ssh
GitHub通过SSH在远程服务器执行Shell命令,支持密码、密钥及Agent认证。自动解析凭据,区分远程与本地操作,用于系统巡检、配置查看等运维任务。
Trigger Scenarios
Install
npx skills add opskat/opskat --skill ssh -g -y
SKILL.md
Frontmatter
{
"name": "ssh",
"description": "Run shell commands on a remote server over SSH via exec. Covers command syntax and the remote-vs-local distinction."
}
SSH assets
Command syntax
Pass the shell command verbatim as command:
uptimesystemctl status nginxcat /etc/nginx/nginx.confdf -h | grep -v tmpfs
Notes
- The command runs on the remote server, never on the user's machine. Tools
named
local_*operate on the user's own machine and are not interchangeable with this one. - Use
cat/ls/grepinside the command to inspect remote files. - The
scopeparameter is not used by SSH assets. - Credentials are resolved automatically; never ask the user for a password.
Asset config (for put_asset)
| field | type | required | notes |
|---|---|---|---|
host |
string | yes | Hostname or IP |
port |
number | no | Defaults to 22 |
username |
string | yes | Login username |
auth_type |
string | no | "password", "key", or "agent"; inferred from plaintext/reference/Agent inputs when omitted |
password |
string | no | Write-only. Encrypted in the asset; never returned and does not create a credential |
credential_id |
number | no | Existing managed password or SSH-key credential ID; its type infers auth when auth_type is omitted and must match an explicit auth type |
agent_source_id |
number | yes for Agent | Existing SSH Agent source ID; the source may be offline at save time |
agent_key_fingerprint |
string | yes for Agent | Canonical SHA256 identity fingerprint; both Agent fields are required and infer Agent auth when auth_type is omitted |
ssh_asset_id |
number | no | Accepted compatibility key; the current automation handler does not persist it |
password and credential_id are mutually exclusive. Agent auth rejects both; non-Agent auth
rejects Agent fields. private_key and passphrase are not accepted by asset automation:
create/import the SSH-key credential in the desktop key manager, then pass credential_id.
Changing auth clears the old asset association but does not delete a possibly shared credential.
Example:
put_asset(name="web-01", type="ssh", config={"host":"10.0.0.7","username":"root","password":"..."})
Version History
-
b159e91
Current 2026-08-19 20:21
重构资产配置结构,引入托管凭据自动化与Agent认证支持;强化安全审计与敏感数据脱敏边界。
-
d6c7a6e
2026-08-16 07:29
修正文档契约漂移,补充auth_type=agent及其相关字段说明。
- aeb4bc3 2026-07-24 16:28


