Agent skill

Ssh Doctor

by steipete in steipete/agent-scripts

SSH triage: Remote Login, launchd sshd, pre-auth closes, stale sessions.

MITAuto-check: notes

Install Ssh Doctor

skills CLI
$ npx skills add steipete/agent-scripts --skill ssh-doctor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install steipete/agent-scripts ssh-doctor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ssh-doctor .claude/skills/ssh-doctor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ssh-doctor
GitHub stars
7.3k
Token cost
~1.2k tokens
SKILL.md length
252 words
Files
1
Skills in repo
45
Repo updated
First seen
Licence
MIT

At a glance

SSH triage: Remote Login, launchd sshd, pre-auth closes, stale sessions.

  • SKILL.md covers Rules, Baseline, Config and Logs, plus 4 more sections
  • Calls ssh; needs OP_SERVICE_ACCOUNT_TOKEN

What it does

Ssh Doctor is an agent skill from steipete/agent-scripts. SSH triage: Remote Login, launchd sshd, pre-auth closes, stale sessions.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Scripts for agents, shared between my repositories. The licence is MIT.

Example prompts

  • “/ssh-doctor”

Requirements

  • A credential in OP_SERVICE_ACCOUNT_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 79150cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OP_SERVICE_ACCOUNT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ssh Doctor loads about 1.2k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 252 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:28
    sudo systemsetup -getremotelogin
  • NoteRuns commands with sudoSKILL.md:29
    sudo systemsetup -setremotelogin on
  • NoteRuns commands with sudoSKILL.md:30
    sudo launchctl print system/com.openssh.sshd 2>&1 | head -80
  • NoteRuns commands with sudoSKILL.md:31
    sudo launchctl kickstart -k system/com.openssh.sshd
  • NoteRuns commands with sudoSKILL.md:32
    sudo lsof -nP -iTCP:22 -sTCP:LISTEN
  • NoteRuns commands with sudoSKILL.md:42
    sudo sshd -T 2>&1 | egrep -i '^(allowusers|denyusers|allowgroups|denygroups|listenaddress|maxstartups|logingracetime|use
  • NoteRuns commands with sudoSKILL.md:43
    sudo egrep -n '^[[:space:]]*(AllowUsers|DenyUsers|AllowGroups|DenyGroups|Match|MaxStartups|LoginGraceTime|ListenAddress|
  • NoteRuns commands with sudoSKILL.md:58
    sudo log show --last 30m --predicate 'process == "sshd" OR process == "launchd"' --style compact | tail -160
  • NoteRuns commands with sudoSKILL.md:75
    sudo launchctl print system/com.openssh.sshd 2>&1 | egrep 'active count|copy count|state =|last exit code|runs ='
  • NoteRuns commands with sudoSKILL.md:77
    sudo lsof -nP -c sshd-session -iTCP 2>/dev/null | head -120

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from steipete/agent-scripts at commit 79150cf, republished under its MIT licence (© steipete). 252 words, ~1,221 tokens.

Download SKILL.mdSave it as .claude/skills/ssh-doctor/SKILL.md (or your agent's skills folder).
name
ssh-doctor
description
SSH triage: Remote Login, launchd sshd, pre-auth closes, stale sessions.

SSH Doctor

Use when SSH connects then closes before auth, Remote Login seems advertised but unusable, or local/remote Mac SSH needs diagnosis.

Rules

  • Do not print secrets, tokens, full env, or broad secret grep output.
  • Validate locally first: loopback failure means server-side sshd/launchd/config; loopback success plus remote failure means network/firewall/filter/listen path.
  • Report suspicious config lines before changing /etc/ssh/sshd_config.
  • Prefer non-interactive SSH:
bash
ssh -o RequestTTY=no -o RemoteCommand=none HOST 'hostname; id -un'

Baseline

bash
hostname; id -un; sw_vers
ipconfig getifaddr en0
ipconfig getifaddr en1 2>/dev/null || true
ipconfig getifaddr en7 2>/dev/null || true
sudo systemsetup -getremotelogin
sudo systemsetup -setremotelogin on
sudo launchctl print system/com.openssh.sshd 2>&1 | head -80
sudo launchctl kickstart -k system/com.openssh.sshd
sudo lsof -nP -iTCP:22 -sTCP:LISTEN
nc -vz 127.0.0.1 22
ssh -4 -F /dev/null -o RequestTTY=no -o RemoteCommand=none USER@127.0.0.1 'hostname; id -un'

Use BatchMode=yes only when password fallback would hang or prompt.

Config

bash
sudo sshd -T 2>&1 | egrep -i '^(allowusers|denyusers|allowgroups|denygroups|listenaddress|maxstartups|logingracetime|usepam|passwordauthentication|pubkeyauthentication|authenticationmethods)'
sudo egrep -n '^[[:space:]]*(AllowUsers|DenyUsers|AllowGroups|DenyGroups|Match|MaxStartups|LoginGraceTime|ListenAddress|AuthenticationMethods|UsePAM|PasswordAuthentication|PubkeyAuthentication)\b' /etc/ssh/sshd_config /etc/ssh/sshd_config.d/* 2>/dev/null || true

Suspicious:

  • DenyUsers matching target user
  • restrictive AllowUsers / AllowGroups
  • Match block accidentally applying
  • tiny MaxStartups
  • tiny LoginGraceTime
  • ListenAddress missing target interface

Logs

bash
sudo log show --last 30m --predicate 'process == "sshd" OR process == "launchd"' --style compact | tail -160

Important Mac symptom:

  • client: kex_exchange_identification: Connection closed by remote host
  • server log: Could not create new instance of inetd service: 67: Too many processes
  • launchctl print system/com.openssh.sshd: high copy count
  • many sshd-session: USER processes parented by PID 1

This means launchd accepted TCP but refused to spawn more sshd inetd copies.

Stale sshd-session Fix

Inspect first:

bash
sudo launchctl print system/com.openssh.sshd 2>&1 | egrep 'active count|copy count|state =|last exit code|runs ='
ps -axo pid,ppid,uid,user,state,lstart,etime,comm,args | awk '/sshd-session:/ && !/awk/ {print}'
sudo lsof -nP -c sshd-session -iTCP 2>/dev/null | head -120

If stale sessions are clearly stranded and blocking new SSH, terminate by selected command-line match:

bash
ps -axo pid=,args= | awk '/sshd-session: / && !/awk/ {print $1}' | xargs sudo kill -TERM
sleep 2
ps -axo pid=,args= | awk '/sshd-session: / && !/awk/ {print}'

If TERM leaves blockers, re-check ownership and active shells before using KILL.

Firewall

Only after loopback works but remote fails:

bash
sudo /usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate
sudo /usr/libexec/ApplicationFirewall/socketfilterfw --listapps | grep -i ssh -A2 -B2 || true
sudo pfctl -sr 2>/dev/null | head -80
sudo pfctl -si 2>/dev/null | head -80

Also check listen address and target interface:

bash
ifconfig | awk '/^[a-z0-9]+:/{iface=$1; sub(":","",iface)} iface ~ /^en[0-9]+$/ && /inet / {print iface, $2}'
sudo lsof -nP -iTCP:22 -sTCP:LISTEN

OP Profile Block

If asked to ensure ~/.profile has a Codex-managed OP_SERVICE_ACCOUNT_TOKEN copied from another host:

  • verify exact variable/markers without printing value
  • copy only the matching line/block
  • redirect through a chmod 600 temp file
  • never echo the token

Presence check:

bash
awk 'BEGIN{b=0;e=0;x=0} /BEGIN Codex-managed OP_SERVICE_ACCOUNT_TOKEN/ {b=1} /END Codex-managed OP_SERVICE_ACCOUNT_TOKEN/ {e=1} /^[[:space:]]*(export[[:space:]]+)?OP_SERVICE_ACCOUNT_TOKEN=/ {x=1} END{print "marker_begin", b; print "marker_end", e; print "exact_var", x}' ~/.profile

Append from remote host:

bash
tmpfile=$(mktemp /tmp/codex-op-token.XXXXXX)
chmod 600 "$tmpfile"
ssh -o RequestTTY=no -o RemoteCommand=none HOST 'awk '\''/^[[:space:]]*(export[[:space:]]+)?OP_SERVICE_ACCOUNT_TOKEN=/ {print; exit}'\'' ~/.profile' > "$tmpfile"
if [ -s "$tmpfile" ]; then
  {
    printf '\n# BEGIN Codex-managed OP_SERVICE_ACCOUNT_TOKEN\n'
    sed -n '1p' "$tmpfile"
    printf '# END Codex-managed OP_SERVICE_ACCOUNT_TOKEN\n'
  } >> ~/.profile
fi
rm -f "$tmpfile"

Closeout

Report:

  • root cause
  • exact commands changed
  • validation output, redacted as needed
  • whether remote should retry

© steipete, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ssh-doctor of steipete/agent-scripts.

Open the folder on GitHubat commit 79150cf

Compare with similar skills

Ssh Doctor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ssh Doctor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ssh Doctor this skillsteipete/agent-scripts7.3k—~1.2kAutomated safety check: NotesMIT
Remote Compute Sshaipoch/open-science5.5k—~5.7kAutomated safety check: PassApache-2.0
Triaging Issuespytorch/pytorch104k—~4.2kAutomated safety check: PassCustom licence
Remotion Interactivityremotion-dev/remotion62k5 repos~4.8kAutomated safety check: PassCustom licence
Issue Triagepaperclipai/paperclip99k—~1kAutomated safety check: PassMIT
Triagepnpm/pnpm37k—~2.9kAutomated safety check: PassMIT

Similar skills

  • Remote Compute Ssh

    aipoch/open-science

    Evaluate and use SSH Remote Compute before choosing where to run GPU, high-memory, parallel, batch, model-inference, bioinformatics, or other long-running scientific work; supports short remote…

    5.5k GitHub stars~5.7k tokensUpdated yesterday
    Research & ScienceAuto-check passed
  • Triaging Issues

    pytorch/pytorch

    Triages GitHub issues by routing to oncall teams, applying labels, and closing questions.

    104k GitHub stars~4.2k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Remotion Interactivity

    remotion-dev/remotion

    Official

    Structure Remotion markup for interactivity. An agent skill from remotion-dev/remotion.

    62k GitHub starsUsed in 5 repos~4.8k tokens
    Media & CreativeAuto-check passed
  • Issue Triage

    paperclipai/paperclip

    Triage Paperclip inbox issues that are stale, blocked, in-review, or assigned-but-not-progressing, and decide a single next action per issue (resume, reassign, unblock, escalate, or close).

    99k GitHub stars~1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Triage

    pnpm/pnpm

    Triage an incoming GitHub issue against the pnpm codebase and related open issues, then apply exactly one implementation-readiness label using pnpm's state: taxonomy.

    37k GitHub stars~2.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Herdr Issue Triage

    herdrdev/herdr

    Triages open herdr GitHub issues into a short decision-first Markdown table with a priority light, recommendation, age, reactions and a reason for each.

    43k GitHub stars~517 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from steipete/agent-scripts

All 45 skills in this repo
  • Mac Fleet Maintenance

    steipete/agent-scripts

    Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

    7.3k GitHub stars~4.8k tokensUpdated 4 days ago
    Auto-check passed
  • Agent Transcript for PRs

    steipete/agent-scripts

    Finds a coding agent's session log, trims and redacts it, and inserts it into a GitHub PR or issue only when the user has asked for a transcript.

    7.3k GitHub starsUsed in 1 repo~698 tokens
    Auto-check passed
  • Parallels macOS VM Lab

    steipete/agent-scripts

    Uses a clean Parallels macOS VM to test GUI automation, TCC permission prompts and screenshot tools like Peekaboo, verifying results from outside the guest.

    7.3k GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • ClawSweeper Status

    steipete/agent-scripts

    Reports ClawSweeper's status with a bundled script: workflow health, active workers, queue health and recently merged, reviewed, commented and closed items.

    7.3k GitHub stars~972 tokensUpdated 4 days ago
    Auto-check passed
  • GitHub Project Triage

    steipete/agent-scripts

    Produces maintainer-facing triage cards for a project's GitHub issues and pull requests, each with its URL, risk, test state, blockers and a next action.

    7.3k GitHub stars~4k tokensUpdated 4 days ago
    Auto-check passed
  • Nano Banana Image Generation

    steipete/agent-scripts

    Generates and edits images with Google's Nano Banana 2 (Gemini 3.1 Flash Image) through a uv script, with a draft-then-final workflow and sizes from 512 to 4K.

    7.3k GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed

Questions about Ssh Doctor

What does Ssh Doctor do?

SSH triage: Remote Login, launchd sshd, pre-auth closes, stale sessions. Ssh Doctor is an agent skill from steipete/agent-scripts. SSH triage: Remote Login, launchd sshd, pre-auth closes, stale sessions.

How do I install Ssh Doctor in Claude Code?

Run `npx skills add steipete/agent-scripts --skill ssh-doctor -a claude-code`. Or copy the skill folder (skills/ssh-doctor in steipete/agent-scripts) into .claude/skills/ssh-doctor in your project. Claude Code loads it when a task matches its description.

How do I install Ssh Doctor in Codex?

Run `npx skills add steipete/agent-scripts --skill ssh-doctor -a codex`. Or copy the skill folder (skills/ssh-doctor in steipete/agent-scripts) into .agents/skills/ssh-doctor in your project. Codex loads it when a task matches its description.

Can I use Ssh Doctor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add steipete/agent-scripts --skill ssh-doctor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ssh-doctor, .gemini/skills/ssh-doctor, .github/skills/ssh-doctor and .opencode/skills/ssh-doctor in your project.

What does Ssh Doctor need to run?

Going by SKILL.md and its folder, Ssh Doctor needs the command-line tools its instructions call (ssh) and credentials named OP_SERVICE_ACCOUNT_TOKEN. Our summary lists: A credential in OP_SERVICE_ACCOUNT_TOKEN.

Does Ssh Doctor access the network?

SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ssh Doctor safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ssh Doctor use?

Ssh Doctor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ssh Doctor use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ssh Doctor?

Skills that share tags, products or a category with Ssh Doctor: Remote Compute Ssh (aipoch/open-science, 5.5k stars), Triaging Issues (pytorch/pytorch, 104k stars), Remotion Interactivity (remotion-dev/remotion, 62k stars) and Issue Triage (paperclipai/paperclip, 99k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ssh Doctor?

steipete (a GitHub user) maintains it in steipete/agent-scripts, which has 7,273 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 4, 2026.

Source: steipete/agent-scripts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.