mcp-ssh-tmux AGENTS.md

A project instruction file that gives coding agents background about the mcp-ssh-tmux project, its code, infrastructure, and design choices.

In plain words
What is it for?
Understanding the project structure, operating its development tools, and avoiding known issues such as blocking an asynchronous server while waiting.
Why use it?
It preserves knowledge between agents and tasks, so future work can follow existing decisions and avoid repeating investigations.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/devnullvoid/mcp-ssh-tmux/agents-md
Clone the repo
git clone --depth 1 https://github.com/devnullvoid/mcp-ssh-tmux

Made for: Codex, OpenCode.

Per session 1,489 This file is loaded in full into every session.
When invoked 1,489 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01489 $0.01489
Opus 5 $0.00745 $0.00745
Sonnet 5 $0.00298 $0.00298
Haiku 4.5 $0.00149 $0.00149

Measured yesterday against content hash 1e23d419040e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

mcp-ssh-tmux AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 82 lines

How it starts

The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agent Continuity Guide

Source Reference

  • Reference Project: mcp-ssh-session
  • Absolute Path: /home/jon/Dev/ai/mcp/mcp-ssh-session
  • Status: Pivot complete. Logic ported and improved.

Current Infrastructure

  • Environment: uv (Python 3.14+)
  • Command Runner: just (see Justfile)
  • Core Library: libtmux (v0.30+ API used)
  • Logic: mcp_ssh_tmux/session_manager.py and server.py.

Technical Insights for Future Agents

Philosophy: LLM-as-Observer

  • The server provides raw visual snapshots. The AI agent is responsible for interpreting state (prompts, errors, etc.).
  • Hints: server.py appends [INFO: ...] hints to snapshots when common shell prompts or password requests are detected.

Async Polling (Critical)

  • send_command and read_file MUST use await asyncio.sleep(), never time.sleep(). The MCP server runs on an async event loop (FastMCP/uvicorn). Synchronous sleep blocks the entire event loop, making the server unresponsive to all other requests during the polling period. This was the root cause of a production bug where send_command with large timeouts (e.g., 60s for docker service update) killed the server's ability to handle concurrent get_snapshot or list_sessions calls.

Key Dispatch

  • send_keys (literal mode) uses pane.cmd("send-keys", *keys.split()) to pass each token as a separate tmux argument. This lets tmux interpret key names (Enter, C-c, Tab) while still sending unrecognized tokens as literal text.
  • Do NOT use libtmux's literal=True — it passes -l to tmux, which disables all key name interpretation (e.g., "yes Enter" would type the word "Enter").

Connection Management

  • SSH Execution: We start ssh directly as the window_shell command in tmux. This is more reliable than starting a shell and sending keys.
  • Config Resolution: We use ssh -G <host> to resolve aliases and identity files from the user's ~/.ssh/config.
  • Interactive Sessions: We intentionally avoid BatchMode=yes for the primary tmux-backed SSH session so the AI can handle interactive password/passphrase prompts visually.
  • Direct File Reads: read_remote_file first attempts a separate non-interactive ssh -o BatchMode=yes ... cat -- <path> using the resolved host/user/port/key info. If that fails, it falls back to bounded tmux history capture.
  • Persistence: remain-on-exit is enabled via window.set_option("remain-on-exit", "on"). This allows capturing final errors after a connection dies.

Read the full file on GitHub · 82 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 82 lines · 1,489 tokens per session scan A 1e23d419040e

Subscribe to this mod's changes

mcp-ssh-tmux AGENTS.md is an instructions file published in the GitHub repository devnullvoid/mcp-ssh-tmux (6 stars, last pushed 2mo ago), licensed MIT. It adds 1,489 tokens to every session, about $0.0074 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.