Documentation menu
On this page

Documentation

WardenClaw puts the risky commands of an AI agent on a Linux server behind a signature. wardend runs the agent under a seccomp filter, stops every exec that trips a rule right in the kernel, and lets it run only with an Ed25519 signature from a device you paired: the phone app, or wardenctl on your laptop. The signing key never lives on the server.

Status: prototype. Flags and formats can still change.

Two ways in

Try it in 5 minutes

No root, no phone, no agent. Install wardend for your own user, run one command under it and approve it from a second terminal with a test key. You see what the kernel stops, what a signed decision does and what lands in the journal.

Try it in 5 minutes

Put it on a server for real

The hardened install: wardend as a root system service, the agent under its own user, so the model cannot turn the gate off. It starts in observe mode, where everything runs and is journaled.

  1. Install wardend: the hardened install, steps 1 to 4.
  2. Get the app: Android, iPhone, or wardenctl on a laptop.
  3. Connect the phone: an address the phone can reach, pairing and a check.
  4. Observe, check the forecast, then ticket: step 5 of the install.

I want to…