A rapid security hardening skill to protect Linux servers running OpenClaw from unauthorized access and brute-force attacks.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install server-host-hardening
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install server-host-hardening using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Host Hardening is a specialized security configuration skill designed to lock down Linux servers hosting OpenClaw instances. It implements industry-standard security practices including SSH key-only authentication, UFW firewall restrictions, and automated brute-force protection using fail2ban. This skill ensures your Openclaw Skills environment remains resilient against external threats while maintaining high availability for the gateway service.
To apply these security measures to your server, execute the following commands as root:
# Harden SSH access
sed -i 's/^#*PermitRootLogin.*/PermitRootLogin prohibit-password/' /etc/ssh/sshd_config
sed -i 's/^#*PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
systemctl restart ssh
# Configure UFW Firewall
ufw default deny incoming
ufw default allow outgoing
ufw allow ssh
yes | ufw enable
# Install Fail2ban
apt-get install -y fail2ban
systemctl enable --now fail2ban
The skill interacts with system-level configuration files and organizes its data as follows:
| Component | Path | Description |
|---|---|---|
| SSH Config | /etc/ssh/sshd_config |
Primary configuration for the SSH daemon |
| Firewall | /etc/ufw/ |
Directory containing firewall rules and policies |
| Brute-Force | /etc/fail2ban/ |
Configuration for automated IP blocking |
| Credentials | ~/.openclaw/credentials |
Sensitive access tokens protected by 700 permissions |
| Gateway Service | /etc/systemd/system/openclaw-gateway.service |
System service definition for process management |
Loading
A runtime safety control plane that enforces deterministic security policies on shell commands, network requests, and file operations.

An AI agent skill designed to execute multi-step tasks autonomously while adhering to strict safety guardrails and confirmation protocols.

A meta-skill designed to teach developers and agents how to create, structure, and publish their own custom agentic capabilities.

Exoskeletons provide AI agents with a persistent onchain identity, reputation system, and secure marketplace built on the Base network.

A privacy-focused CLI utility for analyzing Apple Health exports and extracting granular health metrics locally.

A comprehensive CLI utility for managing, scheduling, and monitoring local and cloud-based backups using rsync, Time Machine, and rclone.








































