When using logins without a password for SSH connections, the following are disabled: - access from IP addresses that do not require access - port forwarding - agent credential forwarding - X11 forwarding - console access.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.