Linux Security Guardian
Autonomous multi-client Linux server security management via SSH MCP. Runs full audit at 1 AM IST nightly via cron. Iterates over all clients and their serve... Skill: Linux Security Guardian Owner: cyber-bye Summary: Autonomous multi-client Linux server security management via SSH MCP. Runs full audit at 1 AM IST nightly via cron. Iterates over all clients and their serve... Tags: latest:1.6.0 Version history: v1.6.0 | 2026-07-14T10:06:54.523Z | user v1.6.0 — 8 new audit modules (19-26), 5 enhanced modules, backup-restore hook - New: 19-cis-scoring (CIS benchmark alignment
Rank
62
Safety
84
Downloads
1.3k
Updated
Oct 10, 2026
Version
1.6.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.3K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.6.0release · observed Jul 14, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s176ths3s2f0frn4xsrfq480h584nvaj:linux-security-guardian- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-cyber-bye-linux-security-guardian/snapshot"
Documentation
CLAWHUB
155,638 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: linux-security-guardian
description: Autonomous multi-client Linux server security management via SSH MCP. Runs full audit at 1 AM IST nightly via cron. Iterates over all clients and their server fleets. Covers system hardening, CVE scanning (CISA KEV + OSV.dev + NVD API), user auditing, SSH config (incl. weak ciphers/MACs/Kex), firewall rules, running services, file permissions, log analysis, SSL certs, kernel parameters (incl. BPF restrictions), Docker daemon security defaults (userns-remap, no-new-privileges, seccomp), fail2ban auto-install, unattended-upgrades auto-enable, CIS benchmark scoring, systemd sandbox analysis, AppArmor/SELinux audit, and swap encryption check. Non-breaking actions auto-applied. Critical patches and network/firewall changes require owner confirmation. Report sent per-server and per-client via email plugin/skill (not bundled). All owner-specific config lives in core-extra/config/ — no hardcoded names, domains, or emails.
version: 1.6.0
metadata: {"openclaw": {"emoji": "🛡️", "requires": {"bins": ["bash","python3","ss","iptables","systemctl","grep","awk","sed","find","curl"], "mcp": ["ssh_conn","ssh_exec"]}}}
---
# Linux Security Guardian
## ⚡ SSH MCP — REQUIRED DEPENDENCY
> **SSH MCP is a hard dependency. The agent MUST have SSH MCP tools available to operate.**
> No local/legacy fallback. All operations go through SSH MCP.
### Prerequisite
```yaml
# SSH MCP server must be running and accessible
dependency: ssh_mcp
status: required # if unavailable → ABORT, alert owner
```
### Server Profile Config
Each target server needs a saved connection in SSH MCP database. Configure in `SERVER_PROFILE.md`:
```yaml
ssh_mcp:
connection_id: "<id-name-or-alias-from-ssh-conn-list>" # Saved connection ID, Name, or Alias
# OR inline config:
# host: "<server-ip>"
# port: 22
# username: "<user>"
# key_path: "</path/to/key>"
```
### Audit Modules
All 26 modules execute commands via SSH MCP. Each module file lists commands that get wrapped with `ssh_exec(op="run", sessionId, command)`:
```
module command → ssh_exec(op="run", sessionId, command="module command")
→ ssh_exec(op="logs", commandId=cmdId)
→ parse output
```
### CVE Scan
The external CVE scan runs locally (on the guardian host) using curl to CISA KEV, OSV.dev, and NVD API.
Usage requires `--client` and `--server` to write results to per-server paths:
```bash
bash cve/cve-scan.sh --client "client-1" --server "server-01"
# Writes results to:
# cve/<client>/<server>/scan-results/YYYY-MM-DD.md
# cve/<client>/<server>/advisories/<CVE-ID>.md
```
Steps:
```bash
# 1. SSH MCP: ssh_exec(op="run", sessionId, command="dpkg-query -W ...") → save locally
# 2. Read from cve/<client>/<server>/scan-results/installed-packages.txt
# 3. curl CISA KEV → filter Linux entries → write advisories
# 4. curl POST OSV.dev batch → match packages → write advisories
# 5. curl NVD API (optional) → cross-check → write advisories
```
---_meta.json
{
"ownerId": "kn79djxt41q03wtr3nth5h8y8184mgcm",
"slug": "linux-security-guardian",
"version": "1.6.0",
"publishedAt": 1784023614523
}AGENT.md
---
name: linux-security-guardian-agent
description: Behavioral rules for linux-security-guardian. Multi-client, SSH MCP hard dependency, safe-first actions, mandatory confirmations for critical changes, complete audit coverage.
---
# Agent Rules — Linux Security Guardian
## THE PRIME RULE — SAFE FIRST
When in doubt about whether an action is safe: DON'T DO IT.
Log it. Alert owner. Wait for explicit approval.
A delayed fix is always better than an accidental outage.
---
## Rule 1 — SSH MCP Hard Dependency
SSH MCP is a hard dependency. The agent MUST have SSH MCP tools available to operate.
```yaml
required_tools: [ssh_conn, ssh_exec]
version: v2 # 13 tools: ssh_conn, ssh_exec, ssh_bulk_exec, ssh_bulk_audit, ssh_client, etc.
```
If SSH MCP tools are unavailable → ABORT audit, alert owner: "SSH MCP not available".
No local/legacy fallback. All operations go through SSH MCP.
---
## Rule 2 — Multi-Client Audit Flow
SERVER_PROFILE.md contains one or more `## Client:` sections.
The audit MUST iterate over ALL clients and ALL servers:
```
for each client in SERVER_PROFILE.md:
for each server in client.server_fleet:
ssh_conn → test/save connection if needed
ssh_exec(op="open", connectionId) → sessionId
Run all 26 modules via ssh_exec(op="run", sessionId, ...)
Compile per-server findings → audit/results/<client>/<server>/<severity>/
Compile per-server report → reports/<client>/<server>/daily/YYYY-MM-DD.md
ssh_exec(op="close", sessionId)
Compile per-client summary
Append master report
Send via default email account
```
---
## Rule 3 — Email Account Selection
- **Default account**: Used for ALL outgoing reports and alerts.
- **Admin account**: Personal account. NEVER use for automated reports.
- Rule: Always use default account. Never specify `--account admin`.
- Check available accounts: `himalaya account list` (identify default vs admin).
- If no email plugin available → log to AUDIT_LOG.md, report is on disk. Non-fatal.
---
## Rule 4 — Read SERVER_PROFILE.md Before Every Audit
Load SERVER_PROFILE.md at audit start.
Parse each `## Client:` section. Extract server fleet table.
Expected ports, services, users, SUID list — all per-server from this file.
Deviation from profile = finding.
Profile not filled = abort audit, alert owner.
---
## Rule 5 — Auto-Actions Whitelist Only
Agent can ONLY auto-execute actions listed in SERVER_PROFILE.md under `Auto-Actions Allowed`.
Anything not explicitly whitelisted → queue for confirmation.
No exceptions. Owner preference > agent judgment.
Auto-action execution:
1. Run pre-action safety check (hooks/pre-action.md)
2. Execute action via SSH MCP
3. Verify result (hooks/post-action.md)
4. Log to actions/<client>/<server>/auto-done/
5. Include in email report
---
## Rule 6 — Confirmation Queue Protocol
When action requires confirmation:
1. Generate unique ID: `ACT-YYYYMMDD-NNN`
2. Write to actions/<client>/<server>/pending-confirm/<id>-<slug>.md
3. Include in email reporAUDIT_LOG.md
# Audit Log *Append-only. One entry per audit run.* ---
audit/modules/01-system.md
# Module 01 — System Info ## Commands ```bash uname -r # kernel version uname -a # full kernel info lsb_release -a 2>/dev/null # OS info cat /etc/os-release # OS info fallback uptime -p # uptime last reboot | head -5 # reboot history df -h # disk usage free -h # memory nproc # CPU count cat /proc/cpuinfo | grep "model name" | head -1 timedatectl # NTP sync status ``` ## Checks & Findings ### OS EOL Check - Ubuntu 20.04 LTS → EOL April 2025 → if still running: HIGH finding - Ubuntu 22.04 LTS → EOL April 2027 → OK - Ubuntu 24.04 LTS → EOL April 2029 → OK - Debian 11 → EOL June 2026 → OK - Debian 10 → EOL June 2024 → HIGH if still running ### Kernel Version Check - Compare against latest stable for the distro - More than 2 major versions behind → HIGH - Security patch available → MEDIUM ### NTP Sync - timedatectl | grep "NTP service: active" → PASS - NTP not synced → MEDIUM (time drift breaks certs/logs) ### Disk Usage - < 80% → PASS - 80-85% → LOW - 85-95% → WARNING - > 95% → CRITICAL (auto-alert) ### Last Reboot - No reboot in > 90 days with kernel updates pending → MEDIUM - Server rebooted unexpectedly (not matching known maintenance) → HIGH ## Output Format ``` [PASS/FINDING] 01-system: <check> | <result> ```
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/cyber-bye/skills/linux-security-guardian",
"sourceUrl": "https://clawhub.ai/cyber-bye/skills/linux-security-guardian",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T17:55:01.674Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-cyber-bye-linux-security-guardian/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-cyber-bye-linux-security-guardian/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T17:55:01.674Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.3K downloads",
"href": "https://clawhub.ai/cyber-bye/linux-security-guardian",
"sourceUrl": "https://clawhub.ai/cyber-bye/linux-security-guardian",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T17:55:01.674Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.6.0",
"href": "https://clawhub.ai/cyber-bye/linux-security-guardian",
"sourceUrl": "https://clawhub.ai/cyber-bye/linux-security-guardian",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-14T10:06:54.523Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-cyber-bye-linux-security-guardian/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-cyber-bye-linux-security-guardian/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.6.0",
"description": "v1.6.0 — 8 new audit modules (19-26), 5 enhanced modules, backup-restore hook - New: 19-cis-scoring (CIS benchmark alignment %) - New: 20-systemd-analyze (per-service sandboxing, exposure scoring) - New: 21-mount-hardening (noexec/nosuid/nodev enforcement) - New: 22-apparmor-selinux (MAC enforcement, process confinement) - New: 23-proc-hidepid (/proc visibility isolation) - New: 24-swap-encryption (LUKS/dm-crypt verification) - New: 25-usbguard (USB device authorization) - New: 26-ipv6-audit (RA/redirect/NDP hardening) - Enhanced: 03-ssh (weak ciphers/MACs/Kex CIS checks) - Enhanced: 04-auth (fail2ban auto-install, password policy) - Enhanced: 06-packages (unattended-upgrades auto-enable) - Enhanced: 11-kernel (BPF restrictions) - Enhanced: 15-docker (daemon.json security defaults) - Added: hooks/backup-restore.sh - Preserved: core-extra config system intact",
"href": "https://clawhub.ai/cyber-bye/linux-security-guardian",
"sourceUrl": "https://clawhub.ai/cyber-bye/linux-security-guardian",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-14T10:06:54.523Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
