ssh
Use when configuring SSH access, keys, tunnels, host diagnostics, or safe remote command workflows.
What this skill does
<!-- TOC: Quick Start | THE EXACT PROMPT | Essential Commands | Config | AGENTS.md Blurb | References --> # SSH — Secure Remote Access > **Core Capability:** Secure shell connections, key management, tunneling, and file transfers. --- ## Quick Start ```bash # Connect to server ssh user@hostname # Connect with specific key ssh -i ~/.ssh/my_key user@hostname # Run remote command ssh user@host "cd /app && git status" # Copy file to remote scp local.txt user@host:/remote/path/ # Sync directory (preferred over scp) rsync -avzP ./local/ user@host:/remote/ ``` --- ## THE EXACT PROMPT — Common Workflows ### Connect Through Jump Host ```bash # Single jump (bastion) ssh -J jumphost user@internal-server # Multiple jumps ssh -J jump1,jump2 user@internal-server ``` ### Local Port Forward (access remote service locally) ```bash # Access remote:80 via localhost:8080 ssh -L 8080:localhost:80 user@host # Access db-server:5432 via localhost:5432 through jumphost ssh -L 5432:db-server:5432 user@jumphost ``` ### Generate and Deploy Key ```bash # Generate Ed25519 key (recommended) ssh-keygen -t ed25519 -C "[email protected]" # Copy public key to server ssh-copy-id user@host ``` --- ## Essential Commands | Task | Command | |------|---------| | Connect | `ssh user@host` | | Connect on port | `ssh -p 2222 user@host` | | Connect with key | `ssh -i ~/.ssh/key user@host` | | Run remote command | `ssh user@host "command"` | | Interactive remote | `ssh -t user@host "htop"` | | Copy to remote | `scp file.txt user@host:/path/` | | Copy from remote | `scp user@host:/path/file.txt ./` | | Sync to remote | `rsync -avzP ./local/ user@host:/remote/` | | Local forward | `ssh -L local:remote:port user@host` | | Remote forward | `ssh -R remote:local:port user@host` | | SOCKS proxy | `ssh -D 1080 user@host` | | Jump host | `ssh -J bastion user@internal` | | Generate key | `ssh-keygen -t ed25519` | | Copy key to server | `ssh-copy-id user@host` | | Debug connection | `ssh -vvv user@host` | --- ## SSH Config Location: `~/.ssh/config` ``` Host myserver HostName 192.168.1.100 User deploy Port 22 IdentityFile ~/.ssh/myserver_key ForwardAgent yes Host internal HostName 10.0.0.50 User deploy ProxyJump bastion ``` Then connect with just: `ssh myserver` ### Connection Multiplexing (faster reconnects) ``` Host * ControlMaster auto ControlPath ~/.ssh/sockets/%r@%h-%p ControlPersist 600 ``` ```bash mkdir -p ~/.ssh/sockets ``` --- ## SSH Agent ```bash # Start agent eval "$(ssh-agent -s)" # Add key ssh-add ~/.ssh/id_ed25519 # Add with macOS keychain ssh-add --apple-use-keychain ~/.ssh/id_ed25519 # List loaded keys ssh-add -l ``` --- ## Security Tips - Use Ed25519 keys (faster, more secure than RSA) - Set `PasswordAuthentication no` on servers - Keep keys encrypted with passphrases - Use `ssh-agent` to avoid typing passphrase repeatedly - Restrict key usage with `command=` in authorized_keys --- ## AGENTS.md Blurb Copy this to your project's AGENTS.md: ```markdown ### SSH Access SSH is configured for these servers: - **Production:** `ssh prod` (via ~/.ssh/config) - **Staging:** `ssh staging` Common operations: \`\`\`bash ssh prod "cd /app && git status" # Check deploy status rsync -avzP ./dist/ prod:/app/dist/ # Sync files ssh -L 5432:localhost:5432 prod # DB tunnel \`\`\` Keys: `~/.ssh/id_ed25519` (add with `ssh-add`) ``` --- ## References | Topic | Reference | |-------|-----------| | Full command reference | [COMMANDS.md](references/COMMANDS.md) | | Port forwarding details | [TUNNELS.md](references/TUNNELS.md) | | Key management | [KEYS.md](references/KEYS.md) |
Related in General
modeling-omnistudio-epc-catalog
IncludedSalesforce Industries CME EPC product-modeling skill for Product2-based catalog creation. Use when creating EPC products, configuring product attributes, building offer bundles with Product Child Items, or reviewing EPC DataPack JSON metadata for product catalog changes. TRIGGER when: user creates or updates Product2 EPC records, AttributeAssignment payloads, AttributeMetadata/AttributeDefaultValues, Offer bundles, or ProductChildItem relationships. DO NOT TRIGGER when: designing OmniScripts/FlexCards/Integration Procedures (use building-omnistudio-omniscript, building-omnistudio-flexcard, or building-omnistudio-integration-procedure), implementing Apex business logic (use generating-apex), or troubleshooting deployment pipelines (use deploying-metadata).
relationship-science-coach
IncludedUse this skill for direct, practical adult relationship coaching: couples conflict, repair, trust, marriage, dating, flirting, attachment patterns, emotional connection, sex, desire differences, eroticism, kink negotiation, affection, love languages, breakups, and long-term passion. Draw on Gottman, EFT and Hold Me Tight, attachment science, modern sex research, Perel, Nagoski, Kerner, Schnarch, Love and Stosny, and flexible love-language tools. Be concrete and low-hedge. Redirect only for imminent danger, abuse, coercive control, minors, non-consent, self-harm, stalking, or medical/legal/psychiatric decisions.
building-sf-integrations
IncludedSalesforce integration architecture and runtime plumbing with 120-point scoring. Use this skill to set up Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, and Change Data Capture. TRIGGER when: user sets up Named Credentials, External Services, REST/SOAP callouts, Platform Events, CDC, or touches .namedCredential-meta.xml files. DO NOT TRIGGER when: Connected App/OAuth config (use configuring-connected-apps), Apex-only logic (use generating-apex), or data import/export (use handling-sf-data).
venue-templates
IncludedAccess comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and grant proposals (NSF, NIH, DOE, DARPA). This skill should be used when preparing manuscripts for journal submission, conference papers, research posters, or grant proposals and need venue-specific formatting requirements and templates.
let-fate-decide
IncludedDraws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over ask-questions-if-underspecified when the user's tone is casual or playful rather than precision-seeking.
net-ops
IncludedCross-platform network troubleshooting (Windows, macOS, Linux) via local or remote shell. Use for: DNS broken, can't resolve hostnames, nslookup/dig works but apps fail, NRPT, WFP, scutil, /etc/resolver, systemd-resolved, /etc/resolv.conf, NetworkManager, VPN DNS leak residue (ProtonVPN/Mullvad/WireGuard/AnyConnect), AV/firewall blocking DNS or DoH, Tailscale DNS interaction, intermittent connectivity, remote diagnostics over SSH.