Documentation
WardenClaw puts the risky commands of an AI agent on a Linux server behind a signature. wardend runs the agent under a seccomp filter, stops every exec that trips a rule right in the kernel, and lets it run only with an Ed25519 signature from a device you paired: the phone app, or wardenctl on your laptop. The signing key never lives on the server.
Status: prototype. Flags and formats can still change.
Two ways in
Try it in 5 minutes
No root, no phone, no agent. Install wardend for your own user, run one command under it and approve it from a second terminal with a test key. You see what the kernel stops, what a signed decision does and what lands in the journal.
Put it on a server for real
The hardened install: wardend as a root system service, the agent under its own user, so the model cannot turn the gate off. It starts in observe mode, where everything runs and is journaled.
- Install wardend: the hardened install, steps 1 to 4.
- Get the app: Android, iPhone, or
wardenctlon a laptop. - Connect the phone: an address the phone can reach, pairing and a check.
- Observe, check the forecast, then ticket: step 5 of the install.
I want to…
- see what gets stopped and why: How it works on the main page, Modes and Policy modes in the CLI reference.
- know why the model can’t just turn it off: Why the model can’t turn it off.
- check a release before I install it: Verify releases.
- approve from a script or a laptop: External approvers and test automation.
- use an iPhone: iPhone app, Push notifications (APNs).
- see a card on a locked phone: Notifications on a locked phone.
- look up a command, a flag or a config key: CLI reference.
- step back to observe or remove it: Uninstall.
- report a vulnerability: Security policy.