Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Chapter 9 of 12

    Automation — Scripts, MCP & AI Assistant

    Three ways MangoSSH runs things for you (or lets something else run things through it): saved Scripts against one or many hosts, an MCP server that lets external AI tools (Claude Desktop, Cursor) drive your SSH hosts under a policy gate, and an in-app AI Assistant that reads a terminal's recent output to help diagnose problems — with nothing ever sent anywhere without your explicit approval.

    Running a Script on One or Many Hosts

    A script body in the in-place editor. Ctrl+S saves; the shell and line count are shown above.

    Purpose

    Save a reusable multi-line command sequence once, and run it against a single connected host or a whole set of hosts, with hard timeouts so a hung command doesn't block your queue forever.

    How to do it

    1. Toolbar → Scripts dropdown → Run Scripts , then + New .
    2. Fill in a Script name , Description , and the command body (multi-line shell commands).
    3. Set a Wall timeout (hard deadline regardless of activity) and optionally an Idle timeout (kills the run after this long with no new output — off by default).
    4. Add Tags for organization, and optional attachments (files staged alongside the run — click Empty attachment placeholder, name it, then Edit to type content directly with no upload step).
    5. Click Run now , then pick one or more target hosts from the "Run on hosts" picker.

    How to verify

    1. Run a trivial script (e.g. echo test ) against a single connected host and confirm its output appears attributed to that host.
    2. Run the same script against two hosts at once and confirm output from each is kept separate, not interleaved into one stream.
    3. Deliberately set a short Wall timeout and run a script that sleeps longer than it, then confirm it's actually killed at the deadline rather than running indefinitely.

    Troubleshooting

    • Script finishes locally on one host but never returns on another — check Monitor Script Runs (Scripts dropdown) for that specific run's status; a still-running entry there means it's genuinely still executing (or waiting on the Idle timeout), not stuck silently.
    • Attachment content doesn't appear on the target — attachments stage alongside the run; reference their filename directly in the script body, they aren't auto-injected into the shell's working directory unless your script body does that itself.

    Scheduling & Sharing Scripts

    Saved scripts. Hosts are remembered for scheduled runs; a script run by hand asks for its hosts each time, so that column shows where it last ran.

    Purpose

    Run a script automatically on a recurring interval or at a specific future time, and share a working script with your team instead of re-writing it per person.

    How to do it

    1. On a saved script's Mode field: Off (manual only, the default), Every N minutes (set the interval), or Once at a specific time (pick a date/time).
    2. Import/Export (top of the Scripts view): move scripts between machines/profiles as files, beyond plain JSON.
    3. Share to Team (visible once Team Vault is set up): publishes the script to the team's shared list; Update shared pushes your edits back; Copy to local forks a team script into your own private copy.

    How to verify

    1. Set a short interval schedule on a harmless test script and confirm it actually fires automatically without you clicking Run.
    2. Share a script to the team, confirm it appears for a teammate, and confirm editing your own copy doesn't silently change theirs until you explicitly Update shared.

    Troubleshooting

    • Scheduled run never fires — scheduling requires MangoSSH to actually be running at the scheduled time; it isn't a background service that runs while the app is closed.
    • Team members see stale script content — remember Update shared is a deliberate action, not automatic; local edits stay local until you push them.

    MCP Server (External AI Tool Integration)

    Purpose

    • Let an external AI assistant you already use — Claude Desktop, Cursor, or any other MCP-compatible client — list your saved hosts and run commands over SSH on your behalf, through a small, explicit policy gate rather than unrestricted shell access.
    • This is the reverse direction from the in-app AI Assistant below: MCP lets an external AI tool drive MangoSSH; the AI Assistant lets MangoSSH itself call out to an AI provider from inside a terminal session.

    How to do it

    1. Launch MangoSSH once with mangossh --mcp — this starts the MCP server speaking JSON-RPC 2.0 over stdio instead of opening the normal window.
    2. In your AI tool's MCP config (e.g. Claude Desktop's claude_desktop_config.json ), add an mcpServers entry pointing at the MangoSSH executable with --mcp as its argument.
    3. Restart the AI tool; it now has four tools available: ssh_list_hosts , ssh_run , ssh_run_on_group , and ssh_ping .

    How to verify

    1. Ask the AI tool to list your MangoSSH hosts and confirm the names it returns match your real saved list.
    2. Ask it to run a harmless read-only command (e.g. uptime ) on one host and confirm the output it shows you matches what you'd see connecting directly.
    3. Ask it to run something on the policy denylist (a destructive pattern) and confirm it's refused rather than executed.

    Troubleshooting

    • AI tool doesn't see the mangossh MCP server at all — this is standard MCP-client config troubleshooting: confirm the config file path and JSON syntax are exactly right for that specific AI tool, and that you restarted it after editing the config.
    • A command gets refused unexpectedly — the policy gate blocks by substring match against a small denylist of destructive patterns; if a legitimate command trips it, that's a deliberate, conservative default, not a bug to route around.

    AI Assistant (In-App Terminal Diagnosis)

    Purpose

    • Ask an AI model to help diagnose a problem using a session's own recent terminal output — entirely manual invoke, nothing read or sent anywhere until you explicitly approve it.
    • redact approve You type your question Redaction preview you approve before anything sends AI provider Anthropic / Groq / etc. Likely secrets (passwords, keys, tokens) are redacted from the terminal text automatically, before you even see the preview — not just before sending.

    How to do it

    1. Configure a provider first: Settings → AI Assistant — pick any OpenAI-compatible provider (Groq, Cloudflare Workers AI, OpenRouter, Ollama for a fully local/free option, or a custom endpoint) or Anthropic directly, and add that provider's API key (skipped entirely for Ollama, which needs no key).
    2. In an open SSH session, click the toolbar button labeled " n Ask AI" and type an optional question (or leave it blank to just ask for a general diagnosis of recent output).
    3. A modal titled "Send to AI model?" appears, showing the exact terminal text that will be sent (with a note like "N likely secrets (passwords, keys, tokens) were redacted below before you even see this" when anything was caught) and a "Don't ask again" checkbox.
      • Confirm to actually send it, or cancel to back out entirely.
    4. If a reply includes a suggested shell command, it renders as its own block with a " n Run in terminal" button.
      • Clicking it opens one more confirm titled "Run in terminal?" ; confirming only types the command into your terminal input, it never presses Enter for you.

    How to verify

    1. Configure a real key for your chosen provider, click Ask AI , ask a question, confirm the "Send to AI model?" preview, and confirm you get back a genuine model reply in the panel (not an "Error: …" line).
    2. Deliberately have some secret-looking text in the terminal (e.g. type password=test123 and press Enter so it's in scrollback), click Ask AI again, and confirm the preview text shows [REDACTED:...] in place of the real value, with the note above the preview reporting a nonzero redaction count.
    3. Check "Don't ask again" before confirming a send, then ask another question.
      • Expect the request to go straight through with no confirm modal this time.
    4. Go to Settings → AI Assistant and re-enable the confirm toggle.
      • Ask again and confirm the "Send to AI model?" preview reappears.
    5. Click " n Run in terminal" on a suggested command, confirm the "Run in terminal?" prompt, and confirm the command appears typed in the terminal's input line without having been submitted — you still have to press Enter yourself.

    Troubleshooting

    • Sidebar/panel says "not configured" even after adding a key — reopen the AI panel once (it re-checks availability on every open now, not just the first time this session); also confirm the Enable toggle in Settings → AI Assistant is actually checked and that you picked a real model ID for your provider (use Fetch models rather than typing a guessed one).
    • Redaction preview shows garbled escape-code text instead of readable terminal output — a real bug (an ANSI-stripping pattern too narrow to catch DEC private-mode sequences like cursor-visibility/bracketed-paste codes) fixed this session; confirm you're on a current build if you still see this.
    • Tired of confirming every single question — check Don't ask again in the confirmation dialog itself (re-enable the confirmation anytime from Settings → AI Assistant if you change your mind).
    • A suggested command shows as inert text with no Run button — it tripped the same kind of safety policy check as the MCP server's denylist above; that's deliberate, not a rendering bug.