Yeah I was thinking of something like that. But I still feel a bit uneasy with configuring OpenSSH securely, I’ve escaped such setups before, gaining full shell access through exploits. Maybe I’m overly paranoid.
Then again many programs aren’t secure against untrusted input either.