Agent skill

Alibabacloud Ecs Sec Kernel

by aliyun in aliyun/alibabacloud-ecs-troubleshoot-skills

Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

Apache-2.0Auto-check: notesSecurity

Install Alibabacloud Ecs Sec Kernel

skills CLI
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-kernel --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-kernel .claude/skills/alibabacloud-ecs-sec-kernel && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
alibabacloud-ecs-sec-kernel
GitHub stars
148
Token cost
~2.4k tokens
SKILL.md length
414 words
Files
823 (incl. scripts, references, assets)
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

  • Tasks that involve Vulnerability scanning
  • SKILL.md covers 触发场景, ⚠️ 安全声明, 快速使用 and CLI 参数, plus 7 more sections
  • Runs Shell and Python scripts from its folder; calls python3
  • Tasks that involve Capture the flag

What it does

Alibabacloud Ecs Sec Kernel is an agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计。 88 个内核 CVE 检测器(2003-2026),覆盖 Netfilter/eBPF/TLS/iouring/xfrm 等子系统的本地提权(LPE)漏洞。 采用 CTF 挑战模式客观验证漏洞可利用性:nobody 用户通过内核漏洞写入/读取 root 文件即为提权成功。 PoC 二进制从源码动态编译(--compile-poc),无需预置二进制文件。需要 root 权限(sudo)运行。 与 sec-userspace(用户态入侵检测)互补,共同构成完整的 ECS 安全评估方案。 务必在检测内核漏洞时使用此技能。每当需要验证 CVE 或执行 PoC 验证时,优先调用此技能。 当用户提到内核安全、CVE 检测、漏洞利用验证、提权漏洞时,主动触发。

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 826 other files, including scripts, reference files and assets (for example `CHANGELOG.md`, `CONTRIBUTOR.md` and `__init__.py`).

It sits in Security, covering Vulnerability scanning and Capture the flag. It works with Alibaba Cloud and Linux. The repository describes itself as: Troubleshooting skills for Alibaba Cloud ECS. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Vulnerability scanning
  • Tasks that involve Capture the flag

Example prompts

  • “/alibabacloud-ecs-sec-kernel”

Requirements

  • Python 3
  • A Bash shell
  • Pre-approved tools (allowed-tools): terminal (sudo required), file-read, file-write

What it can do on your machine

Read from SKILL.md and the folder at commit 809887f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • terminal (sudo required)
    • file-read
    • file-write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell and Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Alibabacloud Ecs Sec Kernel loads about 2.4k tokens when it runs, and up to ~7.7k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 414 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:13
    - terminal (sudo required)
  • NoteRuns commands with sudoSKILL.md:50
    sudo python3 -m scripts --compile-poc --verbose
  • NoteRuns commands with sudoSKILL.md:53
    sudo python3 -m scripts --verbose
  • NoteRuns commands with sudoSKILL.md:56
    sudo python3 -m scripts --cve-id CVE-2026-31431 -v
  • NoteRuns commands with sudoSKILL.md:62
    sudo python3 -m scripts --format json -v

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aliyun/alibabacloud-ecs-troubleshoot-skills at commit 809887f, republished under its Apache-2.0 licence (© aliyun). 414 words, ~2,371 tokens.

Download SKILL.mdSave it as .claude/skills/alibabacloud-ecs-sec-kernel/SKILL.md (or your agent's skills folder). This skill also uses 822 other files; get the full folder from GitHub.
name
alibabacloud-ecs-sec-kernel
description
Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计。 88 个内核 CVE 检测器(2003-2026),覆盖 Netfilter/eBPF/TLS/io_uring/xfrm 等子系统的本地提权(LPE)漏洞。 采用 CTF 挑战模式客观验证漏洞可利用性:nobody 用户通过内核漏洞写入/读取 root 文件即为提权成功。 PoC 二进制从源码动态编译(--compile-poc),无需预置二进制文件。需要 root 权限(sudo)运行。 与 sec-userspace(用户态入侵检测)互补,共同构成完整的 ECS 安全评估方案。 务必在检测内核漏洞时使用此技能。每当需要验证 CVE 或执行 PoC 验证时,优先调用此技能。 当用户提到内核安全、CVE 检测、漏洞利用验证、提权漏洞时,主动触发。
allowed-tools
terminal (sudo required), file-read, file-write
version
1.4.1

sec-kernel

Linux 内核 CVE 漏洞检测与 PoC 验证工具。88 个内核漏洞检测器,CTF 挑战模式验证。

Version: 1.4.1 (JSON-driven architecture)

触发场景

当以下场景出现时,务必主动调用此技能:

  • 检测 Linux 内核漏洞
  • 验证特定 CVE 是否可利用
  • 执行 PoC 三阶段验证(Prepare → Run → Post)
  • 内核安全评估或审计
  • 用户提到 "内核安全"、"CVE"、"提权漏洞"、"PoC" 等关键词
  • 需要判断当前内核版本是否存在已知漏洞
  • 执行本地提权(LPE)路径验证

⚠️ 安全声明

PoC 验证可能导致 kernel crash (panic/hang/deadlock),建议在隔离的虚拟机/可快照环境中运行。 PoC 不会永久改写系统文件,不会进行持久化提权。所有临时修改均在 Post 阶段完整恢复。 使用本工具即表示您同意遵守 完整安全声明 中的所有条款。 违规使用需承担全部法律责任。

快速使用

bash
# 从 skill 根目录执行:

# 需要 root 权限(sudo)

# 首次运行:编译 PoC 二进制 + 全量检测(推荐)
sudo python3 -m scripts --compile-poc --verbose

# 全量检测与 PoC 验证(poc-bin 已编译后)
sudo python3 -m scripts --verbose

# 单 CVE 验证
sudo python3 -m scripts --cve-id CVE-2026-31431 -v

# 列出所有检测器(无需 root)
python3 -m scripts --list-detectors

# 输出 JSON 格式报告
sudo python3 -m scripts --format json -v

CLI 参数

参数类型默认值说明
--modechoicehost运行模式(仅 host,Linux 服务器环境)
--poc-outputpath./workspacePoC 证据输出目录
--poc-timeoutint30PoC 执行超时时间(秒)
--no-prepareflagoff跳过 Prepare 阶段
--no-postflagoff跳过 Post 阶段
--poc-userstringnobodyRun 阶段执行用户(降权执行)
--no-force-demoteflagoff不强制降权到非特权用户
--compile-pocflagoff自动编译缺失的 PoC 二进制文件(plain 模式)
--output-dirpath./workspace报告输出目录
--formatchoicemarkdown报告格式(markdown / json)
--cve-idstring-仅检测指定 CVE
--configpath-配置文件路径
--verbose / -vflagoff详细输出
--list-detectorsflagoff列出所有检测器(无需 root)
关键参数说明

默认行为: 所有在 kernel_cves.yaml 中 enabled: true 的 CVE 都会自动执行 PoC 验证,无需额外参数。唯一跳过 PoC 的条件是将 CVE 设置为 enabled: false。

--compile-poc: 当 poc-bin/ 目录下缺少对应 ELF binary 时,自动调用 poc-src/build.sh 编译。首次运行时必须使用此参数(poc-bin/ 不再随仓库分发,需从源码动态编译)。

Why: PoC 二进制从源码动态编译,避免在 git 中存储大量 ELF 文件。编译采用静态链接 + strip,确保跨发行版兼容。

--no-prepare / --no-post: 跳过三阶段验证中的 Prepare 或 Post 阶段。用于调试目的,生产环境建议保留完整三阶段。

--poc-user: Run 阶段以指定用户身份执行 PoC binary,默认 nobody(uid=65534)。用于验证 LPE(本地提权)路径。

--no-force-demote: 默认情况下 PoC 执行会强制降权到 --poc-user 指定的非特权用户。此参数禁用强制降权。

为什么需要 sudo(root 权限)

PoC 三阶段验证需要 root 权限的原因:

  • Phase 1 (Prepare): 需要加载内核模块(modprobe algif_aead、modprobe esp4 等)、创建 root 拥有的目标文件、配置 xfrm SA/SP 等安全策略
  • Phase 3 (Post): 需要读取 root 文件验证写入结果、卸载内核模块、清理 xfrm 状态、恢复系统状态
  • 权限分离: Phase 2 (Run) 故意降权到 nobody,以验证漏洞是否能让非特权用户越权操作
为什么使用 CTF 模式

CTF 挑战模式的设计理由:

  • 客观验证: 通过文件内容的读/写来客观证明漏洞是否触发,而非主观判断
  • 提权证据: nobody 用户成功写入 root 文件 = 证明存在 LPE 路径
  • 安全约束: PoC 不会真正执行 setuid(0),只是通过文件操作证明漏洞可被利用
  • 可复现性: CTF flag 每次随机生成,确保每次验证都是真实触发而非缓存结果

检测器统计

指标数量
总检测器数88
write_root_file 模式84
read_root_file 模式24
uaf 模式5
Show full SKILL.md (165 more words)Show less

新增功能 (v1.2.0)

PoC 执行统计模块

每次执行完成后自动输出详细统计报表,包含:

  • SUCCESS(EXPLOITABLE / NOT_EXPLOITABLE)分类统计
  • FAILED(TIMEOUT / CRASH / MISSING_BIN / PARSE_ERROR / PERMISSION)细分
  • SKIPPED(NO_MODULE)
  • 失败分析(root cause + recommendation + 是否为 PoC 实现问题)
三种 PoC 模式标准化
模式目标文件权限验证方式数量
write_root_fileroot:root 0644nobody 通过内核漏洞写入 root 文件86
read_root_fileroot:root 0400nobody 通过内核漏洞读取 root 文件24
uafN/AUse-After-Free 利用验证5
增强的证据展示
  • CTF flag 验证(write 模式:写入并回读确认;read 模式:读取受保护内容)
  • 失败分析引擎(自动判定 root cause 并给出修复建议)
  • PoC 实现问题标记([PoC-IMPL] 标签区分环境问题和代码问题)
  • 三阶段完整证据链输出

输出格式

检测摘要
==============================================================
  sec-kernel v1.4.1 - Linux Kernel CVE Detection
==============================================================
  Kernel: 5.15.0-91-generic (x86_64)
  Mode: host (Linux Server)
==============================================================

==============================================================
  Detection Summary
==============================================================
  Total CVEs checked:     88
  Vulnerable:             3
  Not Vulnerable:         80
  Uncertain:              2
  PoC Exploitable:        2
  Execution time:         45.32s
==============================================================
PoC 执行统计
================================================================
  sec-kernel PoC Execution Statistics
================================================================
  Total Detectors:     88    (with PoC capability)
  PoC Executed:        83
  ------------------------------------------------------------
  SUCCESS (ran correctly):     78
    +- EXPLOITABLE:            2   (vulnerability confirmed)
    +- NOT_EXPLOITABLE:        76  (kernel patched/mitigated)
  ------------------------------------------------------------
  FAILED (execution error):    5
    +- TIMEOUT:                2
    +- CRASH:                  1
    +- MISSING_BIN:            0
    +- PARSE_ERROR:            2
    +- PERMISSION:             0
  ------------------------------------------------------------
  SKIPPED:                     2
    +- NO_MODULE:              2
  ------------------------------------------------------------
  Execution Time:         45.32s
================================================================
CTF 挑战模式输出示例
⚠️  SECURITY DISCLAIMER / 安全声明
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
本工具仅限在已授权的隔离测试环境中使用。
严禁用于生产环境或未授权系统。违规使用需承担全部法律责任。
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

[Phase 1: Prepare] (root)
  ✓ Loaded kernel module: algif_aead
  ✓ Created target file: /tmp/sec-kernel-poc-XXXX/poc_target (root:root 0644)
  ✓ Initial content: writeme_a3f8b2c1

[Phase 2: Run] (nobody, uid=65534)
  CTF_READ_BEFORE:writeme_a3f8b2c1
  CTF_WRITE:ctf{164d74cd804f9361} (attempting...)
  CTF_READ_AFTER:ctf{164d74cd804f9361}
  CTF_FLAG:ctf{164d74cd804f9361}
  POC_RESULT:EXPLOITABLE

[Phase 3: Post] (root)
  ✓ File content verified: ctf{164d74cd804f9361} ✓ MATCH
  ✓ Cleanup completed
  ✓ System state restored

[RESULT] CVE-2026-31431: EXPLOITABLE (confidence=0.95)
关键输出字段
字段含义
CTF_READ_BEFORE:PoC 执行前读取的原始文件内容
CTF_WRITE:PoC 尝试写入的 CTF 值
CTF_READ_AFTER:PoC 执行后读取的文件内容
CTF_FLAG:ctf{xxx}漏洞利用成功的标志值
POC_RESULT:EXPLOITABLE漏洞可利用
POC_RESULT:NOT_EXPLOITABLE漏洞不可利用(内核已修复)
结果判定
结果含义建议操作
EXPLOITABLE当前内核存在可利用漏洞立即升级内核
NOT_EXPLOITABLE漏洞条件不满足或已修复无需操作
DETECTION_ONLY版本匹配但未执行 PoC建议进一步验证
CTF 提权验证证据

以下 CVE 已在真实内核环境中通过 CTF 挑战模式验证提权成功(EXPLOITABLE),CTF flag 每次随机生成。

CVE-2026-31431 (CRITICAL) - AF_ALG AEAD splice 页缓存污染
[Phase 1: Prepare] (root)
  Created CTF target: /tmp/sec-kernel-poc-XXXX/poc_target_canary
  mode=write_root_file, uid=0, perm=644
  Initial content: writeme_f9de12afe0d6da5a

[Phase 2: Run] (nobody, uid=65534)
  CTF_WRITE:ctf{dddb28301f24e3db} (attempting...)
  CTF_FLAG:ctf{dddb28301f24e3db}
  POC_RESULT:EXPLOITABLE

[Phase 3: Post] (root)
  CTF write_root_file PASSED: inner value matches (dddb28301f24e3db)
  Rollback executed: target file removed
  System state restored

[RESULT] CVE-2026-31431: EXPLOITABLE (confidence=0.95)
  Kernel: 6.6.87.2-microsoft-standard-WSL2
  Exploit path: AF_ALG AEAD authencesn + splice() -> page cache corruption
CVE-2026-PENDING-DIRTYFRAG (CRITICAL) - DirtyFrag ESP+RxRPC 双变体
[Phase 1: Prepare] (root)
  Created CTF target: /tmp/sec-kernel-poc-XXXX/poc_target_dirtyfrag
  mode=write_root_file, uid=0, perm=644, size=4096
  Module state snapshot: esp4=loaded

[Phase 2: Run] (nobody, uid=65534)
  CTF_WRITE:ctf{ab2084cd52cdad11} (attempting via rxrpc/rxkad...)
  RxRPC variant failed (EAFNOSUPPORT), trying ESP/xfrm fallback...
  CTF_WRITE:ctf{ab2084cd52cdad11} (attempting via esp/xfrm fallback...)
  CTF_FLAG:ctf{ab2084cd52cdad11}
  POC_RESULT:EXPLOITABLE

[Phase 3: Post] (root)
  CTF write_root_file PASSED: inner value matches (ab2084cd52cdad11)
  Rollback executed: target file removed
  System state restored

[RESULT] CVE-2026-PENDING-DIRTYFRAG: EXPLOITABLE (confidence=0.95)
  Kernel: 6.6.87.2-microsoft-standard-WSL2
  Exploit path: ESP/xfrm variant (RxRPC fallback) -> splice() page cache write
  Dual-variant: RxRPC (Ubuntu 24.04) / ESP (WSL2) automatic fallback

三阶段执行流程

Phase 1 (root):   准备环境 — 加载模块、创建目标文件、记录初始状态
Phase 2 (nobody): 执行 PoC — 读原值 → 漏洞利用写入 → 读回验证
Phase 3 (root):   验证清理 — 独立确认写入结果、恢复系统状态

支持的 CVE

完整 CVE 检测列表见 references/cve-list.md(88 个内核漏洞检测器,全部启用 CTF 挑战模式验证)。

覆盖子系统:Netfilter/nf_tables (18) | eBPF/BPF (8) | Network/Socket (12) | TLS (7) | io_uring (3) | Memory/Page Cache (5) | Filesystem (3) | IPsec/xfrm (3) | ptrace/cred (3) | Others (23)

系统要求

  • Linux x86_64
  • Python 3.8+
  • root 权限(sudo)
  • 内核模块加载能力(modprobe)

日志

PoC 执行日志:workspace/poc-{CVE-ID}.log 回退路径:/tmp/poc-{CVE-ID}.log(workspace 不可写时)

© aliyun, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 822 other files (scripts, references, assets) in skills/alibabacloud-ecs-sec-kernel of aliyun/alibabacloud-ecs-troubleshoot-skills.

  • SKILL.md
  • CHANGELOG.md
  • CONTRIBUTOR.md
  • VERSION
  • __init__.py
  • __main__.py
  • assets/.gitkeep
  • bundle_python311.sh
  • configs/kernel_cve_database.json
  • configs/kernel_cves.yaml
  • configs/sec-kernel.yaml
  • install.sh
  • poc-src/Makefile
  • poc-src/build.sh
  • poc-src/common/.gitkeep
  • poc-src/common/poc_common.h
  • poc-src/common/safe_syscall.h
  • … and 806 more

Open the folder on GitHubat commit 809887f

Compare with similar skills

Alibabacloud Ecs Sec Kernel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Alibabacloud Ecs Sec Kernel compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Alibabacloud Ecs Sec Kernel this skillaliyun/alibabacloud-ecs-troubleshoot-skills148—~2.4kAutomated safety check: NotesApache-2.0
Secknowledge SkillPa55w0rd/secknowledge-skill425—~2.7kAutomated safety check: PassNone
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT
Remediate Image Cveskubernetes-sigs/cloud-provider-azure294—~3.9kAutomated safety check: PassApache-2.0
Network Scannerptn1411/skill219—~1.4kAutomated safety check: NotesNone
Ctf Forensicswgpsec/AboutSecurity1.8k—~878Automated safety check: NotesNone

Similar skills

  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    425 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 26 days ago
    SecurityAuto-check: notes
  • Remediate Image Cves

    kubernetes-sigs/cloud-provider-azure

    Official

    Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification…

    294 GitHub stars~3.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Network Scanner

    ptn1411/skill

    Run authorized network reconnaissance with Nmap on Windows (or Linux).

    219 GitHub stars~1.4k tokensUpdated 18 days ago
    SecurityAuto-check: notes
  • Ctf Forensics

    wgpsec/AboutSecurity

    CTF 数字取证与信号分析技术。当挑战提供磁盘镜像(.dd/.E01)、内存 dump(.raw/.vmem)、网络抓包(.pcap/.pcapng)、隐写图片/音频、Windows 事件日志(.evtx)时使用。覆盖 Volatility 内存分析、Wireshark 流量还原、binwalk 隐写提取、文件系统恢复等取证全链路

    1.8k GitHub stars~878 tokensUpdated today
    SecurityAuto-check: notes
  • Defender For Endpoint

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation…

    175 GitHub stars~2.3k tokensUpdated 3 mo ago
    SecurityAuto-check passed

More from aliyun/alibabacloud-ecs-troubleshoot-skills

  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Alibabacloud Ecs Linux Os Troubleshooting

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Troubleshoot an Alibaba Cloud ECS Linux OS. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

    148 GitHub stars~4.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Alibabacloud Ecs Windows Os Troubleshooting

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Troubleshoot and repair Alibaba Cloud ECS Windows instances from inside the GuestOS or remotely via Cloud Assistant.

    148 GitHub stars~6.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Alibabacloud Ecs Sec Kernel

What does Alibabacloud Ecs Sec Kernel do?

Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. Alibabacloud Ecs Sec Kernel is an agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

When should I use Alibabacloud Ecs Sec Kernel?

Alibabacloud Ecs Sec Kernel fits situations like: tasks that involve Vulnerability scanning; tasks that involve Capture the flag.

How do I install Alibabacloud Ecs Sec Kernel in Claude Code?

Run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a claude-code`. Or copy the skill folder (skills/alibabacloud-ecs-sec-kernel in aliyun/alibabacloud-ecs-troubleshoot-skills) into .claude/skills/alibabacloud-ecs-sec-kernel in your project. Claude Code loads it when a task matches its description.

How do I install Alibabacloud Ecs Sec Kernel in Codex?

Run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a codex`. Or copy the skill folder (skills/alibabacloud-ecs-sec-kernel in aliyun/alibabacloud-ecs-troubleshoot-skills) into .agents/skills/alibabacloud-ecs-sec-kernel in your project. Codex loads it when a task matches its description.

Can I use Alibabacloud Ecs Sec Kernel in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alibabacloud-ecs-sec-kernel, .gemini/skills/alibabacloud-ecs-sec-kernel, .github/skills/alibabacloud-ecs-sec-kernel and .opencode/skills/alibabacloud-ecs-sec-kernel in your project.

What does Alibabacloud Ecs Sec Kernel need to run?

Going by SKILL.md and its folder, Alibabacloud Ecs Sec Kernel needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3; A Bash shell. Its frontmatter pre-approves these tools: terminal (sudo required), file-read, file-write.

Does Alibabacloud Ecs Sec Kernel access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Alibabacloud Ecs Sec Kernel safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Alibabacloud Ecs Sec Kernel use?

Alibabacloud Ecs Sec Kernel is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Alibabacloud Ecs Sec Kernel use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.

What are the alternatives to Alibabacloud Ecs Sec Kernel?

Skills that share tags, products or a category with Alibabacloud Ecs Sec Kernel: Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars), Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Remediate Image Cves (kubernetes-sigs/cloud-provider-azure, 294 stars) and Network Scanner (ptn1411/skill, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Alibabacloud Ecs Sec Kernel?

aliyun (a GitHub organization) maintains it in aliyun/alibabacloud-ecs-troubleshoot-skills, which has 148 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on August 20, 2026.

Source: aliyun/alibabacloud-ecs-troubleshoot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.