check / check (push) Successful in 5s
`cli.Main` ran the command tree on a background context, so SIGINT, SIGTERM or SIGHUP killed the process before deferred cleanup ran: `ssh to` left its agent socket and directory behind, and `ssh install` left a copy of the host's `authorized_keys` in its working directory. `Main` now runs the tree on a `signal.NotifyContext` for those signals; the cancelled context ends the child `ssh` or `sftp` and the cleanup runs. `ssh to` stops its child with SIGTERM, not a kill, so `ssh` restores the terminal. Exit status after a signal is 1 unless `ssh` reported its own. The test re-runs the test binary as the tool, waits for the agent socket, sends each signal and checks the directory is gone. Disclosure: the repeated `"uptime"` test literal became a `remoteCommand` constant because `goconst` required it. Model: opus-4-8 (implementation, review); fable-5-1 (merge message)