Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/daidaij/2native-ssh-mcp/2native-ssh-mcp-agentnpx skills add daidaiJ/2native-ssh-mcp --skill 2native-ssh-mcp-agentgit clone --depth 1 https://github.com/daidaiJ/2native-ssh-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/daidaij/2native-ssh-mcp/2native-ssh-mcp-agent)<a href="https://agentmods.dev/skills/daidaij/2native-ssh-mcp/2native-ssh-mcp-agent"><img src="https://agentmods.dev/badge/skills/daidaij/2native-ssh-mcp/2native-ssh-mcp-agent.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.01542 |
| Opus 5 | $0.00032 | $0.00771 |
| Sonnet 5 | $0.00013 | $0.00308 |
| Haiku 4.5 | $0.00006 | $0.00154 |
Grade A, and why
2native-ssh-mcp-agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 99 lines — stays where its author put it; the contents beside it link to each section on GitHub.
2native-ssh-mcp-agent
Defensive playbook for agents using 2native-ssh-mcp. Read this before executing on production hosts.
Golden rules
- Call
list-serversfirst — read metadata, aliases, notes; pickconnectionNameor plan asessionName. - Never use root — use a dedicated low-privilege account.
- Prefer narrow commands — scope with
head,tail,grep,wc, paths; avoid blindcaton large files. - Respect whitelist/blacklist — if a command is rejected, do not bypass; ask the operator to widen policy.
- Secrets — redaction is off by default (
"redactSecrets": trueenables it per connection); regardless, avoid printing credentials. - Host key rejection — if a connection fails with a host key mismatch (server reimaged / key rotated), do not bypass; report it. Fix is operator-side: remove the stale line from
known_hosts(or set"hostKeyCheck": "none"for dynamic-IP hosts).
Output & tokens
Built-in (automatic)
2native-ssh-mcp layers large output automatically:
- Directories transfer recursively via
file-transfer(per-file atomic upload,files/failedin the result; single files get a sha256 check). - ≥ 8KB (
outputSpillThreshold,-1disables): the full output is written to a local file (default.ssh-mcp-out/,outputSpillDirconfigurable, newest 32 kept). The result carries only a short notice, the absolute path, byte/line counts and a ~12-line preview. Grep/Read that local file — never re-run the command orcatit remotely. - 4–8KB: light compression — head + tail lines, middle replaced with
... [N lines omitted] ..., duplicate/blank lines collapsed. - Disable compression per connection:
"outputCompressLight": false; tune threshold:"outputCompressThreshold": 8192.
ANSI escape sequences (colors, progress bars) are stripped from all output by default; disable per connection: "stripAnsi": false.
Agent-side habits (before running)
| Bad | Better |
|---|---|
cat /var/log/app.log |
tail -n 100 /var/log/app.log |
find / -name '*.log' |
find /var/log -maxdepth 2 -name '*.log' 2>/dev/null | head -50 |
docker ps -a (huge) |
docker ps --format 'table {{.Names}}\t{{.Status}}' | head -30 |
kubectl get pods -A |
add | head or -l app=... |
ls -laR / |
ls -la /specific/path |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · -3 lines 00cf9db19bb4
- 5d ago First seen · 102 lines · 63 tokens per session scan A 9acf30c069b9
2native-ssh-mcp-agent is a skill published in the GitHub repository daidaiJ/2native-ssh-mcp (0 stars, last pushed yesterday), licensed ISC. It adds 63 tokens to every session and 1,542 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…