I think that you can do this with remote port forwarding on the first host.
What I'd like to be able to do is to use winSCP to connect to one server with a strict host allow file, then to open a second connection to another server that can be reached from the first one.