Give your agent a limited account on machines you own
SSH connects your agent to servers you already run. It executes commands, reads files and service logs, checks and restarts services, and moves files in and out. Several machines can sit on one agent, each with its own working directory, its own approval policy and its own safety mode, so a request lands on the right box instead of being guessed at. The read-only tools are declared read-only, which is what makes an unattended morning health report possible without handing anything permission to change. What bounds the agent is the SSH account you create for it: a restricted user and a narrow sudoers list, never root. The guard in front of the shell stops accidents and the approval gate makes a person say yes to one specific command, but the account on the far side is the real boundary, and the setup text says so where you can read it.
Features
What you can ask
Frequently Asked Questions
Try the SSH skill
Add this skill to your agents and start using it right away.

