{"id":"5d147b99-2ad6-4140-ad56-78603e9c6d6a","entityType":"agent","slug":"marcusgraetsch-vps-openclaw-security-hardening","name":"vps-openclaw-security-hardening","canonicalUrl":"https://www.xpersona.co/agent/marcusgraetsch-vps-openclaw-security-hardening","canonicalPath":"/agent/marcusgraetsch-vps-openclaw-security-hardening","generatedAt":"2026-10-09T06:45:20.627Z","source":"GITHUB_OPENCLEW","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"description":"Production-ready security hardening for VPS running OpenClaw AI agents. Includes SSH hardening (custom port), firewall, audit logging, credential management, and intelligent alerting. Follows BSI IT-Grundschutz and NIST guidelines with minimal resource overhead. --- name: vps-openclaw-security-hardening description: Production-ready security hardening for VPS running OpenClaw AI agents. Includes SSH hardening (custom port), firewall, audit logging, credential management, and intelligent alerting. Follows BSI IT-Grundschutz and NIST guidelines with minimal resource overhead. version: 1.0.6 author: OpenClaw Community homepage: https://github.com/MarcusGraetsch/vps-openclaw-sec","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"git clone https://github.com/MarcusGraetsch/vps-openclaw-security-hardening.git","sourceUrl":"https://github.com/MarcusGraetsch/vps-openclaw-security-hardening","homepage":"https://github.com/MarcusGraetsch/vps-openclaw-security-hardening","primaryLinks":[{"label":"View Source","url":"https://github.com/MarcusGraetsch/vps-openclaw-security-hardening","kind":"source"}],"safetyScore":94,"overallRank":30.7,"popularityScore":0,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Production-ready security hardening for VPS running OpenClaw AI agents. Includes SSH hardening (custom port), firewall, audit logging, credential management, an"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"No source adoption metrics were available."},"stars":0,"forks":0,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-04-15T01:13:33.721Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T05:21:22.124Z","lastCrawledAt":"2026-04-15T01:13:33.721Z","lastIndexedAt":null,"nextCrawlAt":"2026-04-16T01:13:33.721Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"git clone https://github.com/MarcusGraetsch/vps-openclaw-security-hardening.git","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_OPENCLEW","generatedAt":"2026-10-09T06:45:20.627Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/marcusgraetsch-vps-openclaw-security-hardening/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"high","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"readme":"---\nname: vps-openclaw-security-hardening\ndescription: Production-ready security hardening for VPS running OpenClaw AI agents. Includes SSH hardening (custom port), firewall, audit logging, credential management, and intelligent alerting. Follows BSI IT-Grundschutz and NIST guidelines with minimal resource overhead.\nversion: 1.0.6\nauthor: OpenClaw Community\nhomepage: https://github.com/MarcusGraetsch/vps-openclaw-security-hardening\nmetadata:\n  openclaw:\n    emoji: 🛡️\n    requires:\n      bins: [\"ssh\", \"ufw\", \"auditd\", \"systemctl\", \"apt-get\"]\n      optional: [\"fail2ban\"]\n      os: [\"ubuntu\", \"debian\"]\n    tags: [\"security\", \"hardening\", \"vps\", \"audit\", \"monitoring\", \"firewall\", \"ssh\", \"fail2ban\"]\n    install: \"SSH_PORT=4848 ./scripts/install.sh\"\n    verify: \"./scripts/verify.sh\"\n    warning: \"DO NOT use on machines with sensitive personal data. Use dedicated VPS only. Test in VM first.\"\n---\n\n# VPS Security Hardening for OpenClaw\n\nProduction-ready security hardening for AI agent deployments on VPS.\n\n## ⚠️ CRITICAL WARNINGS\n\n**DO NOT run OpenClaw on servers/machines with sensitive personal data.** Use a dedicated machine (VPS, bare-metal, or on-premise server dedicated to OpenClaw).\n\n**Supported OS:** Ubuntu 20.04+, Debian 11+. Not for Windows (use WSL2) or macOS.\n\n## ⚠️ Choose Your SSH Port First\n\n**You must choose a custom SSH port (1024-65535) before installing.** This makes you conscious of the security decision.\n\n```bash\n# Choose your port (example: 4848)\nexport SSH_PORT=4848\n\n# Install\ncd ~/.openclaw/skills/vps-openclaw-security-hardening\nsudo ./scripts/install.sh\n\n# Verify\n./scripts/verify.sh\n\n# Test SSH (new terminal)\nssh -p ${SSH_PORT} root@your-vps-ip\n```\n\n## What It Does\n\n| Layer | Protection | Implementation |\n|-------|------------|----------------|\n| **Network** | Firewall, SSH hardening | UFW, custom port (your choice), key-only |\n| **System** | Auto-updates, monitoring | unattended-upgrades, auditd |\n| **Secrets** | Credential management | Centralized .env, 600 permissions |\n| **Monitoring** | Audit logging, alerting | Kernel-level audit, multi-channel alerts |\n\n## Requirements\n\n- **OS:** Ubuntu 20.04+ or Debian 11+ (Linux only)\n- **NOT supported:** Windows (use WSL2), macOS\n- Root access\n- Existing SSH key authentication\n- Alert channel (optional): Telegram, Discord, Slack, Email, or Webhook\n- **Custom SSH port of your choice (1024-65535)**\n\n## Security Changes\n\n### SSH\n- Port: 22 → ${SSH_PORT} (your choice, 1024-65535)\n- Auth: Keys only (no passwords)\n- Root login: Disabled\n- Max retries: 3\n- Fail2ban: Brute-force protection\n\n### Firewall\n- Default: Deny incoming\n- Allow: Your chosen SSH port only\n\n### Services\n- CUPS (printing): Stopped & disabled\n- Fail2ban: Intrusion detection enabled\n- Auto-updates: Security patches automatic\n\n### Monitoring\n- Credential file access tracking\n- SSH config change detection\n- Privilege escalation alerts\n- Daily security briefing\n\n## Resource Usage\n\n| Component | RAM | Disk |\n|-----------|-----|------|\n| Auditd | ~2 MB | 40 MB max |\n| UFW | ~1 MB | Negligible |\n| Scripts | ~5 MB | Negligible |\n| **Total** | **<10 MB** | **<50 MB** |\n\n## Files\n\n- `scripts/install.sh` - Main installation\n- `scripts/verify.sh` - Verify installation\n- `scripts/rollback-ssh.sh` - Emergency rollback\n- `scripts/critical-alert.sh` - Telegram alerts\n- `scripts/daily-briefing.sh` - Daily reports\n- `rules/audit.rules` - Audit configuration\n\n## Documentation\n\nSee [README.md](README.md) for full documentation.\n\n## License\n\nMIT - See LICENSE file\n","readmeExcerpt":"--- name: vps-openclaw-security-hardening description: Production-ready security hardening for VPS running OpenClaw AI agents. Includes SSH hardening (custom port), firewall, audit logging, credential management, and intelligent alerting. Follows BSI IT-Grundschutz and NIST guidelines with minimal resource overhead. version: 1.0.6 author: OpenClaw Community homepage: https://github.com/MarcusGraetsch/vps-openclaw-sec","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"# Choose your port (example: 4848)\nexport SSH_PORT=4848\n\n# Install\ncd ~/.openclaw/skills/vps-openclaw-security-hardening\nsudo ./scripts/install.sh\n\n# Verify\n./scripts/verify.sh\n\n# Test SSH (new terminal)\nssh -p ${SSH_PORT} root@your-vps-ip"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"GITHUB OPENCLEW","editorialOverview":"Production-ready security hardening for VPS running OpenClaw AI agents. Includes SSH hardening (custom port), firewall, audit logging, credential management, and intelligent alerting. Follows BSI IT-Grundschutz and NIST guidelines with minimal resource overhead. --- name: vps-openclaw-security-hardening description: Production-ready security hardening for VPS running OpenClaw AI agents. Includes SSH hardening (custom port), firewall, audit logging, credential management, and intelligent alerting. Follows BSI IT-Grundschutz and NIST guidelines with minimal resource overhead. version: 1.0.6 author: OpenClaw Community homepage: https://github.com/MarcusGraetsch/vps-openclaw-sec","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":412,"uniquenessScore":61,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T06:45:20.627Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/github_openclew","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}