MarketingClaw host healthcheck
Goal: assess host risk, run read-only checks, then propose staged hardening without breaking access.
Rules
- Ask before state-changing actions.
- Do not change SSH/firewall/remote access until access path is confirmed.
- Prefer reversible steps and rollback notes.
- Never claim MarketingClaw manages OS firewall, SSH, or updates.
- If identity/role unknown, recommend only.
- User choices: numbered list.
- Never print secrets.
Context to infer first
- OS/version, container vs host.
- Privilege level.
- Access path: local, SSH, RDP, tailnet.
- Network exposure: public IP, reverse proxy, tunnel, LAN only.
- MarketingClaw gateway status, bind, auth.
- Backup status.
- Disk encryption.
- Automatic security updates.
- Usage mode: personal workstation, local assistant box, remote server, other.
Ask only for missing facts. Simple phrasing preferred.
Read-only checks
Ask once for permission to run read-only checks. Then run relevant commands.
Common:
marketingclaw security audit --deep
marketingclaw gateway status --deep
marketingclaw doctor
macOS:
sw_vers
lsof -nP -iTCP -sTCP:LISTEN
/usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate
pfctl -s info
tmutil status
fdesetup status
softwareupdate --schedule
Linux:
cat /etc/os-release
ss -ltnup || ss -ltnp
ufw status || firewall-cmd --state || nft list ruleset
systemctl status ssh sshd
lsblk -f
Windows:
systeminfo
Get-NetFirewallProfile
Get-BitLockerVolume
Risk profile
After context is known, ask desired posture:
- Convenience: local/private, minimal prompts.
- Balanced: secure defaults, low friction.
- Strict: remote/public/sensitive data, more lock-down.
Report shape
- Current posture: one paragraph.
- Findings: severity + evidence + why it matters.
- Recommended plan: staged, reversible.
- Commands: read-only first; write actions only after approval.
- Gaps: what could not be checked.
Hardening menu
Offer only relevant items:
- Bind gateway to loopback/LAN/tailnet intentionally.
- Require auth for remote access.
- Close public ports or restrict by firewall.
- Enable OS security updates.
- Enable disk encryption.
- Verify backups and restore path.
- Disable password SSH or require keys/MFA where appropriate.
- Add scheduled
marketingclaw security audit --deep.
Confirm exact action before applying.
1---2name: healthcheck3description: Audit/harden MarketingClaw hosts: SSH, firewall, updates, exposure, backups, disk encryption, gateway security.4---56# MarketingClaw host healthcheck78Goal: assess host risk, run read-only checks, then propose staged hardening without breaking access.910## Rules1112- Ask before state-changing actions.13- Do not change SSH/firewall/remote access until access path is confirmed.14- Prefer reversible steps and rollback notes.15- Never claim MarketingClaw manages OS firewall, SSH, or updates.16- If identity/role unknown, recommend only.17- User choices: numbered list.18- Never print secrets.1920## Context to infer first2122- OS/version, container vs host.23- Privilege level.24- Access path: local, SSH, RDP, tailnet.25- Network exposure: public IP, reverse proxy, tunnel, LAN only.26- MarketingClaw gateway status, bind, auth.27- Backup status.28- Disk encryption.29- Automatic security updates.30- Usage mode: personal workstation, local assistant box, remote server, other.3132Ask only for missing facts. Simple phrasing preferred.3334## Read-only checks3536Ask once for permission to run read-only checks. Then run relevant commands.3738Common:3940```bash41marketingclaw security audit --deep42marketingclaw gateway status --deep43marketingclaw doctor44```4546macOS:4748```bash49sw_vers50lsof -nP -iTCP -sTCP:LISTEN51/usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate52pfctl -s info53tmutil status54fdesetup status55softwareupdate --schedule56```5758Linux:5960```bash61cat /etc/os-release62ss -ltnup || ss -ltnp63ufw status || firewall-cmd --state || nft list ruleset64systemctl status ssh sshd65lsblk -f66```6768Windows:6970```powershell71systeminfo72Get-NetFirewallProfile73Get-BitLockerVolume74```7576## Risk profile7778After context is known, ask desired posture:79801. Convenience: local/private, minimal prompts.812. Balanced: secure defaults, low friction.823. Strict: remote/public/sensitive data, more lock-down.8384## Report shape8586- Current posture: one paragraph.87- Findings: severity + evidence + why it matters.88- Recommended plan: staged, reversible.89- Commands: read-only first; write actions only after approval.90- Gaps: what could not be checked.9192## Hardening menu9394Offer only relevant items:9596- Bind gateway to loopback/LAN/tailnet intentionally.97- Require auth for remote access.98- Close public ports or restrict by firewall.99- Enable OS security updates.100- Enable disk encryption.101- Verify backups and restore path.102- Disable password SSH or require keys/MFA where appropriate.103- Add scheduled `marketingclaw security audit --deep`.104105Confirm exact action before applying.