Synology Backup
Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a... Skill: Synology Backup Owner: pfrederiksen Summary: Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a... Tags: latest:2.0.3 Version history: v2.0.3 | 2026-04-05T00:24:31.353Z | user Cleaned notification flow, removed hidden shell-side delivery, aligned docs with implementation, and kept backup behavior hardened
Rank
62
Safety
84
Downloads
2.6k
Updated
Oct 9, 2026
Version
2.0.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.6K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.6K downloadsadoption · observed Oct 9, 2026
- Latest release
- 2.0.3release · observed Apr 5, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17fk3ter6h1bve6rnejmqxjfx83eymx:synology-backup- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/snapshot"
Documentation
CLAWHUB
110,839 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: synology-backup
description: "Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Designed for explicit OpenClaw cron/session notifications instead of hidden shell-side delivery."
metadata:
openclaw:
requires:
bins:
- rsync
- jq
apt:
- rsync
- jq
- cifs-utils
notes: "SSH transport requires SSH key auth to Synology. SMB transport requires cifs-utils and a chmod 600 credentials file. Cron/session layer should own notifications explicitly."
---
# Synology Backup
Backup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.
## Setup
### 1. Network Connectivity
For VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:
1. Install Tailscale on the Synology (Package Center → search "Tailscale")
2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform
3. Join both to the same tailnet
4. Use the Synology's Tailscale IP in config
For local network setups, use the NAS local IP directly.
### 2. Synology Preparation
1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions
2. Create or choose a shared folder (e.g., `backups`)
3. Grant the user read/write access to **only** that folder — not admin access
### 3. Credentials File (SMB transport)
Create an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:
```bash
touch ~/.openclaw/.smb-credentials
chmod 600 ~/.openclaw/.smb-credentials
# Add two lines:
# username=<your-synology-user>
# password=<your-synology-password>
```
### 4. Configuration
Create `~/.openclaw/synology-backup.json`:
```json
{
"host": "100.x.x.x",
"share": "backups/openclaw",
"mountPoint": "/mnt/synology",
"credentialsFile": "~/.openclaw/.smb-credentials",
"smbVersion": "3.0",
"transport": "smb",
"notifyOnSuccess": false,
"backupPaths": [
"~/.openclaw/workspace",
"~/.openclaw/openclaw.json",
"~/.openclaw/cron",
"~/.openclaw/agents"
],
"backupExclude": [],
"includeSubAgentWorkspaces": true,
"retention": 7,
"preRestoreRetention": 3,
"schedule": "0 3 * * *"
}
```
**SSH transport (recommended):** Set `"transport": "ssh"` and add `"sshUser": "your-user"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.
> ⚠️ **SSH host key warning:** Scripts use `StrictHostKeyChecking=yes`. Add your NAS host key to `~/.ssh/known_hosts` first by connecting manually once (`ssh user@nasREADME.md
# Synology Backup
[](https://clawhub.ai/pfrederiksen/synology-backup)
[]()
An [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Supports Tailscale for secure remote VPS-to-NAS connectivity.
## Features
- 💾 **Incremental backup** — workspace, configs, agent data, cron jobs, sub-agent workspaces
- 🚫 **Smart exclusions** — `.git/`, `node_modules/`, `__pycache__/` excluded by default; configurable
- 🔄 **Safe restore** — automatically snapshots current state before restoring (undo in one command)
- 🔍 **Integrity verification** — checksums key files and counts directory contents
- 📊 **Status checks** — mount health, disk space, last success timestamp, snapshot inventory
- ✅ **State tracking** — records last successful backup timestamp + manifest checksum
- ⚠️ **Failure alerting** — Telegram alert on backup failure (optional success notification too)
- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh
- 🔑 **SSH/rsync transport** — alternative to SMB; key-based auth, no credentials file needed
- 🧹 **Auto-pruning** — daily snapshots and pre-restore safety snapshots pruned automatically
- 🛡️ **Security-hardened** — all config values validated, no `eval`, no shell injection possible
## Scripts
| Script | Description |
|--------|-------------|
| `backup.sh [--dry-run]` | Run incremental backup |
| `restore.sh [date]` | Restore from snapshot (lists available if no date given) |
| `status.sh` | Show mount health, last backup, snapshot inventory |
| `verify.sh [date]` | Verify snapshot integrity via checksums |
## Installation
```bash
clawhub install synology-backup
```
## Quick Setup
1. Install dependencies: `apt-get install -y cifs-utils rsync`
2. Create a dedicated Synology user with access to one share only
3. Create credentials file: `touch ~/.openclaw/.smb-credentials && chmod 600 ~/.openclaw/.smb-credentials`
4. Create config at `~/.openclaw/synology-backup.json` (see SKILL.md for full reference)
5. Test: `bash scripts/backup.sh --dry-run`
6. Register cron: `openclaw cron add --name "Synology Backup" --cron "0 3 * * *" --tz "America/Los_Angeles" --agent main --message "exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. Reply NO_REPLY."`
## Configuration
```json
{
"host": "100.x.x.x",
"share": "backups/openclaw",
"mountPoint": "/mnt/synology",
"credentialsFile": "~/.openclaw/.smb-credentials",
"smbVersion": "3.0",
"transport": "smb",
"telegramTarget": "",
"notifyOnSuccess": false,
"backupPaths": [
"~/.openclaw/workspace",
"~/.openclaw/openclaw.json",
"~/.openclaw/cron",
"~/.openclaw/agents"
],
"backupExclude": [],
"includeSubAgentWorkspaces": true,
"ret_meta.json
{
"ownerId": "kn7cvyzb78ahvv8e5888vj9r5581apwf",
"slug": "synology-backup",
"version": "2.0.3",
"publishedAt": 1775348671353
}skill-card.md
## Description: Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. This skill is ready for commercial/non-commercial use. ## Publisher: [pfrederiksen](https://clawhub.ai/user/pfrederiksen) ### License/Terms of Use: MIT-0 ## Use Case: External users, developers, and operators use this skill to configure and run Synology NAS backups for OpenClaw workspaces, inspect backup health, verify snapshots, and restore from dated backups. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The security summary reports that backups can copy secrets to the NAS outside the documented opt-in boundary. Mitigation: Keep .env and other secrets out of backupPaths unless the NAS share is restricted and encrypted; review restore behavior before restoring configuration files. Risk: The security summary reports that rsync can follow symlinks out of approved folders. Mitigation: Remove rsync --copy-links or enforce canonical symlink containment before relying on automated backups. Risk: Backup data can be exposed if NAS credentials, shares, or network access are too broad. Mitigation: Use a dedicated low-privilege NAS user, restrict the backup share, avoid public SMB exposure, run a dry run first, and pre-provision SSH host keys when using SSH transport. ## Reference(s): - [ClawHub skill listing](https://clawhub.ai/pfrederiksen/skills/synology-backup) - [Publisher profile](https://clawhub.ai/user/pfrederiksen) - [OpenClaw](https://openclaw.ai) - [Tailscale](https://tailscale.com) - [Tailscale install guide](https://tailscale.com/download) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, configuration, guidance] **Output Format:** [Markdown guidance with shell commands and JSON configuration examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Requires rsync and jq; SMB transport also requires cifs-utils and a chmod 600 credentials file.] ## Skill Version(s): 2.0.3 (source: server release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/pfrederiksen/skills/synology-backup",
"sourceUrl": "https://clawhub.ai/pfrederiksen/skills/synology-backup",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T13:16:08.313Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T13:16:08.313Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.6K downloads",
"href": "https://clawhub.ai/pfrederiksen/synology-backup",
"sourceUrl": "https://clawhub.ai/pfrederiksen/synology-backup",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T13:16:08.313Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.0.3",
"href": "https://clawhub.ai/pfrederiksen/synology-backup",
"sourceUrl": "https://clawhub.ai/pfrederiksen/synology-backup",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-05T00:24:31.353Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.0.3",
"description": "Cleaned notification flow, removed hidden shell-side delivery, aligned docs with implementation, and kept backup behavior hardened for safer cron-owned alerts.",
"href": "https://clawhub.ai/pfrederiksen/synology-backup",
"sourceUrl": "https://clawhub.ai/pfrederiksen/synology-backup",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-05T00:24:31.353Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
