{"id":"edac2fae-e083-4719-8b36-c32fce976a0d","entityType":"agent","slug":"clawhub-pfrederiksen-synology-backup","name":"Synology Backup","canonicalUrl":"https://www.xpersona.co/agent/clawhub-pfrederiksen-synology-backup","canonicalPath":"/agent/clawhub-pfrederiksen-synology-backup","generatedAt":"2026-10-10T03:35:13.815Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T13:16:08.313Z","emptyReason":null},"description":"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a... Skill: Synology Backup Owner: pfrederiksen Summary: Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a... Tags: latest:2.0.3 Version history: v2.0.3 | 2026-04-05T00:24:31.353Z | user Cleaned notification flow, removed hidden shell-side delivery, aligned docs with implementation, and kept backup behavior hardened","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.6K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17fk3ter6h1bve6rnejmqxjfx83eymx:synology-backup","sourceUrl":"https://clawhub.ai/pfrederiksen/synology-backup","homepage":"https://clawhub.ai/pfrederiksen/skills/synology-backup","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/pfrederiksen/synology-backup","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/pfrederiksen/skills/synology-backup","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":59,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T13:16:08.313Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T13:16:08.313Z","emptyReason":null},"stars":null,"forks":null,"downloads":2578,"packageName":null,"latestVersion":"2.0.3","tractionLabel":"2.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T13:16:08.312Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T13:16:08.313Z","lastCrawledAt":"2026-10-09T13:16:08.312Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T13:16:08.313Z","lastVerifiedAt":null,"highlights":[{"version":"2.0.3","createdAt":"2026-04-05T00:24:31.353Z","changelog":"Cleaned notification flow, removed hidden shell-side delivery, aligned docs with implementation, and kept backup behavior hardened for safer cron-owned alerts.","fileCount":9,"zipByteSize":18781},{"version":"2.0.2","createdAt":"2026-04-02T17:01:39.488Z","changelog":"Security hardening: StrictHostKeyChecking=yes in all scripts (was accept-new), add metadata.requires declaring rsync/jq/cifs-utils dependencies for registry scanners","fileCount":8,"zipByteSize":17641},{"version":"2.0.1","createdAt":"2026-04-02T16:57:39.123Z","changelog":"Docs: address security review findings — document jq dependency, Telegram alert mechanism (no bot token stored), SSH accept-new host key warning, .env exclusion rationale, dry-run recommendation before enabling cron","fileCount":8,"zipByteSize":17556},{"version":"2.0.0","createdAt":"2026-04-02T16:54:34.843Z","changelog":"Fix fragile rsync: --copy-links to dereference symlinks (fixes SMB I/O errors on symlinked files), continue past per-path failures instead of aborting, mount retry with health check, detailed failure alerts showing which paths failed","fileCount":8,"zipByteSize":16899},{"version":"1.2.1","createdAt":"2026-03-25T23:38:15.896Z","changelog":"- Improved backup logging: now prints a summary table after each backup run, including status, snapshot date, and result for easier tracking. - Enhanced error handling in backup.sh to ensure clearer exit codes and failure alerts. - Refactored code in scripts/backup.sh and scripts/lib.sh for reliability and maintainability. - No changes to configuration or usage required.","fileCount":8,"zipByteSize":14231},{"version":"1.2.0","createdAt":"2026-03-25T23:36:25.465Z","changelog":"- Adds support for excluding files/folders via backupExclude config field. - Adds preRestoreRetention setting to control how long pre-restore safety snapshots are kept. - Option to send Telegram notification on successful backups with notifyOnSuccess. - Expanded and clarified SSH transport configuration (sshHost, sshPort, sshDest). - Always excludes .git/ and node_modules/ from backups to save space and improve speed.","fileCount":8,"zipByteSize":14128},{"version":"1.1.5","createdAt":"2026-03-25T21:15:31.418Z","changelog":"synology-backup 1.1.5 - Updated scripts/backup.sh (details not specified). - No changes to documented usage or configuration. - SKILL.md unchanged except for this release record.","fileCount":8,"zipByteSize":12152},{"version":"1.1.4","createdAt":"2026-03-25T21:14:10.097Z","changelog":"- Internal improvements to scripts/lib.sh for reliability or maintainability. - No user-facing changes or modifications to documentation or behavior.","fileCount":8,"zipByteSize":12091}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17fk3ter6h1bve6rnejmqxjfx83eymx:synology-backup","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T03:35:13.812Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pfrederiksen-synology-backup/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T13:16:08.313Z","emptyReason":null},"readme":"Skill: Synology Backup\n\nOwner: pfrederiksen\n\nSummary: Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a...\n\nTags: latest:2.0.3\n\nVersion history:\n\nv2.0.3 | 2026-04-05T00:24:31.353Z | user\n\nCleaned notification flow, removed hidden shell-side delivery, aligned docs with implementation, and kept backup behavior hardened for safer cron-owned alerts.\n\nv2.0.2 | 2026-04-02T17:01:39.488Z | user\n\nSecurity hardening: StrictHostKeyChecking=yes in all scripts (was accept-new), add metadata.requires declaring rsync/jq/cifs-utils dependencies for registry scanners\n\nv2.0.1 | 2026-04-02T16:57:39.123Z | user\n\nDocs: address security review findings — document jq dependency, Telegram alert mechanism (no bot token stored), SSH accept-new host key warning, .env exclusion rationale, dry-run recommendation before enabling cron\n\nv2.0.0 | 2026-04-02T16:54:34.843Z | user\n\nFix fragile rsync: --copy-links to dereference symlinks (fixes SMB I/O errors on symlinked files), continue past per-path failures instead of aborting, mount retry with health check, detailed failure alerts showing which paths failed\n\nv1.2.1 | 2026-03-25T23:38:15.896Z | auto\n\n- Improved backup logging: now prints a summary table after each backup run, including status, snapshot date, and result for easier tracking.\n- Enhanced error handling in backup.sh to ensure clearer exit codes and failure alerts.\n- Refactored code in scripts/backup.sh and scripts/lib.sh for reliability and maintainability.\n- No changes to configuration or usage required.\n\nv1.2.0 | 2026-03-25T23:36:25.465Z | auto\n\n- Adds support for excluding files/folders via backupExclude config field.\n- Adds preRestoreRetention setting to control how long pre-restore safety snapshots are kept.\n- Option to send Telegram notification on successful backups with notifyOnSuccess.\n- Expanded and clarified SSH transport configuration (sshHost, sshPort, sshDest).\n- Always excludes .git/ and node_modules/ from backups to save space and improve speed.\n\nv1.1.5 | 2026-03-25T21:15:31.418Z | auto\n\nsynology-backup 1.1.5\n\n- Updated scripts/backup.sh (details not specified).\n- No changes to documented usage or configuration.\n- SKILL.md unchanged except for this release record.\n\nv1.1.4 | 2026-03-25T21:14:10.097Z | auto\n\n- Internal improvements to scripts/lib.sh for reliability or maintainability.\n- No user-facing changes or modifications to documentation or behavior.\n\nv1.1.3 | 2026-03-25T21:11:55.465Z | auto\n\nsynology-backup v1.1.3\n\n- Minor update to scripts/lib.sh.  \n- No changes to usage, configuration, or feature set.  \n- Documentation remains unchanged except for possible small edits.  \n- No impact on existing backups or compatibility.\n\nv1.1.2 | 2026-03-25T21:10:33.525Z | auto\n\n- Updated documentation to clarify configuration details and improve setup instructions.\n- Changed the example `telegramTarget` value from a hardcoded group ID to a placeholder (`-100xxxxxxxxxx`) for better security and clarity.\n- Fixed commands in the cron registration example to use `~` for home directory instead of absolute `/root/` paths.\n- Updated configuration table to refine default values and descriptions, especially for `telegramTarget`.\n- No changes to the skill logic or functionality; documentation only.\n\nv1.1.1 | 2026-03-25T21:09:51.075Z | auto\n\n- Updated the failure alert example to use placeholders for hostname and date instead of specific values.\n- Removed default Telegram alert target group reference from documentation.\n- No changes to functionality; documentation only.\n\nv1.1.0 | 2026-03-25T21:05:17.654Z | auto\n\n**Adds SSH/rsync transport, integrity verification, and failure alerting via Telegram.**\n\n- SSH/rsync can now be used as an alternative to SMB for backups.\n- New `verify.sh` script checks backup integrity with checksums and counts.\n- Backup failures automatically trigger a Telegram alert (configurable target).\n- Pre-restore safety snapshots are created before restoring, enabling quick undo.\n- Enhanced validation, security notes, and improved modular code via new `lib.sh`.\n\nv1.0.4 | 2026-02-20T00:53:42.989Z | user\n\nSecurity hardening: added regex validation for share (alphanumeric/slashes only), mountPoint (absolute path only), and backupPaths (no command substitution, semicolons, pipes, backticks, or path traversal). Added boolean validation for includeSubAgentWorkspaces. Restore workspace names validated against strict pattern. All config inputs now validated before any shell command execution.\n\nv1.0.3 | 2026-02-20T00:50:34.030Z | user\n\nSecurity fix: hardened all scripts against shell injection. All config-derived variables are now quoted, validated with regex allowlists (host, smbVersion, date format), and read via safe loops instead of command substitution expansion. Added path traversal protection in restore.\n\nv1.0.2 | 2026-02-20T00:46:01.261Z | user\n\nSecurity hardening: removed curl-pipe-sh install pattern (link to official docs instead), made .env backup opt-in not default, replaced rm -rf prune with trash-then-clean pattern, added guidance for minimal NAS user permissions.\n\nv1.0.1 | 2026-02-20T00:44:37.370Z | user\n\nFix: removed example credential patterns that triggered security scanner. Credentials setup now uses editor instructions instead of inline examples.\n\nv1.0.0 | 2026-02-20T00:37:31.164Z | user\n\nInitial release: backup, restore, status scripts. SMB over Tailscale. Config-driven with credentials file auth. 7-day retention with auto-prune.\n\nArchive index:\n\nArchive v2.0.3: 9 files, 18781 bytes\n\nFiles: README.md (4003b), scripts/backup.sh (12053b), scripts/lib.sh (11246b), scripts/restore.sh (4100b), scripts/status.sh (3529b), scripts/verify.sh (3037b), skill-card.md (2325b), SKILL.md (8842b), _meta.json (134b)\n\nFile v2.0.3:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Designed for explicit OpenClaw cron/session notifications instead of hidden shell-side delivery.\"\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - rsync\n        - jq\n      apt:\n        - rsync\n        - jq\n        - cifs-utils\n      notes: \"SSH transport requires SSH key auth to Synology. SMB transport requires cifs-utils and a chmod 600 credentials file. Cron/session layer should own notifications explicitly.\"\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (recommended):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n> ⚠️ **SSH host key warning:** Scripts use `StrictHostKeyChecking=yes`. Add your NAS host key to `~/.ssh/known_hosts` first by connecting manually once (`ssh user@nas-ip`) before automation.\n\n**Sensitive files:** The `.env` file (containing API keys) is **excluded by default**. Only add it to `backupPaths` if your NAS share is restricted to a dedicated low-privilege user and encrypted at rest. When in doubt, leave it out — you can always re-enter API keys from scratch.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of daily snapshots to keep | `7` |\n| `preRestoreRetention` | Days to keep pre-restore safety snapshots | `3` |\n| `backupExclude` | rsync exclude patterns (`.git/`, `node_modules/` always excluded) | `[]` |\n| `notifyOnSuccess` | Write success state and allow higher-level success reporting if desired | `false` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n| `sshUser` | SSH username (required for ssh transport) | — |\n| `sshHost` | SSH hostname (defaults to `host`) | — |\n| `sshPort` | SSH port | `22` |\n| `sshDest` | Remote backup directory path (required for ssh transport) | — |\n\n### 5. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync jq\n```\n\n`jq` is required — all scripts use it to parse the config JSON.\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If either step fails, use the OpenClaw message tool explicitly to alert the target channel with the failing step and key error text. Then reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails, the recommended pattern is for the **OpenClaw cron/session layer** to send the alert explicitly via the `message` tool.\n\nRecommended alert contents:\n- which step failed (`backup.sh` or `verify.sh`)\n- key error text\n- hostname and snapshot date when available\n\n## Before You Enable Automated Cron\n\nRun with `--dry-run` first and review the output:\n```bash\nscripts/backup.sh --dry-run\n```\n\nThen make sure your cron prompt owns notification behavior explicitly instead of relying on shell-side delivery.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated SMB credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **jq required**: Install with `apt-get install -y jq`. All scripts depend on it for config parsing.\n- **Notifications**: Keep notification ownership in the OpenClaw cron/session layer. Avoid hidden shell-side delivery paths.\n- **SSH host keys**: Pre-provision `~/.ssh/known_hosts` and keep `StrictHostKeyChecking=yes` in `lib.sh` for hardened setups.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` excluded by default — only include if NAS access is tightly restricted.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values validated before use — no shell injection via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq` (required)\n**Secrets stored:** None — SMB credentials live in a separate `chmod 600` file\n\nFile v2.0.3:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.2.1-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Incremental backup** — workspace, configs, agent data, cron jobs, sub-agent workspaces\n- 🚫 **Smart exclusions** — `.git/`, `node_modules/`, `__pycache__/` excluded by default; configurable\n- 🔄 **Safe restore** — automatically snapshots current state before restoring (undo in one command)\n- 🔍 **Integrity verification** — checksums key files and counts directory contents\n- 📊 **Status checks** — mount health, disk space, last success timestamp, snapshot inventory\n- ✅ **State tracking** — records last successful backup timestamp + manifest checksum\n- ⚠️ **Failure alerting** — Telegram alert on backup failure (optional success notification too)\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- 🔑 **SSH/rsync transport** — alternative to SMB; key-based auth, no credentials file needed\n- 🧹 **Auto-pruning** — daily snapshots and pre-restore safety snapshots pruned automatically\n- 🛡️ **Security-hardened** — all config values validated, no `eval`, no shell injection possible\n\n## Scripts\n\n| Script | Description |\n|--------|-------------|\n| `backup.sh [--dry-run]` | Run incremental backup |\n| `restore.sh [date]` | Restore from snapshot (lists available if no date given) |\n| `status.sh` | Show mount health, last backup, snapshot inventory |\n| `verify.sh [date]` | Verify snapshot integrity via checksums |\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Quick Setup\n\n1. Install dependencies: `apt-get install -y cifs-utils rsync`\n2. Create a dedicated Synology user with access to one share only\n3. Create credentials file: `touch ~/.openclaw/.smb-credentials && chmod 600 ~/.openclaw/.smb-credentials`\n4. Create config at `~/.openclaw/synology-backup.json` (see SKILL.md for full reference)\n5. Test: `bash scripts/backup.sh --dry-run`\n6. Register cron: `openclaw cron add --name \"Synology Backup\" --cron \"0 3 * * *\" --tz \"America/Los_Angeles\" --agent main --message \"exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. Reply NO_REPLY.\"`\n\n## Configuration\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3\n}\n```\n\nFor SSH transport, replace `\"transport\": \"smb\"` with `\"transport\": \"ssh\"` and add `sshUser`, `sshHost`, `sshPort`, `sshDest`.\n\n## Requirements\n\n- Synology NAS with SMB share (or SSH access)\n- OpenClaw installed\n- `cifs-utils` and `rsync` (`apt-get install -y cifs-utils rsync`)\n- Tailscale (optional, recommended for remote backup)\n\n## Security\n\n- Credentials stored in a dedicated file with `chmod 600`, never inline\n- All config values validated before use — no shell injection possible\n- Restore uses an explicit allowlist of safe paths — no arbitrary writes\n- Pre-restore safety snapshots automatically pruned after `preRestoreRetention` days\n- Default exclusions prevent backing up `.git/`, `node_modules/`, temp files\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n- [SKILL.md](./SKILL.md) — full configuration reference\n\nFile v2.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"2.0.3\",\n  \"publishedAt\": 1775348671353\n}\n\nFile v2.0.3:skill-card.md\n\n## Description:\n\nBackup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[pfrederiksen](https://clawhub.ai/user/pfrederiksen)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users, developers, and operators use this skill to configure and run Synology NAS backups for OpenClaw workspaces, inspect backup health, verify snapshots, and restore from dated backups.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The security summary reports that backups can copy secrets to the NAS outside the documented opt-in boundary.\n\nMitigation: Keep .env and other secrets out of backupPaths unless the NAS share is restricted and encrypted; review restore behavior before restoring configuration files.\n\nRisk: The security summary reports that rsync can follow symlinks out of approved folders.\n\nMitigation: Remove rsync --copy-links or enforce canonical symlink containment before relying on automated backups.\n\nRisk: Backup data can be exposed if NAS credentials, shares, or network access are too broad.\n\nMitigation: Use a dedicated low-privilege NAS user, restrict the backup share, avoid public SMB exposure, run a dry run first, and pre-provision SSH host keys when using SSH transport.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/pfrederiksen/skills/synology-backup)\n- [Publisher profile](https://clawhub.ai/user/pfrederiksen)\n- [OpenClaw](https://openclaw.ai)\n- [Tailscale](https://tailscale.com)\n- [Tailscale install guide](https://tailscale.com/download)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell commands and JSON configuration examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires rsync and jq; SMB transport also requires cifs-utils and a chmod 600 credentials file.]\n\n## Skill Version(s):\n\n2.0.3 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v2.0.2: 8 files, 17641 bytes\n\nFiles: README.md (4003b), scripts/backup.sh (11423b), scripts/lib.sh (11431b), scripts/restore.sh (4100b), scripts/status.sh (3529b), scripts/verify.sh (3037b), SKILL.md (9369b), _meta.json (134b)\n\nFile v2.0.2:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Sends Telegram alert on failure.\"\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - rsync\n        - jq\n      apt:\n        - rsync\n        - jq\n        - cifs-utils\n      notes: \"SSH transport requires SSH key auth to Synology. SMB transport requires cifs-utils and a chmod 600 credentials file. openclaw CLI required for cron registration and Telegram alerts.\"\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"-100xxxxxxxxxx\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (recommended):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n> ⚠️ **SSH host key warning:** Scripts use `StrictHostKeyChecking=accept-new`, which auto-trusts a host key on first connection. To harden this: SSH to your NAS manually once first (`ssh user@nas-ip`) to add its key to `~/.ssh/known_hosts`, then change to `StrictHostKeyChecking=yes` in `lib.sh`.\n\n**Sensitive files:** The `.env` file (containing API keys) is **excluded by default**. Only add it to `backupPaths` if your NAS share is restricted to a dedicated low-privilege user and encrypted at rest. When in doubt, leave it out — you can always re-enter API keys from scratch.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `telegramTarget` | Telegram target for failure alerts | your group/chat ID |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of daily snapshots to keep | `7` |\n| `preRestoreRetention` | Days to keep pre-restore safety snapshots | `3` |\n| `backupExclude` | rsync exclude patterns (`.git/`, `node_modules/` always excluded) | `[]` |\n| `notifyOnSuccess` | Send Telegram on successful backup (in addition to failures) | `false` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n| `sshUser` | SSH username (required for ssh transport) | — |\n| `sshHost` | SSH hostname (defaults to `host`) | — |\n| `sshPort` | SSH port | `22` |\n| `sshDest` | Remote backup directory path (required for ssh transport) | — |\n\n### 5. Telegram Alerts (optional)\n\nFailure alerts use `openclaw message send` — no bot token needed; OpenClaw handles delivery. Just set `telegramTarget` in config to your chat/group ID (e.g. `-1001234567890`). Leave it empty to disable alerts entirely.\n\n### 6. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync jq\n```\n\n`jq` is required — all scripts use it to parse the config JSON.\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If backup fails, it will automatically send a Telegram alert. Reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails for any reason, a Telegram alert is sent automatically:\n\n> ⚠️ Synology backup FAILED on <hostname> at <date> — exit code 1\n\nConfigure the target via `telegramTarget` in the config.\n\n## Before You Enable Automated Cron\n\nRun with `--dry-run` first and review the output:\n```bash\nscripts/backup.sh --dry-run\n```\n\nCheck `scripts/lib.sh` — specifically `send_telegram()` — to understand what network calls are made. No credentials are stored there; it delegates to `openclaw message send`.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated SMB credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **jq required**: Install with `apt-get install -y jq`. All scripts fail silently without it.\n- **Telegram alerts**: Use `openclaw message send` (no bot token in this skill). Set `telegramTarget` to your chat ID or leave empty to disable.\n- **SSH host keys**: `StrictHostKeyChecking=accept-new` auto-trusts on first connect. For hardened setups, pre-provision `~/.ssh/known_hosts` and switch to `StrictHostKeyChecking=yes` in `lib.sh`.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` excluded by default — only include if NAS access is tightly restricted.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values validated before use — no shell injection via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq` (required), `openclaw message send` (for Telegram alerts, no bot token stored here)\n**Secrets stored:** None — SMB credentials live in a separate `chmod 600` file; Telegram delivery handled by OpenClaw\n\nFile v2.0.2:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.2.1-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Incremental backup** — workspace, configs, agent data, cron jobs, sub-agent workspaces\n- 🚫 **Smart exclusions** — `.git/`, `node_modules/`, `__pycache__/` excluded by default; configurable\n- 🔄 **Safe restore** — automatically snapshots current state before restoring (undo in one command)\n- 🔍 **Integrity verification** — checksums key files and counts directory contents\n- 📊 **Status checks** — mount health, disk space, last success timestamp, snapshot inventory\n- ✅ **State tracking** — records last successful backup timestamp + manifest checksum\n- ⚠️ **Failure alerting** — Telegram alert on backup failure (optional success notification too)\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- 🔑 **SSH/rsync transport** — alternative to SMB; key-based auth, no credentials file needed\n- 🧹 **Auto-pruning** — daily snapshots and pre-restore safety snapshots pruned automatically\n- 🛡️ **Security-hardened** — all config values validated, no `eval`, no shell injection possible\n\n## Scripts\n\n| Script | Description |\n|--------|-------------|\n| `backup.sh [--dry-run]` | Run incremental backup |\n| `restore.sh [date]` | Restore from snapshot (lists available if no date given) |\n| `status.sh` | Show mount health, last backup, snapshot inventory |\n| `verify.sh [date]` | Verify snapshot integrity via checksums |\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Quick Setup\n\n1. Install dependencies: `apt-get install -y cifs-utils rsync`\n2. Create a dedicated Synology user with access to one share only\n3. Create credentials file: `touch ~/.openclaw/.smb-credentials && chmod 600 ~/.openclaw/.smb-credentials`\n4. Create config at `~/.openclaw/synology-backup.json` (see SKILL.md for full reference)\n5. Test: `bash scripts/backup.sh --dry-run`\n6. Register cron: `openclaw cron add --name \"Synology Backup\" --cron \"0 3 * * *\" --tz \"America/Los_Angeles\" --agent main --message \"exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. Reply NO_REPLY.\"`\n\n## Configuration\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3\n}\n```\n\nFor SSH transport, replace `\"transport\": \"smb\"` with `\"transport\": \"ssh\"` and add `sshUser`, `sshHost`, `sshPort`, `sshDest`.\n\n## Requirements\n\n- Synology NAS with SMB share (or SSH access)\n- OpenClaw installed\n- `cifs-utils` and `rsync` (`apt-get install -y cifs-utils rsync`)\n- Tailscale (optional, recommended for remote backup)\n\n## Security\n\n- Credentials stored in a dedicated file with `chmod 600`, never inline\n- All config values validated before use — no shell injection possible\n- Restore uses an explicit allowlist of safe paths — no arbitrary writes\n- Pre-restore safety snapshots automatically pruned after `preRestoreRetention` days\n- Default exclusions prevent backing up `.git/`, `node_modules/`, temp files\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n- [SKILL.md](./SKILL.md) — full configuration reference\n\nFile v2.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"2.0.2\",\n  \"publishedAt\": 1775149299488\n}\n\nArchive v2.0.1: 8 files, 17556 bytes\n\nFiles: README.md (4003b), scripts/backup.sh (11444b), scripts/lib.sh (11438b), scripts/restore.sh (4100b), scripts/status.sh (3529b), scripts/verify.sh (3037b), SKILL.md (9034b), _meta.json (134b)\n\nFile v2.0.1:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Sends Telegram alert on failure.\"\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"-100xxxxxxxxxx\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (recommended):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n> ⚠️ **SSH host key warning:** Scripts use `StrictHostKeyChecking=accept-new`, which auto-trusts a host key on first connection. To harden this: SSH to your NAS manually once first (`ssh user@nas-ip`) to add its key to `~/.ssh/known_hosts`, then change to `StrictHostKeyChecking=yes` in `lib.sh`.\n\n**Sensitive files:** The `.env` file (containing API keys) is **excluded by default**. Only add it to `backupPaths` if your NAS share is restricted to a dedicated low-privilege user and encrypted at rest. When in doubt, leave it out — you can always re-enter API keys from scratch.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `telegramTarget` | Telegram target for failure alerts | your group/chat ID |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of daily snapshots to keep | `7` |\n| `preRestoreRetention` | Days to keep pre-restore safety snapshots | `3` |\n| `backupExclude` | rsync exclude patterns (`.git/`, `node_modules/` always excluded) | `[]` |\n| `notifyOnSuccess` | Send Telegram on successful backup (in addition to failures) | `false` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n| `sshUser` | SSH username (required for ssh transport) | — |\n| `sshHost` | SSH hostname (defaults to `host`) | — |\n| `sshPort` | SSH port | `22` |\n| `sshDest` | Remote backup directory path (required for ssh transport) | — |\n\n### 5. Telegram Alerts (optional)\n\nFailure alerts use `openclaw message send` — no bot token needed; OpenClaw handles delivery. Just set `telegramTarget` in config to your chat/group ID (e.g. `-1001234567890`). Leave it empty to disable alerts entirely.\n\n### 6. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync jq\n```\n\n`jq` is required — all scripts use it to parse the config JSON.\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If backup fails, it will automatically send a Telegram alert. Reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails for any reason, a Telegram alert is sent automatically:\n\n> ⚠️ Synology backup FAILED on <hostname> at <date> — exit code 1\n\nConfigure the target via `telegramTarget` in the config.\n\n## Before You Enable Automated Cron\n\nRun with `--dry-run` first and review the output:\n```bash\nscripts/backup.sh --dry-run\n```\n\nCheck `scripts/lib.sh` — specifically `send_telegram()` — to understand what network calls are made. No credentials are stored there; it delegates to `openclaw message send`.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated SMB credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **jq required**: Install with `apt-get install -y jq`. All scripts fail silently without it.\n- **Telegram alerts**: Use `openclaw message send` (no bot token in this skill). Set `telegramTarget` to your chat ID or leave empty to disable.\n- **SSH host keys**: `StrictHostKeyChecking=accept-new` auto-trusts on first connect. For hardened setups, pre-provision `~/.ssh/known_hosts` and switch to `StrictHostKeyChecking=yes` in `lib.sh`.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` excluded by default — only include if NAS access is tightly restricted.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values validated before use — no shell injection via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq` (required), `openclaw message send` (for Telegram alerts, no bot token stored here)\n**Secrets stored:** None — SMB credentials live in a separate `chmod 600` file; Telegram delivery handled by OpenClaw\n\nFile v2.0.1:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.2.1-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Incremental backup** — workspace, configs, agent data, cron jobs, sub-agent workspaces\n- 🚫 **Smart exclusions** — `.git/`, `node_modules/`, `__pycache__/` excluded by default; configurable\n- 🔄 **Safe restore** — automatically snapshots current state before restoring (undo in one command)\n- 🔍 **Integrity verification** — checksums key files and counts directory contents\n- 📊 **Status checks** — mount health, disk space, last success timestamp, snapshot inventory\n- ✅ **State tracking** — records last successful backup timestamp + manifest checksum\n- ⚠️ **Failure alerting** — Telegram alert on backup failure (optional success notification too)\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- 🔑 **SSH/rsync transport** — alternative to SMB; key-based auth, no credentials file needed\n- 🧹 **Auto-pruning** — daily snapshots and pre-restore safety snapshots pruned automatically\n- 🛡️ **Security-hardened** — all config values validated, no `eval`, no shell injection possible\n\n## Scripts\n\n| Script | Description |\n|--------|-------------|\n| `backup.sh [--dry-run]` | Run incremental backup |\n| `restore.sh [date]` | Restore from snapshot (lists available if no date given) |\n| `status.sh` | Show mount health, last backup, snapshot inventory |\n| `verify.sh [date]` | Verify snapshot integrity via checksums |\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Quick Setup\n\n1. Install dependencies: `apt-get install -y cifs-utils rsync`\n2. Create a dedicated Synology user with access to one share only\n3. Create credentials file: `touch ~/.openclaw/.smb-credentials && chmod 600 ~/.openclaw/.smb-credentials`\n4. Create config at `~/.openclaw/synology-backup.json` (see SKILL.md for full reference)\n5. Test: `bash scripts/backup.sh --dry-run`\n6. Register cron: `openclaw cron add --name \"Synology Backup\" --cron \"0 3 * * *\" --tz \"America/Los_Angeles\" --agent main --message \"exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. Reply NO_REPLY.\"`\n\n## Configuration\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3\n}\n```\n\nFor SSH transport, replace `\"transport\": \"smb\"` with `\"transport\": \"ssh\"` and add `sshUser`, `sshHost`, `sshPort`, `sshDest`.\n\n## Requirements\n\n- Synology NAS with SMB share (or SSH access)\n- OpenClaw installed\n- `cifs-utils` and `rsync` (`apt-get install -y cifs-utils rsync`)\n- Tailscale (optional, recommended for remote backup)\n\n## Security\n\n- Credentials stored in a dedicated file with `chmod 600`, never inline\n- All config values validated before use — no shell injection possible\n- Restore uses an explicit allowlist of safe paths — no arbitrary writes\n- Pre-restore safety snapshots automatically pruned after `preRestoreRetention` days\n- Default exclusions prevent backing up `.git/`, `node_modules/`, temp files\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n- [SKILL.md](./SKILL.md) — full configuration reference\n\nFile v2.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"2.0.1\",\n  \"publishedAt\": 1775149059123\n}\n\nArchive v2.0.0: 8 files, 16899 bytes\n\nFiles: README.md (4003b), scripts/backup.sh (11444b), scripts/lib.sh (11438b), scripts/restore.sh (4100b), scripts/status.sh (3529b), scripts/verify.sh (3037b), SKILL.md (7380b), _meta.json (134b)\n\nFile v2.0.0:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Sends Telegram alert on failure.\"\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"-100xxxxxxxxxx\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (alternative):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n**Sensitive files:** The `.env` file (containing API keys) is not included by default. Add `\"~/.openclaw/.env\"` to `backupPaths` only if your NAS share has restricted access.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `telegramTarget` | Telegram target for failure alerts | your group/chat ID |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of daily snapshots to keep | `7` |\n| `preRestoreRetention` | Days to keep pre-restore safety snapshots | `3` |\n| `backupExclude` | rsync exclude patterns (`.git/`, `node_modules/` always excluded) | `[]` |\n| `notifyOnSuccess` | Send Telegram on successful backup (in addition to failures) | `false` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n| `sshUser` | SSH username (required for ssh transport) | — |\n| `sshHost` | SSH hostname (defaults to `host`) | — |\n| `sshPort` | SSH port | `22` |\n| `sshDest` | Remote backup directory path (required for ssh transport) | — |\n\n### 5. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync\n```\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If backup fails, it will automatically send a Telegram alert. Reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails for any reason, a Telegram alert is sent automatically:\n\n> ⚠️ Synology backup FAILED on <hostname> at <date> — exit code 1\n\nConfigure the target via `telegramTarget` in the config.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` is excluded by default. Only include it if your NAS is properly secured.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values are validated before use — no shell injection possible via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq`, `openclaw message send`\n\nFile v2.0.0:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.2.1-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Incremental backup** — workspace, configs, agent data, cron jobs, sub-agent workspaces\n- 🚫 **Smart exclusions** — `.git/`, `node_modules/`, `__pycache__/` excluded by default; configurable\n- 🔄 **Safe restore** — automatically snapshots current state before restoring (undo in one command)\n- 🔍 **Integrity verification** — checksums key files and counts directory contents\n- 📊 **Status checks** — mount health, disk space, last success timestamp, snapshot inventory\n- ✅ **State tracking** — records last successful backup timestamp + manifest checksum\n- ⚠️ **Failure alerting** — Telegram alert on backup failure (optional success notification too)\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- 🔑 **SSH/rsync transport** — alternative to SMB; key-based auth, no credentials file needed\n- 🧹 **Auto-pruning** — daily snapshots and pre-restore safety snapshots pruned automatically\n- 🛡️ **Security-hardened** — all config values validated, no `eval`, no shell injection possible\n\n## Scripts\n\n| Script | Description |\n|--------|-------------|\n| `backup.sh [--dry-run]` | Run incremental backup |\n| `restore.sh [date]` | Restore from snapshot (lists available if no date given) |\n| `status.sh` | Show mount health, last backup, snapshot inventory |\n| `verify.sh [date]` | Verify snapshot integrity via checksums |\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Quick Setup\n\n1. Install dependencies: `apt-get install -y cifs-utils rsync`\n2. Create a dedicated Synology user with access to one share only\n3. Create credentials file: `touch ~/.openclaw/.smb-credentials && chmod 600 ~/.openclaw/.smb-credentials`\n4. Create config at `~/.openclaw/synology-backup.json` (see SKILL.md for full reference)\n5. Test: `bash scripts/backup.sh --dry-run`\n6. Register cron: `openclaw cron add --name \"Synology Backup\" --cron \"0 3 * * *\" --tz \"America/Los_Angeles\" --agent main --message \"exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. Reply NO_REPLY.\"`\n\n## Configuration\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3\n}\n```\n\nFor SSH transport, replace `\"transport\": \"smb\"` with `\"transport\": \"ssh\"` and add `sshUser`, `sshHost`, `sshPort`, `sshDest`.\n\n## Requirements\n\n- Synology NAS with SMB share (or SSH access)\n- OpenClaw installed\n- `cifs-utils` and `rsync` (`apt-get install -y cifs-utils rsync`)\n- Tailscale (optional, recommended for remote backup)\n\n## Security\n\n- Credentials stored in a dedicated file with `chmod 600`, never inline\n- All config values validated before use — no shell injection possible\n- Restore uses an explicit allowlist of safe paths — no arbitrary writes\n- Pre-restore safety snapshots automatically pruned after `preRestoreRetention` days\n- Default exclusions prevent backing up `.git/`, `node_modules/`, temp files\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n- [SKILL.md](./SKILL.md) — full configuration reference\n\nFile v2.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"2.0.0\",\n  \"publishedAt\": 1775148874843\n}\n\nArchive v1.2.1: 8 files, 14231 bytes\n\nFiles: README.md (1143b), scripts/backup.sh (6853b), scripts/lib.sh (9945b), scripts/restore.sh (4100b), scripts/status.sh (3529b), scripts/verify.sh (3037b), SKILL.md (7466b), _meta.json (134b)\n\nFile v1.2.1:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Sends Telegram alert on failure.\"\ntags: [\"backup\", \"synology\", \"nas\", \"smb\", \"rsync\", \"disaster-recovery\", \"tailscale\"]\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"-100xxxxxxxxxx\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (alternative):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n**Sensitive files:** The `.env` file (containing API keys) is not included by default. Add `\"~/.openclaw/.env\"` to `backupPaths` only if your NAS share has restricted access.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `telegramTarget` | Telegram target for failure alerts | your group/chat ID |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of daily snapshots to keep | `7` |\n| `preRestoreRetention` | Days to keep pre-restore safety snapshots | `3` |\n| `backupExclude` | rsync exclude patterns (`.git/`, `node_modules/` always excluded) | `[]` |\n| `notifyOnSuccess` | Send Telegram on successful backup (in addition to failures) | `false` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n| `sshUser` | SSH username (required for ssh transport) | — |\n| `sshHost` | SSH hostname (defaults to `host`) | — |\n| `sshPort` | SSH port | `22` |\n| `sshDest` | Remote backup directory path (required for ssh transport) | — |\n\n### 5. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync\n```\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If backup fails, it will automatically send a Telegram alert. Reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails for any reason, a Telegram alert is sent automatically:\n\n> ⚠️ Synology backup FAILED on <hostname> at <date> — exit code 1\n\nConfigure the target via `telegramTarget` in the config.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` is excluded by default. Only include it if your NAS is properly secured.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values are validated before use — no shell injection possible via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq`, `openclaw message send`\n\nFile v1.2.1:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.0.4-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Full backup** — workspace, configs, agent data, cron jobs\n- 🔄 **Snapshot restore** — restore from any previous backup point\n- 📊 **Status checks** — mount health, disk space, snapshot inventory\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- ⏰ **Cron scheduling** — automated daily/weekly backups\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Usage\n\n```bash\nbash scripts/status.sh\n```\n\n## Requirements\n\n- Synology NAS with SMB share\n- OpenClaw installed\n- `cifs-utils` for mounting\n- Tailscale (optional, for remote backup)\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n\nFile v1.2.1:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"1.2.1\",\n  \"publishedAt\": 1774481895896\n}\n\nArchive v1.2.0: 8 files, 14128 bytes\n\nFiles: README.md (1143b), scripts/backup.sh (6705b), scripts/lib.sh (9213b), scripts/restore.sh (4100b), scripts/status.sh (3529b), scripts/verify.sh (3037b), SKILL.md (7466b), _meta.json (134b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Sends Telegram alert on failure.\"\ntags: [\"backup\", \"synology\", \"nas\", \"smb\", \"rsync\", \"disaster-recovery\", \"tailscale\"]\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"-100xxxxxxxxxx\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (alternative):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n**Sensitive files:** The `.env` file (containing API keys) is not included by default. Add `\"~/.openclaw/.env\"` to `backupPaths` only if your NAS share has restricted access.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `telegramTarget` | Telegram target for failure alerts | your group/chat ID |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of daily snapshots to keep | `7` |\n| `preRestoreRetention` | Days to keep pre-restore safety snapshots | `3` |\n| `backupExclude` | rsync exclude patterns (`.git/`, `node_modules/` always excluded) | `[]` |\n| `notifyOnSuccess` | Send Telegram on successful backup (in addition to failures) | `false` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n| `sshUser` | SSH username (required for ssh transport) | — |\n| `sshHost` | SSH hostname (defaults to `host`) | — |\n| `sshPort` | SSH port | `22` |\n| `sshDest` | Remote backup directory path (required for ssh transport) | — |\n\n### 5. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync\n```\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If backup fails, it will automatically send a Telegram alert. Reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails for any reason, a Telegram alert is sent automatically:\n\n> ⚠️ Synology backup FAILED on <hostname> at <date> — exit code 1\n\nConfigure the target via `telegramTarget` in the config.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` is excluded by default. Only include it if your NAS is properly secured.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values are validated before use — no shell injection possible via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq`, `openclaw message send`\n\nFile v1.2.0:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.0.4-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Full backup** — workspace, configs, agent data, cron jobs\n- 🔄 **Snapshot restore** — restore from any previous backup point\n- 📊 **Status checks** — mount health, disk space, snapshot inventory\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- ⏰ **Cron scheduling** — automated daily/weekly backups\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Usage\n\n```bash\nbash scripts/status.sh\n```\n\n## Requirements\n\n- Synology NAS with SMB share\n- OpenClaw installed\n- `cifs-utils` for mounting\n- Tailscale (optional, for remote backup)\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1774481785465\n}\n\nArchive v1.1.5: 8 files, 12152 bytes\n\nFiles: README.md (1143b), scripts/backup.sh (3896b), scripts/lib.sh (5588b), scripts/restore.sh (4100b), scripts/status.sh (3299b), scripts/verify.sh (3037b), SKILL.md (6883b), _meta.json (134b)\n\nFile v1.1.5:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Sends Telegram alert on failure.\"\ntags: [\"backup\", \"synology\", \"nas\", \"smb\", \"rsync\", \"disaster-recovery\", \"tailscale\"]\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"-100xxxxxxxxxx\",\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (alternative):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n**Sensitive files:** The `.env` file (containing API keys) is not included by default. Add `\"~/.openclaw/.env\"` to `backupPaths` only if your NAS share has restricted access.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `telegramTarget` | Telegram target for failure alerts | your group/chat ID |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of snapshots to keep | `7` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n\n### 5. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync\n```\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If backup fails, it will automatically send a Telegram alert. Reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails for any reason, a Telegram alert is sent automatically:\n\n> ⚠️ Synology backup FAILED on <hostname> at <date> — exit code 1\n\nConfigure the target via `telegramTarget` in the config.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` is excluded by default. Only include it if your NAS is properly secured.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values are validated before use — no shell injection possible via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq`, `openclaw message send`\n\nFile v1.1.5:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.0.4-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Full backup** — workspace, configs, agent data, cron jobs\n- 🔄 **Snapshot restore** — restore from any previous backup point\n- 📊 **Status checks** — mount health, disk space, snapshot inventory\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- ⏰ **Cron scheduling** — automated daily/weekly backups\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Usage\n\n```bash\nbash scripts/status.sh\n```\n\n## Requirements\n\n- Synology NAS with SMB share\n- OpenClaw installed\n- `cifs-utils` for mounting\n- Tailscale (optional, for remote backup)\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n\nFile v1.1.5:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"1.1.5\",\n  \"publishedAt\": 1774473331418\n}\n\nArchive v1.1.4: 8 files, 12091 bytes\n\nFiles: README.md (1143b), scripts/backup.sh (3782b), scripts/lib.sh (5588b), scripts/restore.sh (4100b), scripts/status.sh (3299b), scripts/verify.sh (3037b), SKILL.md (6883b), _meta.json (134b)\n\nFile v1.1.4:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Sends Telegram alert on failure.\"\ntags: [\"backup\", \"synology\", \"nas\", \"smb\", \"rsync\", \"disaster-recovery\", \"tailscale\"]\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"-100xxxxxxxxxx\",\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (alternative):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n**Sensitive files:** The `.env` file (containing API keys) is not included by default. Add `\"~/.openclaw/.env\"` to `backupPaths` only if your NAS share has restricted access.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `telegramTarget` | Telegram target for failure alerts | your group/chat ID |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of snapshots to keep | `7` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n\n### 5. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync\n```\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If backup fails, it will automatically send a Telegram alert. Reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails for any reason, a Telegram alert is sent automatically:\n\n> ⚠️ Synology backup FAILED on <hostname> at <date> — exit code 1\n\nConfigure the target via `telegramTarget` in the config.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` is excluded by default. Only include it if your NAS is properly secured.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values are validated before use — no shell injection possible via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq`, `openclaw message send`\n\nFile v1.1.4:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.0.4-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Full backup** — workspace, configs, agent data, cron jobs\n- 🔄 **Snapshot restore** — restore from any previous backup point\n- 📊 **Status checks** — mount health, disk space, snapshot inventory\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- ⏰ **Cron scheduling** — automated daily/weekly backups\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Usage\n\n```bash\nbash scripts/status.sh\n```\n\n## Requirements\n\n- Synology NAS with SMB share\n- OpenClaw installed\n- `cifs-utils` for mounting\n- Tailscale (optional, for remote backup)\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n\nFile v1.1.4:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"1.1.4\",\n  \"publishedAt\": 1774473250097\n}\n\nArchive v1.1.3: 8 files, 12050 bytes\n\nFiles: README.md (1143b), scripts/backup.sh (3782b), scripts/lib.sh (5490b), scripts/restore.sh (4100b), scripts/status.sh (3299b), scripts/verify.sh (3037b), SKILL.md (6883b), _meta.json (134b)\n\nFile v1.1.3:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Sends Telegram alert on failure.\"\ntags: [\"backup\", \"synology\", \"nas\", \"smb\", \"rsync\", \"disaster-recovery\", \"tailscale\"]\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"-100xxxxxxxxxx\",\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (alternative):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n**Sensitive files:** The `.env` file (containing API keys) is not included by default. Add `\"~/.openclaw/.env\"` to `backupPaths` only if your NAS share has restricted access.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `telegramTarget` | Telegram target for failure alerts | your group/chat ID |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of snapshots to keep | `7` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n\n### 5. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync\n```\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If backup fails, it will automatically send a Telegram alert. Reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails for any reason, a Telegram alert is sent automatically:\n\n> ⚠️ Synology backup FAILED on <hostname> at <date> — exit code 1\n\nConfigure the target via `telegramTarget` in the config.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` is excluded by default. Only include it if your NAS is properly secured.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values are validated before use — no shell injection possible via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq`, `openclaw message send`\n\nFile v1.1.3:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.0.4-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Full backup** — workspace, configs, agent data, cron jobs\n- 🔄 **Snapshot restore** — restore from any previous backup point\n- 📊 **Status checks** — mount health, disk space, snapshot inventory\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- ⏰ **Cron scheduling** — automated daily/weekly backups\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Usage\n\n```bash\nbash scripts/status.sh\n```\n\n## Requirements\n\n- Synology NAS with SMB share\n- OpenClaw installed\n- `cifs-utils` for mounting\n- Tailscale (optional, for remote backup)\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n\nFile v1.1.3:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"1.1.3\",\n  \"publishedAt\": 1774473115465\n}\n\nArchive v1.1.2: 8 files, 12059 bytes\n\nFiles: README.md (1143b), scripts/backup.sh (3782b), scripts/lib.sh (5460b), scripts/restore.sh (4100b), scripts/status.sh (3299b), scripts/verify.sh (3037b), SKILL.md (6883b), _meta.json (134b)\n\nFile v1.1.2:SKILL.md\n\n---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Sends Telegram alert on failure.\"\ntags: [\"backup\", \"synology\", \"nas\", \"smb\", \"rsync\", \"disaster-recovery\", \"tailscale\"]\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"-100xxxxxxxxxx\",\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (alternative):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n**Sensitive files:** The `.env` file (containing API keys) is not included by default. Add `\"~/.openclaw/.env\"` to `backupPaths` only if your NAS share has restricted access.\n\n| Field | Description | Default |\n|-------|-------------|---------|\n| `host` | Synology IP (Tailscale or local) | required |\n| `share` | SMB share path | required |\n| `mountPoint` | Local mount point | `/mnt/synology` |\n| `credentialsFile` | Path to SMB credentials file | required (SMB) |\n| `smbVersion` | SMB protocol version | `3.0` |\n| `transport` | `smb` or `ssh` | `smb` |\n| `sshUser` | SSH username | required (SSH) |\n| `telegramTarget` | Telegram target for failure alerts | your group/chat ID |\n| `backupPaths` | Paths to backup | workspace + config |\n| `includeSubAgentWorkspaces` | Auto-include `workspace-*` dirs | `true` |\n| `retention` | Days of snapshots to keep | `7` |\n| `schedule` | Cron expression (host timezone) | `0 3 * * *` |\n\n### 5. Install Dependencies\n\n```bash\napt-get install -y cifs-utils rsync\n```\n\n### 6. Register the Backup Cron\n\n```bash\nopenclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If backup fails, it will automatically send a Telegram alert. Reply NO_REPLY.\"\n```\n\n## Usage\n\n### Backup Now\n\n```bash\nscripts/backup.sh\n```\n\nRuns an incremental backup. Add `--dry-run` to preview what would be backed up without touching anything.\n\n### Check Status\n\n```bash\nscripts/status.sh\n```\n\nShows mount health, last backup time, snapshot count, total size, and pre-restore safety snapshots.\n\n### Verify Integrity\n\n```bash\nscripts/verify.sh          # verify latest snapshot\nscripts/verify.sh 2026-03-25  # verify specific date\n```\n\nChecksums key files and counts directory contents against the snapshot to confirm data integrity.\n\n### Restore a Snapshot\n\n```bash\nscripts/restore.sh          # list available snapshots\nscripts/restore.sh 2026-03-25   # restore from specific date\n```\n\nBefore restoring, automatically saves a **pre-restore safety snapshot** of your current state. If the restore goes wrong, restore the safety snapshot to undo.\n\n## What Gets Backed Up\n\n- `~/.openclaw/workspace/` — memory, SOUL, AGENTS, skills, all workspace files\n- `~/.openclaw/workspace-*/` — all sub-agent workspaces (if enabled)\n- `~/.openclaw/openclaw.json` — main config\n- `~/.openclaw/cron/` — cron job definitions\n- `~/.openclaw/agents/` — agent configurations\n- `~/.openclaw/.env` — **opt-in only** (contains API keys)\n\n## Snapshot Structure\n\n```\nbackups/\n├── 2026-03-25/\n│   ├── manifest.json          # timestamp, host, path counts\n│   ├── workspace/\n│   ├── workspace-news/\n│   ├── agents/\n│   ├── cron/\n│   └── openclaw.json\n├── pre-restore-2026-03-25-143022/   # safety snapshot before restore\n├── 2026-03-24/\n└── ...\n```\n\n## Failure Alerting\n\nIf a backup fails for any reason, a Telegram alert is sent automatically:\n\n> ⚠️ Synology backup FAILED on <hostname> at <date> — exit code 1\n\nConfigure the target via `telegramTarget` in the config.\n\n## Security Notes\n\n- **Credentials**: Always use a dedicated credentials file with `chmod 600`. Never inline secrets in config, scripts, or fstab.\n- **Network**: Use Tailscale or a VPN for remote backups. Never expose SMB (port 445) to the public internet.\n- **Sensitive data**: `.env` is excluded by default. Only include it if your NAS is properly secured.\n- **NAS user**: Dedicated user with access to only the backup share — not an admin account.\n- **Input validation**: All config values are validated before use — no shell injection possible via host, share, mount, or path fields.\n- **Path allowlist**: Restore uses an explicit allowlist (`workspace`, `cron`, `agents`, `openclaw.json`, `.env`) — no arbitrary path writes.\n\n## System Access\n\n**Files read:** `~/.openclaw/synology-backup.json`, `~/.openclaw/.smb-credentials`\n**Files written:** Synology NAS share (via SMB mount or SSH/rsync), `manifest.json` in each snapshot\n**Network:** SMB (port 445) or SSH (port 22) to Synology NAS IP only\n**Commands used:** `mount`, `rsync`, `cp`, `find`, `du`, `df`, `md5sum`, `jq`, `openclaw message send`\n\nFile v1.1.2:README.md\n\n# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.0.4-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Full backup** — workspace, configs, agent data, cron jobs\n- 🔄 **Snapshot restore** — restore from any previous backup point\n- 📊 **Status checks** — mount health, disk space, snapshot inventory\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- ⏰ **Cron scheduling** — automated daily/weekly backups\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Usage\n\n```bash\nbash scripts/status.sh\n```\n\n## Requirements\n\n- Synology NAS with SMB share\n- OpenClaw installed\n- `cifs-utils` for mounting\n- Tailscale (optional, for remote backup)\n\n## License\n\nMIT\n\n## Links\n\n- [ClawHub](https://clawhub.ai/pfrederiksen/synology-backup)\n- [OpenClaw](https://openclaw.ai)\n\nFile v1.1.2:_meta.json\n\n{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"1.1.2\",\n  \"publishedAt\": 1774473033525\n}","readmeExcerpt":"Skill: Synology Backup Owner: pfrederiksen Summary: Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a... Tags: latest:2.0.3 Version history: v2.0.3 | 2026-04-05T00:24:31.353Z | user Cleaned notification flow, removed hidden shell-side delivery, aligned docs with implementation, and kept backup behavior hardened","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"touch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>"},{"language":"json","snippet":"{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3,\n  \"schedule\": \"0 3 * * *\"\n}"},{"language":"bash","snippet":"apt-get install -y cifs-utils rsync jq"},{"language":"bash","snippet":"openclaw cron add \\\n  --name \"Synology Backup\" \\\n  --schedule \"0 3 * * *\" \\\n  --tz \"America/Los_Angeles\" \\\n  --message \"Run the daily Synology backup: bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. If either step fails, use the OpenClaw message tool explicitly to alert the target channel with the failing step and key error text. Then reply NO_REPLY.\""},{"language":"bash","snippet":"scripts/backup.sh"},{"language":"bash","snippet":"scripts/status.sh"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: synology-backup\ndescription: \"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a snapshot, checking backup status/health, verifying backup integrity, or setting up automated daily backups. Supports Tailscale for secure remote VPS-to-NAS connectivity. Designed for explicit OpenClaw cron/session notifications instead of hidden shell-side delivery.\"\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - rsync\n        - jq\n      apt:\n        - rsync\n        - jq\n        - cifs-utils\n      notes: \"SSH transport requires SSH key auth to Synology. SMB transport requires cifs-utils and a chmod 600 credentials file. Cron/session layer should own notifications explicitly.\"\n---\n\n# Synology Backup\n\nBackup OpenClaw data to a Synology NAS over SMB or SSH/rsync. Designed for secure, automated daily snapshots with configurable retention, integrity verification, and failure alerting.\n\n## Setup\n\n### 1. Network Connectivity\n\nFor VPS-to-NAS backups, use [Tailscale](https://tailscale.com) for secure connectivity without exposing SMB to the internet:\n\n1. Install Tailscale on the Synology (Package Center → search \"Tailscale\")\n2. Install Tailscale on the VPS — see [Tailscale's official install guide](https://tailscale.com/download) for your platform\n3. Join both to the same tailnet\n4. Use the Synology's Tailscale IP in config\n\nFor local network setups, use the NAS local IP directly.\n\n### 2. Synology Preparation\n\n1. Create a dedicated user on the Synology (e.g., `openclaw-backup`) with minimal permissions\n2. Create or choose a shared folder (e.g., `backups`)\n3. Grant the user read/write access to **only** that folder — not admin access\n\n### 3. Credentials File (SMB transport)\n\nCreate an SMB credentials file with restricted permissions — **never store credentials in config or scripts**:\n\n```bash\ntouch ~/.openclaw/.smb-credentials\nchmod 600 ~/.openclaw/.smb-credentials\n# Add two lines:\n# username=<your-synology-user>\n# password=<your-synology-password>\n```\n\n### 4. Configuration\n\nCreate `~/.openclaw/synology-backup.json`:\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"retention\": 7,\n  \"preRestoreRetention\": 3,\n  \"schedule\": \"0 3 * * *\"\n}\n```\n\n**SSH transport (recommended):** Set `\"transport\": \"ssh\"` and add `\"sshUser\": \"your-user\"`. No credentials file needed — uses SSH key auth. Requires rsync + SSH access to the Synology.\n\n> ⚠️ **SSH host key warning:** Scripts use `StrictHostKeyChecking=yes`. Add your NAS host key to `~/.ssh/known_hosts` first by connecting manually once (`ssh user@nas"},{"path":"README.md","content":"# Synology Backup\n\n[![ClawHub](https://img.shields.io/badge/ClawHub-synology--backup-blue)](https://clawhub.ai/pfrederiksen/synology-backup)\n[![Version](https://img.shields.io/badge/version-1.2.1-green)]()\n\nAn [OpenClaw](https://openclaw.ai) skill for backing up and restoring OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Supports Tailscale for secure remote VPS-to-NAS connectivity.\n\n## Features\n\n- 💾 **Incremental backup** — workspace, configs, agent data, cron jobs, sub-agent workspaces\n- 🚫 **Smart exclusions** — `.git/`, `node_modules/`, `__pycache__/` excluded by default; configurable\n- 🔄 **Safe restore** — automatically snapshots current state before restoring (undo in one command)\n- 🔍 **Integrity verification** — checksums key files and counts directory contents\n- 📊 **Status checks** — mount health, disk space, last success timestamp, snapshot inventory\n- ✅ **State tracking** — records last successful backup timestamp + manifest checksum\n- ⚠️ **Failure alerting** — Telegram alert on backup failure (optional success notification too)\n- 🔒 **Tailscale support** — secure remote backup over WireGuard mesh\n- 🔑 **SSH/rsync transport** — alternative to SMB; key-based auth, no credentials file needed\n- 🧹 **Auto-pruning** — daily snapshots and pre-restore safety snapshots pruned automatically\n- 🛡️ **Security-hardened** — all config values validated, no `eval`, no shell injection possible\n\n## Scripts\n\n| Script | Description |\n|--------|-------------|\n| `backup.sh [--dry-run]` | Run incremental backup |\n| `restore.sh [date]` | Restore from snapshot (lists available if no date given) |\n| `status.sh` | Show mount health, last backup, snapshot inventory |\n| `verify.sh [date]` | Verify snapshot integrity via checksums |\n\n## Installation\n\n```bash\nclawhub install synology-backup\n```\n\n## Quick Setup\n\n1. Install dependencies: `apt-get install -y cifs-utils rsync`\n2. Create a dedicated Synology user with access to one share only\n3. Create credentials file: `touch ~/.openclaw/.smb-credentials && chmod 600 ~/.openclaw/.smb-credentials`\n4. Create config at `~/.openclaw/synology-backup.json` (see SKILL.md for full reference)\n5. Test: `bash scripts/backup.sh --dry-run`\n6. Register cron: `openclaw cron add --name \"Synology Backup\" --cron \"0 3 * * *\" --tz \"America/Los_Angeles\" --agent main --message \"exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/backup.sh && exec bash ~/.openclaw/workspace/skills/synology-backup/scripts/verify.sh. Reply NO_REPLY.\"`\n\n## Configuration\n\n```json\n{\n  \"host\": \"100.x.x.x\",\n  \"share\": \"backups/openclaw\",\n  \"mountPoint\": \"/mnt/synology\",\n  \"credentialsFile\": \"~/.openclaw/.smb-credentials\",\n  \"smbVersion\": \"3.0\",\n  \"transport\": \"smb\",\n  \"telegramTarget\": \"\",\n  \"notifyOnSuccess\": false,\n  \"backupPaths\": [\n    \"~/.openclaw/workspace\",\n    \"~/.openclaw/openclaw.json\",\n    \"~/.openclaw/cron\",\n    \"~/.openclaw/agents\"\n  ],\n  \"backupExclude\": [],\n  \"includeSubAgentWorkspaces\": true,\n  \"ret"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7cvyzb78ahvv8e5888vj9r5581apwf\",\n  \"slug\": \"synology-backup\",\n  \"version\": \"2.0.3\",\n  \"publishedAt\": 1775348671353\n}"},{"path":"skill-card.md","content":"## Description:\n\nBackup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[pfrederiksen](https://clawhub.ai/user/pfrederiksen)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users, developers, and operators use this skill to configure and run Synology NAS backups for OpenClaw workspaces, inspect backup health, verify snapshots, and restore from dated backups.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The security summary reports that backups can copy secrets to the NAS outside the documented opt-in boundary.\n\nMitigation: Keep .env and other secrets out of backupPaths unless the NAS share is restricted and encrypted; review restore behavior before restoring configuration files.\n\nRisk: The security summary reports that rsync can follow symlinks out of approved folders.\n\nMitigation: Remove rsync --copy-links or enforce canonical symlink containment before relying on automated backups.\n\nRisk: Backup data can be exposed if NAS credentials, shares, or network access are too broad.\n\nMitigation: Use a dedicated low-privilege NAS user, restrict the backup share, avoid public SMB exposure, run a dry run first, and pre-provision SSH host keys when using SSH transport.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/pfrederiksen/skills/synology-backup)\n- [Publisher profile](https://clawhub.ai/user/pfrederiksen)\n- [OpenClaw](https://openclaw.ai)\n- [Tailscale](https://tailscale.com)\n- [Tailscale install guide](https://tailscale.com/download)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell commands and JSON configuration examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires rsync and jq; SMB transport also requires cifs-utils and a chmod 600 credentials file.]\n\n## Skill Version(s):\n\n2.0.3 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a... Skill: Synology Backup Owner: pfrederiksen Summary: Backup and restore OpenClaw workspace, configs, and agent data to a Synology NAS via SMB or SSH/rsync. Use when: backing up workspace files, restoring from a... Tags: latest:2.0.3 Version history: v2.0.3 | 2026-04-05T00:24:31.353Z | user Cleaned notification flow, removed hidden shell-side delivery, aligned docs with implementation, and kept backup behavior hardened","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1570,"uniquenessScore":45,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T13:16:08.313Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T13:16:08.313Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:35:13.815Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}