml, else ${XDG_CONFIG_HOME:-~/.config}/ssh-mcp/config.toml). Every ssh-mcp instance on the machine reads it — across every Claude config (Desktop, Code, each project .mcp.json). And because ssh-mcp ignores CLI args entirely once that file exists, creating a sidecar for one server silently flips every other ssh-mcp server on the machine to reading it — potentially breaking servers configured elsewhere. The #102 editor currently makes that global-side-effect file easy to create with no warning that it's global.

ssh-mcp's own separation mechanism is named profiles inside that one file (the [profile.x]-shaped sections the #11 credential-scoping check already inspects; each server selects a profile via an arg/env selector). So configs can be kept distinct — as profiles in one shared file, not file-per-config. BCC treats the file as flat today.

Two parts

  1. Safety — warn it's machine-global. Before create/edit in the sidecar editor (and ideally in the #91 advisory), state plainly: "This file is shared by every ssh-mcp server on this machine, across all your Claude configs. Editing it affects all of them." This is the higher-priority half.
  2. Scope to the profile. Detect which profile a given server targets (confirm the exact ssh-mcp selector — --profile/env — from the package source first) and scope both the advisory and the editor to that profile's section, instead of the whole file. Ties into the existing section picker (#102) and the #11 multi-profile check.

Notes

  • Not a correctness bug in #91/#102 — the "args inert when the file exists" advisory is true regardless of profile (ssh-mcp falls back to args only when the file is absent). This is about clarity + safety on a shared resource.
  • Research task embedded: confirm the per-server profile-selection mechanism from ssh-mcp before building part 2.

Part of epic #94. P1 for part 1 (safety), part 2 is an enhancement.

Surfaced while click-testing #102 on a multi-Claude-config setup. ## The edge `ssh-mcp`'s sidecar is a **single machine-global file** (`~/Library/Application Support/ssh-mcp/config.toml` on macOS, `%APPDATA%\ssh-mcp\config.toml`, else `${XDG_CONFIG_HOME:-~/.config}/ssh-mcp/config.toml`). **Every** ssh-mcp instance on the machine reads it — across *every* Claude config (Desktop, Code, each project `.mcp.json`). And because ssh-mcp ignores CLI args entirely once that file exists, **creating a sidecar for one server silently flips every other ssh-mcp server on the machine to reading it** — potentially breaking servers configured elsewhere. The #102 editor currently makes that global-side-effect file easy to create with **no warning that it's global**. ssh-mcp's own separation mechanism is **named profiles inside that one file** (the `[profile.x]`-shaped sections the #11 credential-scoping check already inspects; each server selects a profile via an arg/env selector). So configs *can* be kept distinct — as profiles in one shared file, not file-per-config. BCC treats the file as flat today. ## Two parts 1. **Safety — warn it's machine-global.** Before create/edit in the sidecar editor (and ideally in the #91 advisory), state plainly: *"This file is shared by every ssh-mcp server on this machine, across all your Claude configs. Editing it affects all of them."* This is the higher-priority half. 2. **Scope to the profile.** Detect which profile a given server targets (confirm the exact ssh-mcp selector — `--profile`/env — from the package source first) and scope both the advisory and the editor to *that* profile's section, instead of the whole file. Ties into the existing section picker (#102) and the #11 multi-profile check. ## Notes - Not a correctness bug in #91/#102 — the "args inert when the file exists" advisory is true regardless of profile (ssh-mcp falls back to args only when the file is *absent*). This is about clarity + safety on a shared resource. - Research task embedded: confirm the per-server profile-selection mechanism from ssh-mcp before building part 2. Part of epic #94. P1 for part 1 (safety), part 2 is an enhancement.
the_og added the P1 label 2026-08-13 00:55:43 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: the_og/better-claude-config#106