Cover passphrase injection via script(1) with env vars and the SSH_ASKPASS alternative for headless automation.
Covers keys, agent, config file, tunnels (local/remote/dynamic), file transfer (scp/rsync/sftp), escape sequences, and hardening.