Awesome. How many people have reviewed it for flaws? How many people have reviewed OpenSSH?
This library does not protect against timing attacks.
Do not allow attackers to measure how long it takes you
to generate a keypair or sign a message. This library
depends upon a strong source of random numbers. Do not
use it on a system where os.urandom() is weak.
I'm not saying Paramiko (or its patch sets) are insecure, just pointing out that the same arguments can be made against the libraries and code that Ansible is based on.So, don't use it in the cloud? [1]
The other big win for me is I can read their code, I understand python & have a number of items I'll be able to contribute to upstream that will help others use the product.
(Then again, that's how it usually goes anyway.)