Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Ssh Expert

CSecurity

SSH mastery — key management, config patterns, multiplexing, tunneling, jump hosts, and hardening.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsrustgoshellbashsqltestingdebugginggitdatabasesecurity

Works with

cli

Security Analysis

C63/100
criticalAccesses sensitive system or user directories
criticalReads or references SSH private keys

Pro shows the line behind each finding and how to fix it

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill ssh-expert --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ssh Expert?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Ssh Expert
[![Security: C — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-ssh-expert/badge)](https://www.skillsdirectory.com/skills/aicodedecode-ssh-expert)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: ssh-expert
description: SSH mastery — key management, config patterns, multiplexing, tunneling, jump hosts, and hardening.
category: development
---

## Overview

SSH is the secure remote-access protocol everything runs through: shell access, file transfer, tunnels, git, port forwarding, and jump hosts. Most people use 5% of it — typing full hostnames, re-entering passwords, and forwarding agents insecurely. Mastery means a config file that makes `ssh prod` do the right thing: right key, right user, right jump host, multiplexed connection.

This skill covers key management, `~/.ssh/config` patterns, connection multiplexing, tunneling, jump hosts, and server hardening — the SSH knowledge that makes remote work frictionless and secure.

## When to use

- Setting up SSH keys and config for hosts.
- Accessing hosts behind bastions/jump hosts.
- Creating tunnels (local/remote/dynamic port forwarding).
- Debugging SSH connection issues (verbose mode, key problems).
- Hardening SSH servers.
- Speeding up repeated SSH/SCP/rsync with multiplexing.
- Replacing insecure agent forwarding.

## Core concepts

- **Keys.** Ed25519 (`ssh-keygen -t ed25519`) for new keys; RSA-4096 where legacy requires it. One key per client device (not per server — servers get your public key). Passphrases on keys + `ssh-agent` — encrypted at rest, convenient in use.
- **ssh-agent.** Holds decrypted keys in memory; `ssh-add` loads them. Use the OS keychain integration (macOS Keychain, Windows OpenSSH agent, Linux keyring) so passphrases unlock once per login.
- **`~/.ssh/config`.** The productivity core: Host aliases with HostName, User, Port, IdentityFile, and ProxyJump. `ssh prod-db` instead of `ssh -i key.pem ubuntu@10.0.4.23 -p 2222`. Version it (minus secrets) in dotfiles.
- **Jump hosts (ProxyJump).** `ProxyJump bastion` — SSH through a bastion transparently; `-J` flag for ad-hoc. Bastions are the controlled entry point to private networks; ProxyJump replaces manual two-hop SSH.
- **Multiplexing.** `ControlMaster auto`, `ControlPath`, `ControlPersist` — one TCP connection reused for subsequent sessions. Second `ssh`/`scp`/`rsync` connects instantly. Dramatic speedup for scripts making many connections.
- **Port forwarding.** `-L` local (expose remote service locally: `-L 5432:db:5432`), `-R` remote (expose local service remotely — for webhooks behind NAT), `-D` dynamic (SOCKS proxy for the browser). `-N` for forward-only sessions; `-f` backgrounds.
- **Tunnels as tools.** Local-forward to reach private databases/UIs securely; dynamic forward as a poor-man's VPN for browsing through a trusted network. Always prefer forwarding over exposing services.
- **SCP/SFTP/rsync.** `scp` for simple copies, `sftp` for interactive, `rsync -e ssh` for efficient syncs (delta transfer, resume). All respect `~/.ssh/config` — aliases work everywhere.
- **Host key verification.** `known_hosts` + `StrictHostKeyChecking` — the MITM protection. Changed host keys mean something changed (rebuild? attack?) — investigate, don't blindly accept. `ssh-keygen -R host` removes stale entries.
- **Certificates (advanced).** SSH certificates (not just keys) — a CA signs short-lived user/host certs, eliminating `authorized_keys` management at scale. The right answer past ~dozens of hosts.
- **Server hardening.** `PasswordAuthentication no`, `PermitRootLogin no` (or `prohibit-password`), key-only auth, non-standard port as obscurity (not security), fail2ban, `AllowUsers`/`AllowGroups` allowlists, `MaxAuthTries`, protocol 2 only.
- **Agent forwarding danger.** `-A` exposes your agent socket to the remote host — a compromised server can use your keys. Prefer ProxyJump (keys never leave your machine). If you must forward, confirm each use (`AddKeysToAgent confirm`).
- **Debugging.** `ssh -v` (up to `-vvv`) shows the handshake: which keys offered, why auth failed, where it hangs. 90% of SSH debugging is reading verbose output.
- **Keepalives.** `ServerAliveInterval 60` + `ServerAliveCountMax` — stop NAT/firewalls killing idle sessions. `ClientAliveInterval` server-side for the same.

## Practical workflow

1. **Generate per-device keys.** Ed25519, passphrase-protected, added to agent:
   ```bash
   ssh-keygen -t ed25519 -C "laptop-2026" -f ~/.ssh/id_ed25519
   ssh-add --apple-use-keychain ~/.ssh/id_ed25519  # macOS; OS equivalent elsewhere
   ```
2. **Write the config.** Aliases, jump hosts, multiplexing — the file that makes SSH pleasant:
   ```ssh
   Host bastion
     HostName bastion.example.com
     User ops
     IdentityFile ~/.ssh/id_ed25519

   Host prod-*
     User ubuntu
     ProxyJump bastion
     IdentityFile ~/.ssh/id_ed25519
     ControlMaster auto
     ControlPath ~/.ssh/cm-%r@%h:%p
     ControlPersist 10m
     ServerAliveInterval 60
   ```
3. **Use ProxyJump, not forwarding.** `ssh -J bastion db.internal` ad-hoc; `ProxyJump` in config permanently. Keys stay local.
4. **Forward ports deliberately.** Database GUI over a private network:
   ```bash
   ssh -N -L 5432:db.internal:5432 prod-bastion   # psql -h localhost now reaches it
   ssh -N -D 1080 prod-bastion                     # SOCKS proxy for the browser
   ```
5. **Debug with verbosity.** `ssh -vvv host` — read the auth section: keys offered, accepted, or why not. Common: wrong IdentityFile, permissions on `~/.ssh` (700) / keys (600), server refusing (check `auth.log`).
6. **Harden servers.** Key-only, no root login, allowlisted users, fail2ban — in `/etc/ssh/sshd_config`, tested with a second session open before restarting sshd (never lock yourself out).
7. **Sync files efficiently.** `rsync -avz -e ssh project/ prod-app:/srv/app/` — delta transfers beat `scp -r` for repeated deploys.
8. **Scale with certificates.** Past dozens of hosts, SSH CAs beat `authorized_keys` distribution — short-lived certs, no key sprawl, instant revocation.

## Common pitfalls

- **Passwords instead of keys** — brute-forceable and annoying; keys + agent everywhere.
- **Agent forwarding (`-A`) habitually** — key-socket exposure on every hop; ProxyJump instead.
- **No `~/.ssh/config`** — typing full commands every time; aliases + defaults.
- **Wrong permissions** — `~/.ssh` 700, private keys 600, `~/.ssh/config` 600; SSH refuses otherwise (by design).
- **One key everywhere** — key sprawl and unclear revocation; per-device keys, per-purpose where sensitive.
- **Blindly accepting changed host keys** — MITM or rebuild; investigate before `ssh-keygen -R`.
- **No multiplexing** — slow repeated connections in scripts; ControlMaster/ControlPersist.
- **Idle disconnects** — NAT timeouts killing sessions; ServerAliveInterval.
- **Locking yourself out** — restarting sshd with bad config and no fallback; keep a session open while testing.
- **Root login allowed** — the most attacked account; `PermitRootLogin no`.
- **`-R` forwarding without GatewayPorts awareness** — accidentally exposing local services; understand bind addresses.
- **Passphraseless keys on servers** — convenient for automation but a stolen file is full access; restrict commands (`command="..."` in authorized_keys) or use certificates.
- **Ignoring `-v` output** — guessing at auth failures; verbose mode tells you exactly what happened.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →