At the end of last year I wrote about jailexec, my Ansible connection plugin that manages FreeBSD jails by SSHing to the jail host and running everything through jexec. That article has a section called Security Design. It proudly explains the two-stage file transfer: upload to a temporary location on the host, then move it into the jail with privilege escalation.