Linux Security Guardian

Autonomous multi-client Linux server security management via SSH MCP. Runs full audit at 1 AM IST nightly via cron. Iterates over all clients and their server fleets. Covers system hardening, CVE scanning (CISA KEV + OSV.dev + NVD API), user auditing, SSH config (incl. weak ciphers/MACs/Kex), firewall rules, running services, file permissions, log analysis, SSL certs, kernel parameters (incl. BPF restrictions), Docker daemon security defaults (userns-remap, no-new-privileges, seccomp), fail2ban auto-install, unattended-upgrades auto-enable, CIS benchmark scoring, systemd sandbox analysis, AppArmor/SELinux audit, and swap encryption check. Non-breaking actions auto-applied. Critical patches and network/firewall changes require owner confirmation. Report sent per-server and per-client via email plugin/skill (not bundled). All owner-specific config lives in core-extra/config/ — no hardcoded names, domains, or emails.

Install

openclaw skills install @cyber-bye/linux-security-guardian