truenas-aiops
Use this skill whenever the user needs to operate TrueNAS SCALE storage — a one-shot health overview, system info, read-only diagnostics / RCA (pool health, alerts & dataset capacity), inspect ZFS pools (list/get/status, capacity, scrub status, start a scrub), datasets (list/get/create), snapshots (list/create/delete), physical disks and S.M.A.R.T. self-test results, system alerts, services (list/restart), and replication / cloud-sync tasks. Always use this skill for "list truenas pools", "truenas dataset", "create zfs snapshot", "start a scrub", "diagnose truenas pool health", "why is my pool degraded", "truenas disk health", "truenas smart test", "truenas alerts", "restart truenas service", or "truenas replication" when the context is explicitly TrueNAS / TrueNAS SCALE / a ZFS NAS appliance. Do NOT use when the target is not a TrueNAS SCALE appliance — other NAS/storage products, backup software, hypervisor VM lifecycle, container clusters, and network devices are out of scope (negative routing hints only). Common TrueNAS SCALE operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). Live-verified against real TrueNAS SCALE 25.04 and 26 appliances over both transports; see docs/VERIFICATION.md for what is and is not covered.
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
0.11.5
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.11.5release · observed Sep 16, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:truenas-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:truenas-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/truenas-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-truenas-aiops/snapshot"
Documentation
CLAWHUB
150,018 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: truenas-aiops
slug: truenas-aiops
displayName: "TrueNAS AIops"
summary: "Governed TrueNAS SCALE storage ops — 25 MCP tools with audit, budget, undo guards."
license: MIT
homepage: https://github.com/AIops-tools/TrueNAS-AIops
tags: [aiops, mcp, governance, truenas]
description: >
Use this skill whenever the user needs to operate TrueNAS SCALE storage — a one-shot health overview, system info, read-only diagnostics / RCA (pool health, alerts & dataset capacity), inspect ZFS pools (list/get/status, capacity, scrub status, start a scrub), datasets (list/get/create), snapshots (list/create/delete), physical disks and S.M.A.R.T. self-test results, system alerts, services (list/restart), and replication / cloud-sync tasks.
Always use this skill for "list truenas pools", "truenas dataset", "create zfs snapshot", "start a scrub", "diagnose truenas pool health", "why is my pool degraded", "truenas disk health", "truenas smart test", "truenas alerts", "restart truenas service", or "truenas replication" when the context is explicitly TrueNAS / TrueNAS SCALE / a ZFS NAS appliance.
Do NOT use when the target is not a TrueNAS SCALE appliance — other NAS/storage products, backup software, hypervisor VM lifecycle, container clusters, and network devices are out of scope (negative routing hints only).
Common TrueNAS SCALE operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). Live-verified against real TrueNAS SCALE 25.04 and 26 appliances over both transports; see docs/VERIFICATION.md for what is and is not covered.
installer:
kind: uv
package: truenas-aiops
argument-hint: "[pool/dataset/snapshot id or describe your TrueNAS task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["truenas-aiops","uvx"]},"optional":{"env":["TRUENAS_AIOPS_CONFIG","TRUENAS_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/TrueNAS-AIops","emoji":"🗄️","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed TrueNAS SCALE storage operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.
All write operations are audited to a local SQLite DB under ~/.truenas-aiops/ (relocatable via TRUENAS_AIOPS_HOME).
Credentials: Each TrueNAS target's API key is stored ENCRYPTED in ~/.truenas-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'truenas-aiops init' to onboard, or 'truenas-aiops secret set <target>' to add one (create the key in the TrueNAS UI: Credentials → API Keys). The store is unlocked by a master password from TRUENAS_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var TRUENAS_<TARGET_NAME_UPPER>_APIKEY is still honoured as a fallback with a deprecation warning (migrate with 'truenas-aiops secret migrate'). The API key is sent as an Authorization: Bearer header at request t_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "truenas-aiops",
"version": "0.11.5",
"publishedAt": 1789601199051
}references/agent-guardrails.md
# Agent guardrails — running truenas-aiops with a smaller / local model
If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.
The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.
## Authorization is not this tool's job — decide it where it belongs
Whether a write should happen is your decision, or the account's. The tool does
not gate it — there is no read-only switch and no approval prompt to configure.
The two right places to control read vs write:
- **The account you connect with.** Scope the TrueNAS API key to a
limited-privilege account (the key inherits its user's permissions). A write
then fails at the appliance, which is the only place the permission actually
lives — a revoked permission cannot be argued around by a model, but a
skill-side flag can.
- **Your agent's system prompt.** If you want an observe-only session, tell the
model not to call the write tools (they are clearly tagged `[WRITE]`).
What the tool *does* guarantee is that you can always see what happened:
## What the tool enforces — do not waste prompt budget on these
| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Don't invent a value when a field is missing" | A field the TrueNAS middleware did not return comes back as `null`, never as `""`. Absent and empty are distinguishable in the payload — a disk with no `serial`, a dataset with no `mountpoint`, a replication task with no `state` all report `null`. |
| "Tell me if the output was cut off" | `snapshot_list` returns `{"snapshots": [...], "returned": N, "limit": L, "truncated": true/false}` and `undo_list` the same shape under `undos`. Truncation is measured, not guessed from a length coincidence. This matters most for snapshots: a periodic snapshot task retaining hourly/daily/weekly across a few datasets produces thousands of rows. |
| "Preserve the ordering / tell me what's most urgent" | `pool_health_rca` and `alert_and_capacity_rca` findings carry an explicit 1-based `rank`, worst-first. Priority is in the payload, not implied by list position. |
| "Confirm before anything destructive" | `snapshot delete` and `service restart` at the CLI require a `--dry-run`-able preview plus double confirmation. `snapshot_delete` captures the BEFORE state for the audit record. |
| "Log what you did" | Every governed call is audited to `~/.truenas-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. `snapshot_create` additionally records a replayable inverse undo token. |
| "Don't get stuck retrreferences/capabilities.md
# truenas-aiops capabilities
> 25 MCP tools (19 read, 6 write). Routes are resolved against the appliance's
> own method list and were cross-checked on live TrueNAS SCALE 25.04 and 26
> appliances; see docs/VERIFICATION.md for what remains unverified.
## Read tools (19)
| Tool | REST (modelled) | Returns |
|------|----------------|---------|
| `overview` | fan-out | pools (capacity/health), alerts by level, running services |
| `system_info` | `GET /system/info` | version, hostname, memory, cores, uptime |
| `pool_health_rca` | `GET /pool` | worst-first findings: bad ZFS state, read/write/checksum/scan error counts, capacity over 80%/90% |
| `alert_and_capacity_rca` | `POST /alert/list` + `GET /pool/dataset` | worst-first findings: active alerts by level + datasets near quota/available ceiling |
| `pool_list` | `GET /pool` | id, name, status, healthy, size/allocated/free |
| `pool_get` | `GET /pool/id/{id}` | single pool detail |
| `pool_status` | `GET /pool/id/{id}` | health + scan + topology summary |
| `scrub_status` | `GET /pool/id/{id}` | scrub function/state/percentage |
| `pool_capacity` | `GET /pool` | size/allocated/free + used% per pool |
| `dataset_list` | `GET /pool/dataset` | id, name, type, pool, used/available |
| `dataset_get` | `GET /pool/dataset/id/{id}` | single dataset detail |
| `snapshot_list` | `GET /zfs/snapshot` | `{snapshots, returned, limit, truncated}` — id, dataset, name, used (opt. filter by dataset; default limit 200) |
| `disk_list` | `GET /disk` | name, serial, model, size, pool |
| `smart_test_results` | `GET /smart/test/results` | latest S.M.A.R.T. self-test per disk |
| `alert_list` | `POST /alert/list` | level, message, class, dismissed |
| `service_list` | `GET /service` | name, state (RUNNING/STOPPED), enable |
| `replication_list` | `GET /replication` | name, direction, transport, state (PENDING/RUNNING/FINISHED/ERROR, never absent), error, lastSnapshot, lastRun |
| `cloudsync_list` | `GET /cloudsync` | description, direction, path, state (the last run's job state; null until it runs) |
| `undo_list` | governance store | recorded reversible writes / not-yet-applied undo tokens |
## Write tools (6)
| Tool | Risk | REST (modelled) | Undo / safety |
|------|------|----------------|---------------|
| `pool_scrub_start` | medium | `POST /pool/scrub/run` | captures prior scan state; no undo (non-destructive); `dry_run` |
| `dataset_create` | medium | `POST /pool/dataset` | no undo (deletion out of scope); `dry_run` |
| `snapshot_create` | medium | `POST /zfs/snapshot` | records inverse `snapshot_delete` undo descriptor; `dry_run` |
| `snapshot_delete` | **high** | `DELETE /zfs/snapshot/id/{id}` | captures BEFORE state; IRREVERSIBLE, no undo; CLI double-confirm + `dry_run` |
| `service_restart` | medium | `POST /service/restart` | captures prior state; no undo; refuses a name absent from `service_list`, and refuses `ssh` without `confirm=True` (out-of-band recovery path); guards also fire under `dry_run`; CLIreferences/cli-reference.md
# truenas-aiops CLI reference > Exercised against live TrueNAS SCALE 25.04 and 26 appliances over both the > REST and WebSocket transports; see docs/VERIFICATION.md for the gaps. ## Setup & diagnostics ```bash truenas-aiops init # interactive onboarding wizard truenas-aiops doctor [--skip-auth] # config + secret store + connectivity (/system/info) truenas-aiops mcp # start the MCP server (stdio transport) ``` ## Secrets (encrypted store ~/.truenas-aiops/secrets.enc) ```bash truenas-aiops secret set <target> [--value <key>] # store API key (hidden prompt if no --value) truenas-aiops secret list # names only — values never shown truenas-aiops secret rm <target> truenas-aiops secret migrate # import legacy plaintext .env (TRUENAS_<T>_APIKEY) truenas-aiops secret rotate-password # re-encrypt under a new master password ``` ## Read commands ```bash truenas-aiops overview [--target <t>] # pools (capacity/health), alerts by level, running services truenas-aiops system [--target <t>] # version / hostname / memory / cores / uptime truenas-aiops diagnose pool-health # RCA: pool state / error counters / capacity (worst first) truenas-aiops diagnose alerts # RCA: active alerts by level + datasets near full truenas-aiops pool list truenas-aiops pool get <pool_id> truenas-aiops pool status <pool_id> # health + scan + topology summary truenas-aiops pool scrub-status <pool_id> truenas-aiops pool capacity # size / allocated / free / used% per pool truenas-aiops dataset list truenas-aiops dataset get <dataset_id> # e.g. tank/data truenas-aiops snapshot list [--dataset <tank/data>] [--limit 200] truenas-aiops disk list truenas-aiops disk smart # S.M.A.R.T. self-test results per disk truenas-aiops alert list truenas-aiops service list truenas-aiops replication list truenas-aiops replication cloudsync ``` ## Write commands (governed; risk tier in parentheses) ```bash truenas-aiops pool scrub-start <pool_name> # (medium) start an integrity scrub truenas-aiops dataset create <tank/path> [--dry-run] # (medium) create a ZFS dataset truenas-aiops snapshot create <dataset> <name> # (medium) records inverse snapshot_delete undo truenas-aiops snapshot delete <dataset@name> [--dry-run] # (high) double confirm — IRREVERSIBLE truenas-aiops service restart <service> [--dry-run] # (medium) double confirm — smb/nfs/ssh/... ``` ## Common options - `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target) - `--dry-run` — print the API call that would be made, change nothing - Destructive commands (`snapshot delete`, `service restart`) require two confirmations
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/truenas-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/truenas-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T08:08:26.358Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-truenas-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-truenas-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T08:08:26.358Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/zw008/truenas-aiops",
"sourceUrl": "https://clawhub.ai/zw008/truenas-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T08:08:26.358Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.11.5",
"href": "https://clawhub.ai/zw008/truenas-aiops",
"sourceUrl": "https://clawhub.ai/zw008/truenas-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T23:26:39.051Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-truenas-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-truenas-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.11.5",
"description": "Version 0.11.5 - Updated references/agent-guardrails.md with new or revised content. - Removed skill-card.md from the project.",
"href": "https://clawhub.ai/zw008/truenas-aiops",
"sourceUrl": "https://clawhub.ai/zw008/truenas-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T23:26:39.051Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
