Skip to content

AI assistants

An AI assistant that can run shell commands can use cv4pve-node-protect to back up the configuration of the nodes when you ask, and to work with the archives: find a file, extract it into a staging folder, compare it with another run, and give you the steps of a restore. It never writes on a node.

The repository ships a skill, skills/cv4pve-node-protect/SKILL.md: a short file in the Agent Skills format that Claude Code, Codex and other assistants load when a request matches its description. It tells the assistant to:

  • connect only with the options file, passed with @, and use it for backup only, never for an SSH session;
  • before a backup, work out which old backups --keep will delete, name them and wait for your agreement;
  • treat the archives as secrets: not print what is in them, not copy them elsewhere, and leave the restore to you.

Install it with the skills command, which needs Node.js:

npx skills add Corsinvest/cv4pve-node-protect

Or copy the file into the skills folder of your assistant: .claude/skills/ for Claude Code,.agents/skills/ for Codex, in the project or under your home folder:

mkdir -p .claude/skills/cv4pve-node-protect
curl -fL -o .claude/skills/cv4pve-node-protect/SKILL.md https://raw.githubusercontent.com/Corsinvest/cv4pve-node-protect/master/skills/cv4pve-node-protect/SKILL.md

The other cv4pve tools use an API token, which you can limit to reading. cv4pve-node-protect connects as root over SSH, and there is no read-only root: an assistant that can read the options file can do anything on every node, and the skill cannot prevent that. If that is more than you want to give it, run the backup yourself or on a schedule and let the assistant work on the archives, which needs no access to the nodes.

The archives hold what is on the nodes, secrets included: give the assistant access only to the folder it needs.