Ollama Localhost Guardian
When to Use
- User says ollama security or task matches this capability
- User says is ollama exposed or task matches this capability
- User says secure local LLM or task matches this capability
- User says ollama localhost or task matches this capability
Workflow
- Check listener on default Ollama port (11434) via ss or netstat.
- Pass if bound to 127.0.0.1; warn if 0.0.0.0 or ::.
- Optionally check OLLAMA_HOST env and systemd override files (read-only).
- Recommend binding to 127.0.0.1; hitl-approver before config changes.
- Note installed AI packages (mcp, openai, etc.) for inventory only.
Integrations
defensive-mcp-auditexposed-service-triagehitl-approver
Error Handling
| Failure | Response |
|---|---|
| Ollama not running | Report not listening; no install assumed. |
Gotchas
- Check-only; config edits require user approval.
Safety & Ethics (Publication-Ready)
This skill is designed for public distribution. Constraints:
- Read-only checks; no model pulling or inference API abuse.
- No exposure of API keys or model weights.
Prohibited actions
- No unauthorized access, malware, or harmful automation
- No silent exfiltration of data, credentials, or telemetry
- No destructive system changes without hitl-approver
- No publication of user PII or environment secrets in outputs
Example
Input: User request matching triggers above. Output: Structured result per workflow; local artifacts only unless user opts in.