# run_ssh_command_background

A execute tool on the SSH MCP Server MCP server.

Agent View of the PolicyLayer registry record for `run_ssh_command_background`. HTML page: https://policylayer.com/tools/bhayanak-ssh-mcp-server/run-ssh-command-background

## Facts

- Tool: `run_ssh_command_background`
- Server: SSH MCP Server (`bhayanak/ssh-mcp-server`) — https://policylayer.com/tools/bhayanak-ssh-mcp-server.md
- Homepage: https://github.com/bhayanak/ssh-mcp-server
- Risk category: Execute (High risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "run_ssh_command_background",
    "arguments": {}
  }
}
```

## Why run_ssh_command_background is rated High

This tool executes arbitrary shell commands on remote Linux servers via SSH. While the description is empty, the name and context leave no ambiguity—this is a command execution tool. The severity is high because command execution on remote systems can have broad consequences (file modification, data exfiltration, service disruption) depending on the command arguments and server permissions.

From the tool's own definition: "Tool name 'run_ssh_command_background' explicitly indicates execution of SSH commands on remote servers. Server description confirms it 'manage[s] remote Linux servers' and allows users to run commands."

## Use case

AI agents invoke run_ssh_command_background to trigger actions in SSH MCP Server. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches SSH MCP Server:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "run_ssh_command_background": {
      "limits": [
        {
          "counter": "run_ssh_command_background_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on SSH MCP Server (22)

- `cancel_background_job` — Destructive — https://policylayer.com/tools/bhayanak-ssh-mcp-server/cancel-background-job.md
- `remove_ssh_key` — Destructive — https://policylayer.com/tools/bhayanak-ssh-mcp-server/remove-ssh-key.md
- `revoke_cert` — Destructive — https://policylayer.com/tools/bhayanak-ssh-mcp-server/revoke-cert.md
- `sftp_delete` — Destructive — https://policylayer.com/tools/bhayanak-ssh-mcp-server/sftp-delete.md
- `approve_request` — Execute — https://policylayer.com/tools/bhayanak-ssh-mcp-server/approve-request.md
- `request_approval` — Execute — https://policylayer.com/tools/bhayanak-ssh-mcp-server/request-approval.md
- `run_ssh_command` — Execute — https://policylayer.com/tools/bhayanak-ssh-mcp-server/run-ssh-command.md
- `ssh_connect` — Execute — https://policylayer.com/tools/bhayanak-ssh-mcp-server/ssh-connect.md
- `get_audit_logs` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/get-audit-logs.md
- `get_host_facts` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/get-host-facts.md
- `list_background_jobs` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/list-background-jobs.md
- `list_hosts` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/list-hosts.md
- `list_pending_approvals` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/list-pending-approvals.md
- `list_templates` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/list-templates.md
- `poll_background_job` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/poll-background-job.md
- `sftp_list_directory` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/sftp-list-directory.md
- `ssh_list_sessions` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/ssh-list-sessions.md
- `ssh_session_ping` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/ssh-session-ping.md
- `add_ssh_key` — Write — https://policylayer.com/tools/bhayanak-ssh-mcp-server/add-ssh-key.md
- `issue_cert` — Write — https://policylayer.com/tools/bhayanak-ssh-mcp-server/issue-cert.md
- `ssh_disconnect` — Write — https://policylayer.com/tools/bhayanak-ssh-mcp-server/ssh-disconnect.md
- `transfer_file` — Write — https://policylayer.com/tools/bhayanak-ssh-mcp-server/transfer-file.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=bhayanak-ssh-mcp-server · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/bhayanak-ssh-mcp-server
