Agent skill

Sshepherd

by sickn33 in sickn33/agentic-awesome-skills

Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.

MITAuto-check: warningsDevOps & Cloud

Install Sshepherd

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill sshepherd -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills sshepherd --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sshepherd .claude/skills/sshepherd && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sshepherd
GitHub stars
47k
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
751 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.

  • Works in 3 steps: Declare targets once, outside any prompt → Invoke a group + action by name → Discover the command surface
  • Tasks that involve Linux administration
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Examples, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Sshepherd is an agent skill from sickn33/agentic-awesome-skills. Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Linux administration, Containers and Cryptography. It works with PostgreSQL, Docker and Linux. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Linux administration
  • Tasks that involve Containers
  • Tasks that involve Cryptography

Example prompts

  • “/sshepherd”

Requirements

  • Docker

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Declare targets once, outside any prompt
  2. Invoke a group + action by name
  3. Discover the command surface

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sshepherd loads about 1.6k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 751 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:41
    rs on the command line: ssh aliases in `~/.ssh/config`, Postgres targets in `~/.config/sshepherd/targets.toml`, deploy r
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:87
    y alias/target/recipe ahead of time in `~/.ssh/config` / `targets.toml` / recipe TOML — never inline connection details.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 751 words, ~1,636 tokens.

Download SKILL.mdSave it as .claude/skills/sshepherd/SKILL.md (or your agent's skills folder).
name
sshepherd
description
Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.
category
devops
risk
critical
source
community
source_repo
Antheurus/sshepherd
source_type
community
date_added
2026-07-15
author
Antheurus
tags
ssh, devops, cli, server-ops, postgres, deploy, zero-knowledge
tools
claude, cursor, gemini, codex
license
MIT

sshepherd

Overview

sshepherd is a compiled Bun/TypeScript CLI that lets an agent operate a real remote server over SSH — health checks, docker/systemd service control, log tailing, config file edits, read-only Postgres introspection, and declarative deploys — without ever seeing a password, private key, hostname, username, or port. Every operation shells out to the system ssh binary through a single transport path and returns the same typed Envelope<T> (ok, alias, data, error), never a raw terminal dump. The agent passes only a name — an ssh alias, a Postgres target, or a deploy recipe — that resolves entirely outside the process.

When to Use This Skill

  • Use when you need to check a remote server's health (disk, memory, CPU, ports, OOM history) without handing the agent SSH credentials.
  • Use when working with remote docker or systemd services — listing, inspecting, or restarting them — or tailing their logs.
  • Use when the user asks to read or edit a remote config file, run a declarative deploy from a named recipe, introspect a remote Postgres database read-only, or audit SSH/security posture on a box.

How It Works

Step 1: Declare targets once, outside any prompt

Every connection detail is declared ahead of time and never appears on the command line: ssh aliases in ~/.ssh/config, Postgres targets in ~/.config/sshepherd/targets.toml, deploy recipes in recipe TOML files. OpenSSH resolves the real HostName/User/Port/IdentityFile internally.

Step 2: Invoke a group + action by name

This repository does not ship the sshepherd executable. The user must install or build a reviewed upstream release outside the current workspace and provide its explicit absolute path. Verify it is an executable regular file, not a symlink, before use. Never auto-discover or execute ./dist/sshepherd from the repository being operated on.

sshepherd <group> <action> [positionals...] [--flag value]

Nine command groups — hosts, check, logs, services, deploy, config, db, files, security — 52 ops total. Output is JSON to stdout by default; add --pretty for a human-readable table/key-value view. The response only ever echoes back the alias it was given — there is no host/user/port/ip field anywhere in the response type, structurally.

Step 3: Discover the command surface
bash
"/absolute/path/to/sshepherd" --help                 # list groups
"/absolute/path/to/sshepherd" check --help           # list actions + flags for one group

Examples

Example 1: Server health overview
bash
"/absolute/path/to/sshepherd" check overview lms-server

Returns a JSON envelope with disk, memory, CPU, listening ports, and OOM history for the host behind the lms-server alias — the agent never learns the host's address.

Example 2: Restart a docker service and tail its logs
bash
"/absolute/path/to/sshepherd" services restart lms-server --name api
"/absolute/path/to/sshepherd" logs tail lms-server --name api --lines 100
Example 3: Read-only Postgres introspection
bash
"/absolute/path/to/sshepherd" db tables prod

prod is a pg-target name that resolves to how to reach psql on a host — never a database password. psql runs inside the target container, authenticated by peer/trust/.pgpass already on the remote.

Show full SKILL.md (333 more words)Show less

Best Practices

  • ✅ Declare every alias/target/recipe ahead of time in ~/.ssh/config / targets.toml / recipe TOML — never inline connection details.
  • ✅ Pass only names (alias, pg-target, recipe) to the CLI; let OpenSSH own authentication.
  • ✅ Use --pretty for human review and default JSON output for machine parsing.
  • ❌ Don't try to inject a hostname, user, port, or password into a command — the CLI has no field for them.
  • ❌ Don't reach for the ssh2 npm library or hand-rolled SSH; the whole point is delegating to the trusted system ssh binary.

Limitations

  • This skill does not replace environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, or safety boundaries are missing.
  • Requires the system OpenSSH client and pre-declared aliases/targets/recipes; it cannot connect to a host that has not been configured outside the agent.
  • Postgres access is read-only introspection by design.

Security & Safety Notes

  • Zero-knowledge credential model: the agent never sees a password, private key, hostname, username, or port. It only ever passes an ssh alias, a pg-target name, or a recipe name; the real connection tuple is resolved by OpenSSH outside the process, and every response echoes back only the alias.
  • Never reads private key material. Authentication happens entirely inside OpenSSH's own trusted code path.
  • Confirmation gate on mutations: destructive/mutating actions (service restart, config write, deploy) require an explicit --yes confirm flag.
  • Human-only credential entry: the separate setup ssh-alias install action opens a one-shot local browser form that only a human can type a password into — the agent can trigger and wait on it but never sees, logs, or relays the password.
  • Environment expectation: run against hosts you are authorized to operate.

Common Pitfalls

  • Problem: Trying to pass a hostname or password directly to a command. Solution: Register the target first (setup ssh-alias register / setup db-target), then reference it only by name.
  • Problem: A mutating action returns without doing anything. Solution: Add the --yes confirm flag — mutations are gated by design.
  • @devops-automation - When you need broader CI/CD or infrastructure-as-code automation beyond SSH ops.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sshepherd of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Sshepherd next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sshepherd compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sshepherd this skillsickn33/agentic-awesome-skills47k1 repos~1.6kAutomated safety check: WarnMIT
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only
Setup Cpu Proxy Serverdrawthingsai/draw-things-community582—~3.8kAutomated safety check: PassGPL-3.0
PodmanBagelHole/DevOps-Security-Agent-Skills1.1k—~1.9kAutomated safety check: NotesMIT
GitHub Runnermagnus919/agent-skills116—~1.7kAutomated safety check: PassMIT
Linux PatcherLeoYeAI/openclaw-master-skills2.2k—~4.5kAutomated safety check: WarnMIT

Similar skills

  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Setup Cpu Proxy Server

    drawthingsai/draw-things-community

    Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

    582 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Podman

    BagelHole/DevOps-Security-Agent-Skills

    Manage containers using Podman, the daemonless container engine.

    1.1k GitHub stars~1.9k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes
  • GitHub Runner

    magnus919/agent-skills

    Deploy, manage, and troubleshoot self-hosted GitHub Actions runners.

    116 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Linux Patcher

    LeoYeAI/openclaw-master-skills

    Automated Linux server patching and Docker container updates.

    2.2k GitHub stars~4.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: warnings
  • Linux Troubleshooting with Inspektor Gadget

    inspektor-gadget/inspektor-gadget

    Debugs a single Linux host or container runtime at the kernel level with the standalone ig binary and eBPF gadgets, read-only and without Kubernetes.

    2.9k GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Sshepherd

What does Sshepherd do?

Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent. Sshepherd is an agent skill from sickn33/agentic-awesome-skills. Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.

When should I use Sshepherd?

Sshepherd fits situations like: tasks that involve Linux administration; tasks that involve Containers; tasks that involve Cryptography.

How do I install Sshepherd in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill sshepherd -a claude-code`. Or copy the skill folder (skills/sshepherd in sickn33/agentic-awesome-skills) into .claude/skills/sshepherd in your project. Claude Code loads it when a task matches its description.

How do I install Sshepherd in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill sshepherd -a codex`. Or copy the skill folder (skills/sshepherd in sickn33/agentic-awesome-skills) into .agents/skills/sshepherd in your project. Codex loads it when a task matches its description.

Can I use Sshepherd in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill sshepherd -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sshepherd, .gemini/skills/sshepherd, .github/skills/sshepherd and .opencode/skills/sshepherd in your project.

What does Sshepherd need to run?

SKILL.md names no scripts, command-line tools or credentials: Sshepherd is instructions for the agent only. Our summary lists: Docker.

Does Sshepherd access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sshepherd safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Sshepherd use?

Sshepherd is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sshepherd use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sshepherd?

Skills that share tags, products or a category with Sshepherd: Minimega (sandia-minimega/minimega, 160 stars), Setup Cpu Proxy Server (drawthingsai/draw-things-community, 582 stars), Podman (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars) and GitHub Runner (magnus919/agent-skills, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sshepherd?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.