These aren't used _directly_ by SSH at present, but an instance of SHAKE-256 is required by the recently standardised Ed448.