Firewall Manager

Manage UFW and iptables rules from Hermes with threat detection

Security⚠ ReviewAdvancedv1.0.0
Last verified:2026-06-01
Beta Skill

Can block access if misconfigured. Verify rules before applying them on a production host.

About

Manages firewall rules for your server so Hermes can safely open ports, close risky access and whitelist trusted IPs. Built for admins who need fast but controlled network changes with real-time threat detection and automatic blocking of suspicious IPs.

Use Cases

  • Open a port for a new service deployment
  • Restrict SSH access to a trusted IP range
  • Auto-block IPs that trigger multiple failed login attempts

What Firewall Manager can access

Broad access

Read this skill's SKILL.md in full before installing it. Run it against a disposable host or test account first, and give it the narrowest credentials that still work.

  • Can make changes that are hard to undo

    The listing carries an explicit maintainer warning. Test this against something disposable before pointing it at anything you care about.

    Listing carries a maintainer warning: "Can block access if misconfigured. Verify rules before applying them on a production host."

  • Runs commands on the host

    This skill executes commands on the machine running the agent. That is the broadest permission you can grant: anything the agent user can do, this skill can do.

    This skill's own description refers to "iptables"

  • Changes system or network configuration

    It modifies host-level configuration such as firewall rules, certificates or service definitions. A mistake here can lock you out of the machine.

    This skill's own description refers to "firewall"

These permissions are inferred from this listing — the credentials it declares, any maintainer warning, and the operations its own description mentions. ClawVault has not audited this skill's source code. Treat it as a starting point for your own review, not a substitute for one.

Installing Firewall Manager on Hermes Agent

Hermes skills are on-demand knowledge documents stored in hermes/skills/, which is the single source of truth. Bundled skills are copied there on a fresh install, and hub-installed and agent-created skills land there too. Every installed skill automatically becomes a slash command, so a skill named plan is invoked with /plan.

  1. 1

    Search for the skill

    hermes skills search firewall

    Add --source to widen the search: official for curated skills, skills-sh for the public skills.sh directory, browse-sh for site-specific browser automation, or well-known to point Hermes at a site publishing its own skill index.

  2. 2

    Inspect it before installing

    hermes skills inspect official/<category>/firewall

    inspect shows the skill's contents and metadata. Use the fully qualified identifier that search returned, which includes its source and category.

  3. 3

    Install it

    hermes skills install official/<category>/firewall

    Identifiers are source-qualified, for example official/migration/openclaw-migration or skills-sh/anthropics/skills/pdf. You can also install straight from a URL that serves a SKILL.md. --force overrides non-dangerous policy blocks but will not override a dangerous scan verdict.

  4. 4

    Use it as a slash command

    /firewall

    Installed skills become slash commands in any chat session. Run hermes skills list to see everything available, or /skills from inside a session.

Commands follow the official Hermes Agent documentation. Placeholders such as <owner> are filled in by the search step, because registry references are publisher-scoped.

Version & Updates

Current Version
1.0.0
Last Updated
2026-06-01

Safety & verification

Needs review
Not yet independently confirmed. Read the SKILL.md before running it on a Hermes Agent install you care about.

How Hermes Agent screens skills

Hermes checks third-party and community skills against policy before installing, and --force will not override a verdict it considers dangerous. Because Hermes can also write its own skills at runtime, review what the Curator has kept periodically with hermes skills list.

Review before installing

Read this skill's SKILL.md before installing it, so you know what commands it runs and which credentials it reads.

Recommended

Running on a VPS?

Deploy OpenClaw, Hermes, or PicoClaw on Bluehost with the right template for the job.

Related Skills in Security