Reach
Repository: Reach
Author: alexandrosnt · Source status: Clear source
A modern, cross-platform SSH client and remote server management tool.
Score basis:Clear source · Risk needs review · Universal
Compare skills
Pick 2–4 skills and compare what really matters: fit, risk, install effort, and community signal.
Comparison matrix
Highlights show current best; tooltip explains diff/best rules.
SAS-v2.1 diff rules / risk tag notes
Start with the matrix. Open this section when you need to understand audit grades, top threats, control gaps, and best-value highlights.
Suggested baseline
Search to add skills, or paste 2–4 comma-separated slugs.
How differences are detected
A row is marked different when selected skills have distinct values. Only-differences mode hides rows that are identical.
How best values are highlighted
Audit score, evidence confidence, trust score, and community signal prefer higher values; execution risk and install friction prefer lower values.
How to read risk tags
Risk tags come from SAS-v2.1 public-evidence signals and point to command, network, secret, context, or supply-chain items to review before install.
Selected audit signals
mcp-ssh-manager
Execution risk:High
Threat tags:unexpected code execution, data exfiltration, human approval gap
Control gaps:missing license, broad permissions, shell without guardrails
coolify-mcp
Execution risk:High
Threat tags:unexpected code execution, data exfiltration, memory context poisoning
Control gaps:missing license, broad permissions, shell without guardrails
mcp-for-argocd
Execution risk:High
Threat tags:unexpected code execution, data exfiltration, memory context poisoning
Control gaps:missing license, broad permissions, shell without guardrails
| Dimension | mcp-ssh-manager | coolify-mcp | mcp-for-argocd |
|---|---|---|---|
| SAS-v2.1 pre-install audit | |||
Audit grade | C · Review first | C · Review first | C · Review first |
Execution risk | High | High | High |
Threat tags | unexpected code execution, data exfiltration, human approval gap | unexpected code execution, data exfiltration, memory context poisoning | unexpected code execution, data exfiltration, memory context poisoning |
Control gaps | missing license, broad permissions, shell without guardrails | missing license, broad permissions, shell without guardrails | missing license, broad permissions, shell without guardrails |
Permission summary | Permission review, Network, Command | Permission review, Network, Command | Permission review, Network, Command |
Evidence confidence | 65% | 67% | 67% |
| Source & provenance | |||
Provenance | bvisible/mcp-ssh-manager | StuMason/coolify-mcp | argoproj-labs/mcp-for-argocd |
Category | Operations & Infra | Operations & Infra | Operations & Infra |
Freshness | |||
| Risk & trust | |||
Trust score | 79 | 79 | 79 |
Audit signals | |||
| Install & compatibility | |||
Supported tools | Universal | Universal | Universal |
Install method | script-backed | script-backed | script-backed |
Install friction | |||
| Community | |||
Stars | 137 | 297 | 392 |
Repository: claude-code
Author: anthropics · Source status: Clear source
This skill should be used when the user asks to "add MCP server", "integrate MCP", "configure MCP in plugin", "use .mcp.json", "set up Model Context Protocol", "connect external service", mentions "${CLAUDE_PLUGIN_ROOT}
Score basis:Clear source · High risk signals · Claude
2026-04-07 |
2026-04-08 |
2026-03-26 |
No explicit signals |
No explicit signals |
No explicit signals |
Permission hints | repository clone, local runtime dependencies | repository clone, local runtime dependencies | repository clone, local runtime dependencies |
|---|
40 |
40 |
40 |