I have installed OpenClaw on Hetzner. I am debugging with Manus.im with a new SSH key every time. Manus has debugged every issue I encountered so far. Just want to check, is that safe procedure ?
Solution
Nice — glad you tightened it up.
Two last “belt + suspenders” things that are worth doing after any third‑party SSH debugging (even if you trust them):
1) Rotate secrets that were present on the box - Discord bot token / any channel tokens - model API keys - OpenClaw gateway/operator tokens If they had shell access, assume anything readable by that user could’ve been copied.
2) Quick audit + cleanup - Remove the
manus-debug
manus-debug
user + its
authorized_keys
authorized_keys
(or lock the account) - Sanity-check for persistence: