ssh-key-management

ssh-key-management is a skill for Claude Code, Codex from acquia/acquia-skills. It costs 31 tokens per session (1,660 once invoked), scanned D, original, MIT.

A guide for managing SSH keys used to securely access Acquia Cloud. An SSH key is a paired local secret and public credential that can authenticate you without typing a password.

In plain words
What is it for?
For creating or generating keys, listing keys in an Acquia account or IDE, deleting keys, and preparing SSH access for development or automated deployments.
Why use it?
It helps resolve access failures caused by missing keys and supports secure access for computers, IDEs, scripts, and deployment systems. It also keeps key creation, listing, and deletion in one workflow.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Needs its repository: it reads a path above its own folder, which exists only inside the repository. The line is instead of `api:environments:code-switch` (see [MEO Deployments](../meo-deployments/SKILL.md))..

Good fit For creating or generating keys, listing keys in an Acquia account or IDE, deleting keys, and preparing SSH access for development or automated deployments.

Compare 6 skills from other repositories ↓
Install

Getting it into your agent

It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.

Clone the repo
git clone --depth 1 https://github.com/acquia/acquia-skills
agentmods
npx agentmods add skills/acquia/acquia-skills/ssh-key-management

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ssh-key-management

README.md
[![agentmods](https://agentmods.dev/badge/skills/acquia/acquia-skills/ssh-key-management/github.svg)](https://agentmods.dev/skills/acquia/acquia-skills/ssh-key-management)
Your own site
<a href="https://agentmods.dev/skills/acquia/acquia-skills/ssh-key-management"><img src="https://agentmods.dev/badge/skills/acquia/acquia-skills/ssh-key-management/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for ssh-key-management

Your own site · 80×15
<a href="https://agentmods.dev/skills/acquia/acquia-skills/ssh-key-management"><img src="https://agentmods.dev/badge/skills/acquia/acquia-skills/ssh-key-management.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 31 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,660 The whole file, excluding the scripts and references it only reads on demand.
Security scan D 2 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00031 $0.01660
Opus 5 $0.00015 $0.00830
Sonnet 5 $0.00006 $0.00332
Haiku 4.5 $0.00003 $0.00166

Measured 6d ago against content hash d4a029f4a285, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade D, and why

ssh-key-management scanned grade D with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks for rootmediumPrivilege escalation

A mod that escalates privileges can change anything on the machine, not only the project.

chmod 600 ~/.ssh/id_rsa

Reaches for credential fileshighPrivilege escalation

SSH keys, cloud credentials, git-credentials, .npmrc, /etc/shadow: reading these is how a config file becomes a credential leak.

4. Save the private key locally (usually `~/.ssh/id_rsa`)
skills/acli/ssh-key-management/SKILL.md · 306 lines

How it starts

The opening of the file, as written. The whole thing — 306 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Managing SSH Keys

Use when:

  • Adding or generating an SSH key for Acquia Cloud
  • Listing or deleting SSH keys
  • Setting up SSH access for IDEs or CI/CD pipelines

SSH keys provide secure authentication to Acquia Cloud resources without needing to enter passwords.


Why SSH Keys?

SSH keys allow you to:

  • Securely access your IDEs without entering a password
  • Push code to your repositories
  • Execute remote commands on your servers
  • Automate deployments in scripts or CI/CD pipelines

List Your SSH Keys

See all your SSH keys

acli ssh-key:list

Output:

SSH Keys for your account:
  [0] My Laptop (generated 2024-01-15)
      Fingerprint: ab:cd:ef:12:34:56:78:90
  [1] Work Desktop (generated 2024-02-01)
      Fingerprint: 11:22:33:44:55:66:77:88

List keys per IDE

acli ide:ssh-key:list

Generate a New SSH Key

Create an SSH key interactively

acli ssh-key:create

This will:

  1. Prompt for a label (e.g., "My Laptop", "CI Server")
  2. Generate a public/private key pair
  3. Store the public key in your Acquia account
  4. Save the private key locally (usually ~/.ssh/id_rsa)

Example:

$ acli ssh-key:create
? Enter a label for this SSH key: My Laptop
✓ SSH key created!
  Public key added to your account.
  Private key saved to: ~/.ssh/id_rsa
  Fingerprint: ab:cd:ef:12:34:56:78:90

Note: The label prompt is the last step before the key is generated and permanently added to your Acquia account. Confirm your label is correct before pressing Enter.


Upload an Existing SSH Key

If you already have an SSH key, upload it without regenerating:

acli ssh-key:upload --filepath ~/.ssh/id_rsa.pub --label "Existing Key"

Or interactively:

acli ssh-key:upload

Prompts you to select the key file and enter a label.

Skip waiting for propagation

By default, acli waits for the key to propagate to all servers. Skip this with:

acli ssh-key:upload --filepath ~/.ssh/id_rsa.pub --label "My Key" --no-wait

Read the full file on GitHub · 306 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago Changed · +3 lines d4a029f4a285
  2. 10d ago First seen · 303 lines · 31 tokens per session scan D 61f23b031aa0

Subscribe to this mod's changes

ssh-key-management is a skill published in the GitHub repository acquia/acquia-skills (9 stars, last pushed yesterday), licensed MIT. It adds 31 tokens to every session and 1,660 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it D with 2 findings (asks for root, reaches for credential files). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

google-cloud-solution-guided-gke-ai-migration

Guides the migration of existing AI workloads (Cloud Run, Gemini API, Gemini Enterprise Agent Platform) to self-hosted GKE inference using gcloud and kubectl. Use when the user has an existing AI inference workload (on Cloud Run, the Gemini API, Gemini Enterprise Agent Platform, or a custom VM) and wants to move it to…

google/skills · 157 tokens

agent-platform-tuning

Agent Platform Model Tuning. Use when you need to fine-tune open models or Gemini models using Agent Platform infrastructure. Don't use for model training outside Agent Platform, model deployment to endpoints (use agent-platform-deploy), or managing serving endpoints (use agent-platform-endpoint-management).

google/skills · 64 tokens

application-design-center-design-deploy

Processes GCP infrastructure design and deployment workflows within Application Design Center (ADC). Use when: - Designing GCP infrastructure with Terraform. - Validating local HCL. - Performing best-practice plan scans. - Importing templates to Application Design Center (ADC). - Deploying templates. - Troubleshooting…

google/skills · 94 tokens

gke-alert-configuration

Configures alerting policies in Terraform for Google Kubernetes Engine (GKE) clusters, workloads, and services using PromQL and Google Cloud Managed Service for Prometheus. Use when writing, analyzing, validating, or deploying Terraform alerting policies to monitor GKE service latency, traffic, error rates using…

google/skills · 120 tokens

gke-compute-classes

Configures, optimizes, and troubleshoots GKE ComputeClasses. Use when configuring Spot VMs with on-demand fallback, targeting specific accelerators (GPUs/TPUs) or machine families, restricting ComputeClass access, or debugging pending pods related to node pool auto-creation. Do not use for cluster-level Node Auto…

google/skills · 83 tokens

google-cloud-solution-n-tier-serverless-web-app

Assists in designing and implementing secure n-tier serverless web applications and microservices on Google Cloud. Use when users need architecture designs, security checklists, Terraform code, or deployment guidance for multi-tier serverless apps, regional data residency / European sovereignty compliance, zero-trust…

google/skills · 91 tokens