Agent skill

Alibabacloud Ecs Sec Userspace

by aliyun in aliyun/alibabacloud-ecs-troubleshoot-skills

Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

Apache-2.0Auto-check: notesDevOps & Cloud

Install Alibabacloud Ecs Sec Userspace

skills CLI
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-userspace --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-userspace .claude/skills/alibabacloud-ecs-sec-userspace && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
alibabacloud-ecs-sec-userspace
GitHub stars
148
Token cost
~2.6k tokens
SKILL.md length
756 words
Files
403 (incl. scripts, references, assets)
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

  • Works in 6 steps: 环境初始化(首次) → 执行扫描 → 查看报告 → …
  • Tasks that involve Container orchestration
  • SKILL.md covers First Run Setup | 首次运行, Quick Start | 快速开始, What Can It Do? | 能做什么? and Prerequisites | 前置条件, plus 4 more sections
  • Runs Python scripts from its folder; calls python3 and bash

What it does

Alibabacloud Ecs Sec Userspace is an agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。 与 sec-kernel(内核态 CVE 漏洞检测)互补,共同构成完整的 ECS 安全评估方案。 当用户询问服务器安全、入侵检测、系统审计、恶意软件检测、安全事件响应时使用。 每当需要判断服务器是否被入侵、检查后门木马、分析安全事件时,优先使用此技能。 务必在发现安全异常时主动调用此技能,即使用户没有明确要求安全检查。

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 407 other files, including scripts, reference files and assets (for example `CONTRIBUTOR.md`, `__init__.py` and `assets-origin/ioc/manifest.json`).

It sits in DevOps & Cloud, covering Container orchestration, Vulnerability scanning and Containers. It works with Alibaba Cloud, Linux, Kubernetes and Docker. The repository describes itself as: Troubleshooting skills for Alibaba Cloud ECS. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Container orchestration
  • Tasks that involve Vulnerability scanning
  • Tasks that involve Containers

Example prompts

  • “/alibabacloud-ecs-sec-userspace”

Requirements

  • Python 3
  • Node.js
  • Docker
  • Pre-approved tools (allowed-tools): terminal (sudo required for full scan), file-read, file-write

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. 环境初始化(首次)
  2. 执行扫描
  3. 查看报告
  4. Post-Scan Reflection(MANDATORY)
  5. Alert Verification | 告警验证
  6. Functional Consistency | 功能一致性

What it can do on your machine

Read from SKILL.md and the folder at commit 809887f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • terminal (sudo required for full scan)
    • file-read
    • file-write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Alibabacloud Ecs Sec Userspace loads about 2.6k tokens when it runs, and up to ~26k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 756 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~26k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:15
    - terminal (sudo required for full scan)
  • NoteRuns commands with sudoSKILL.md:31
    cd /data/sec-userspace && sudo python3 scripts/setup_permissions.py --auto
  • NoteRuns commands with sudoSKILL.md:55
    cd /data/sec-userspace && sudo bash scripts/setup.sh
  • NoteRuns commands with sudoSKILL.md:64
    cd /data/sec-userspace && sudo python3 -m scripts.main --output-dir /data/sec-userspace/workspace
  • NoteRuns commands with sudoSKILL.md:67
    cd /data/sec-userspace && sudo python3 scripts/main.pyz --output-dir /data/sec-userspace/workspace
  • NoteRuns commands with sudoSKILL.md:166
    cd /data/sec-userspace && sudo python3 -m scripts.main --output-dir /data/sec-userspace/workspace
  • NoteRuns commands with sudoSKILL.md:169
    cd /data/sec-userspace && sudo python3 -m scripts.main --format both
  • NoteRuns commands with sudoSKILL.md:172
    cd /data/sec-userspace && sudo python3 -m scripts.main --full-report
  • NoteRuns commands with sudoSKILL.md:175
    cd /data/sec-userspace && sudo python3 -m scripts.main --force
  • NoteRuns commands with sudoSKILL.md:277
    | 隐藏进程 | `sudo ls /proc/{pid}/exe -la` |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aliyun/alibabacloud-ecs-troubleshoot-skills at commit 809887f, republished under its Apache-2.0 licence (© aliyun). 756 words, ~2,560 tokens.

Download SKILL.mdSave it as .claude/skills/alibabacloud-ecs-sec-userspace/SKILL.md (or your agent's skills folder). This skill also uses 402 other files; get the full folder from GitHub.
name
alibabacloud-ecs-sec-userspace
description
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。 与 sec-kernel(内核态 CVE 漏洞检测)互补,共同构成完整的 ECS 安全评估方案。 当用户询问服务器安全、入侵检测、系统审计、恶意软件检测、安全事件响应时使用。 每当需要判断服务器是否被入侵、检查后门木马、分析安全事件时,优先使用此技能。 务必在发现安全异常时主动调用此技能,即使用户没有明确要求安全检查。
allowed-tools
terminal (sudo required for full scan), file-read, file-write
version
1.4.1
date
2026-05-09

sec-userspace

Linux 服务器安全入侵检测与取证工具 | Linux Server Security Intrusion Detection & Forensics Tool


First Run Setup | 首次运行

AI Agent 首次使用本 Skill 时,MUST 执行以下权限申请(一次性,后续无需重复):

bash
cd /data/sec-userspace && sudo python3 scripts/setup_permissions.py --auto

这将自动:

  1. 检测系统已安装的 AI 工具(Claude Code, Qoder, OpenCode, Windsurf, Cursor, Gemini CLI, Trae)
  2. 配置最小权限集(sudo, read all, write workspace)
  3. 备份已有配置
  4. 验证权限生效

配置完成后重启 AI 工具即可永久生效。验证权限:

bash
cd /data/sec-userspace && python3 scripts/setup_permissions.py --verify

Quick Start | 快速开始

完整流程: 权限申请 → 环境初始化 → 执行扫描 → 反思验证 → 输出结果

Step 1: 环境初始化(首次)
bash
cd /data/sec-userspace && sudo bash scripts/setup.sh

自动完成:检测/安装 Python >= 3.11、创建 workspace、安装 Skill 到 AI 工具目录。

Step 2: 执行扫描
bash
# 推荐(源码模式)
cd /data/sec-userspace && sudo python3 -m scripts.main --output-dir /data/sec-userspace/workspace

# 编译版(需 Python 3.11 精确匹配)
cd /data/sec-userspace && sudo python3 scripts/main.pyz --output-dir /data/sec-userspace/workspace

pyz 失败处理:若出现 bad magic number 错误,详见 references/python-runtime.md

Step 3: 查看报告

报告输出到 /data/sec-userspace/workspace/{YYYY-MM-DD}/report/:

文件格式用途
sec-report-{date}.mdMarkdown主报告:结论、证据、时间线、修复建议
sec-report-{date}.jsonJSON结构化数据,便于程序化处理
attack-chain-{date}.mdMarkdown攻击链分析
sec-userspace-log-{date}.logLog执行日志
Step 4: Post-Scan Reflection(MANDATORY)

扫描完成后,必须先执行反思流程,再向用户汇报结果。 详见 Post-Scan Reflection。


What Can It Do? | 能做什么?

Detection Capabilities | 检测能力

覆盖 12 大检测类别、51 个安全分析器、10 个数据采集器,映射 103+ MITRE ATT&CK 技术。

检测类别核心能力
进程异常隐藏进程、反弹 Shell、进程树异常、代码注入
网络异常C2 通信、DNS 隧道、DGA 域名、威胁情报匹配
认证与凭据SSH 后门密钥、暴力破解、PAM 后门、凭据泄露
持久化机制Crontab/Systemd/Shell 配置后门
Rootkit内核模块异常、LD_PRELOAD 劫持、io_uring/eBPF Rootkit
恶意软件挖矿、勒索软件、RAT、无文件恶意软件
内存取证内存注入、RWX 异常、memfd 无文件攻击
文件系统SUID/SGID 异常、Webshell、隐藏文件
横向移动SSH 横向、端口转发、时序关联分析
容器/K8s容器逃逸、RBAC 风险、运行时行为异常

完整检测能力列表(含全部分析器和采集器详情)见 references/detection-capabilities.md

MITRE ATT&CK 技术映射详表(80+ 技术编号、14 个战术阶段)见 references/technique-mappings.md

Key Features | 核心特性
  • 51 安全分析器 — 覆盖传统威胁、容器安全、内存取证等多维度检测
  • 10 个数据采集器 — 系统/进程/网络/用户/文件/日志/Cron/服务/DNS/软件包 全面采集
  • 103+ MITRE ATT&CK 映射 — 每条告警关联 ATT&CK 技术编号
  • 环境自适应 — 自动识别服务器角色,智能跳过不适用的检测
  • 零系统修改 — 只读操作,不修改系统任何文件
  • IoC 威胁情报 — 内置 base64 编码 IoC 数据库
  • 3 种部署模式 — standalone / docker / k8s

Prerequisites | 前置条件

项目要求
架构x86_64 (AMD64)
操作系统Linux (glibc 2.17+: Ubuntu 14.04+, CentOS 7+, Debian 8+)
Python>= 3.11(setup.sh 可自动安装)
权限root (sudo)
网络扫描无需联网;缺少 Python 3.11 时需网络下载 (~30MB)
Security Model | 安全模型
  • root (sudo) — 读取 /proc、/sys、系统日志等内核信息
  • 只读采集 — 零系统修改,不写入/删除/修改任何系统文件
  • 写入仅限 workspace/ — 仅保存扫描日志和报告
Required Permissions | 最小权限集
json
{
  "permissions": {
    "allow": [
      "Bash(sudo:*)",
      "Bash(python3:*)",
      "Read(**)",
      "Write(/data/sec-userspace/workspace/**)",
      "Write(workspace/**)"
    ]
  }
}

支持的 AI 工具:Claude Code、QoderCLI、OpenCode、Windsurf、Cursor、Gemini CLI、Trae。详见 references/permissions.md。


Command Line | 命令行参考

Core Parameters | 核心参数
bash
# 基本扫描
cd /data/sec-userspace && sudo python3 -m scripts.main --output-dir /data/sec-userspace/workspace

# 指定输出格式
cd /data/sec-userspace && sudo python3 -m scripts.main --format both

# 完整报告(含时间线、攻击链、交叉关联)
cd /data/sec-userspace && sudo python3 -m scripts.main --full-report

# 高负载时强制执行
cd /data/sec-userspace && sudo python3 -m scripts.main --force

# 列出所有分析器
cd /data/sec-userspace && python3 -m scripts.main --list-analyzers

# 查看资产数据
cd /data/sec-userspace && python3 -m scripts.main --show-assets all

# K8s 部署
cd /data/sec-userspace && python3 -m scripts.main k8s-deploy
All Parameters | 完整参数表
参数说明默认值
--output-dir PATH报告输出目录from config
--format {markdown,json,both}输出格式both
--quiet静默模式,适合 crontabfrom config
--force跳过负载保护,强制执行—
--list-analyzers列出全部分析器及耗时—
--show-assets [{all,ioc,whitelist}]显示解码后的资产数据all
--no-fp-suppression禁用误报抑制(审计模式)—
--force-json强制生成 JSON 报告—
--full-report启用完整报告:时间线、攻击链、交叉关联、覆盖率—
--lang {auto,en,zh,both}报告语言auto
--env {auto,development,production,ci,container}环境上下文auto
--retention-days N报告保留天数180
--dry-run仅预览,不上报—
Subcommands | 子命令
子命令用途
standalone独立模式运行(含内置 LLM 客户端)
k8s-deployK8s CronJob 部署、执行、收集结果
whitelist白名单管理(学习 + 用户自定义)
perf性能监控与分析
Deploy Modes | 部署模式
模式路径说明
standalonedeploy/standalone/单机直接运行
dockerdeploy/docker/Docker 容器,含 Dockerfile + compose
k8sdeploy/k8s/CronJob + RBAC + ConfigMap

Understanding Results | 理解扫描结果

Scan Conclusion | 扫描结论
结论含义建议操作
Compromised确认被入侵立即隔离,执行 P0 修复
Highly Suspicious高度可疑深入调查,准备 P1 修复
At Risk存在风险计划修复,加强监控
No Intrusion未发现入侵保持警惕,定期扫描
Alert Priority | 告警优先级
级别响应时间说明
P0-Critical立即确认的入侵,需紧急处理
P1-High24h 内高度可疑,需验证和修复
P2-Medium1 周内潜在风险,建议优化
P3-Low计划内改进建议,安全加固
Performance Constraints | 性能约束
指标约束
Quick scan 执行时间< 90s
Full scan 执行时间< 10 min
CPU 占用(单核)< 50% (nice(19) + 自适应节流)
内存占用< 200 MB
负载保护CPU > 70% 或内存 < 500MB 时自动退出 (--force 跳过)

Post-Scan Reflection | 扫描后反思

MANDATORY — 每次扫描后必须执行

扫描完成后,AI Agent 必须先执行反思流程,才能向用户输出结果。

完整流程见 references/post-run-reflection.md。

Phase 1: Alert Verification | 告警验证
步骤操作要点
0查阅 references/lessons-learned.md已知误报直接跳过
1识别运行环境WSL2/K8s/容器/开发机
2逐条工具验证每条告警执行验证命令
3汇总判定区分真实告警 vs 误报
Show full SKILL.md (304 more words)Show less
Quick Verification Commands | 验证命令速查
告警类型验证命令
隐藏进程sudo ls /proc/{pid}/exe -la
可疑端口sudo ss -tlnp | grep {port}
异常文件sudo stat {path} && sudo file {path}
SSH 密钥sudo cat /root/.ssh/authorized_keys
Crontabsudo crontab -l && sudo ls /etc/cron.d/
Systemd 服务sudo systemctl cat {service}
内核模块sudo lsmod | grep {module}
网络连接sudo ss -anp | grep {ip/port}
Common False Positive Patterns | 常见误报快速判断
环境常见误报判断依据
WSL2内核模块告警uname -r 含 microsoft
开发机Node.js/Python 进程告警AI 工具自身进程
Docker Hostoverlay 文件系统告警/var/lib/docker/overlay2 路径
K8s Nodekubelet 网络告警kube-system 命名空间
CI/CD临时文件告警/tmp 或 /workspace 路径
Phase 2: Functional Consistency | 功能一致性
  • 对照本 SKILL.md 验证功能承诺与实际是否一致
  • 发现不一致立即修复
Core Rules | 核心规则
规则说明
验证优先于汇报未用工具验证过的告警,禁止报给用户
禁止凭经验分类必须有命令输出作为判定依据
禁止"建议用户检查"必须自己执行命令并给出确定结论
发现新误报必须记录追加到 lessons-learned.md

Multi-Skill Security Assessment | 多 Skill 安全联动

当用户询问系统整体安全性时,AI Agent MUST 联动所有可用安全 Skill。

详细协议见 references/call-other-sec-skills.md。

Skill维度调用条件
sec-userspace用户态入侵检测始终调用
sec-kernel内核 CVE 漏洞检测 + PoC 验证available_skills 含 sec-kernel 时 MUST 调用

结论合成规则(取最严重):

sec-userspacesec-kernel最终结论
No Intrusion无漏洞Safe
No IntrusionVULNERABLEAt Risk
No IntrusionEXPLOITABLEAt Risk (Critical)
At Risk+EXPLOITABLEHighly Suspicious
Compromised任意Compromised

Trigger Scenarios | 触发场景

当以下场景出现时,务必主动调用此技能:

  • 用户询问服务器是否被入侵、是否安全
  • 需要进行安全审计或合规检查
  • 发现可疑进程、文件、网络连接
  • 用户提到「安全检查」「入侵检测」「后门」「木马」「挖矿」「Rootkit」「Webshell」等关键词
  • 安全事件响应和取证分析
  • 即使用户只是说「检查一下服务器」或「看看系统有没有问题」,也应主动建议使用此技能
  • 用户询问异常进程、异常网络连接、异常登录时
  • 需要判断告警是否为误报时

For AI Agents | 使用原则

  1. 主动建议 — 用户提到安全问题时,主动建议运行 sec-userspace
  2. 先扫描后回答 — 不要凭经验判断,先用工具验证
  3. 反思过滤 — 汇报前必须执行 Post-Scan Reflection
  4. 证据导向 — 每个告警都要有具体证据和修复建议
  5. 优先级明确 — 按 P0/P1/P2/P3 分级汇报
  6. Python 运行时 — pyz 失败时 MUST 按 references/python-runtime.md 获取 Python 3.11
  7. 多 Skill 联动 — sec-kernel 等安全 Skill 可用时 MUST 调用
Absolute Prohibitions | 绝对禁止
  • 未执行验证命令就向用户报告告警
  • 说"建议用户检查"而不是自己确认
  • 先输出报告再补验证
  • pyz 失败后放弃扫描(MUST 获取 Python 3.11)
  • sec-kernel 可用时不调用就给出"系统安全"结论

Troubleshooting | 故障排除

问题原因解决方法
权限不足未使用 sudosudo python3 -m scripts.main
扫描超时系统负载过高添加 --force
无输出文件输出目录不存在mkdir -p /data/sec-userspace/workspace
pyz bad magic numberPython 版本不兼容见 references/python-runtime.md
Python 版本不足< 3.11sudo bash scripts/setup.sh
资产数据加载失败assets/ 异常python3 -m scripts.main --show-assets all

License & Credits

  • License: MIT License
  • Contributors: See CONTRIBUTOR.md
  • References: UAC, OSSEC, Wazuh, rkhunter, chkrootkit, Falco
  • ATT&CK: MITRE ATT&CK Framework v18

© aliyun, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 402 other files (scripts, references, assets) in skills/alibabacloud-ecs-sec-userspace of aliyun/alibabacloud-ecs-troubleshoot-skills.

  • SKILL.md
  • CONTRIBUTOR.md
  • VERSION
  • __init__.py
  • assets-origin/ioc/domain.b64
  • assets-origin/ioc/hash.b64
  • assets-origin/ioc/ip_port.b64
  • assets-origin/ioc/manifest.json
  • assets-origin/ioc/url.b64
  • assets-origin/whitelist/analyzer_rules.b64
  • assets-origin/whitelist/domain.b64
  • assets-origin/whitelist/hash.b64
  • assets-origin/whitelist/ip_port.b64
  • assets-origin/whitelist/manifest.json
  • assets-origin/whitelist/url.b64
  • assets/ioc/.gitkeep
  • … and 387 more

Open the folder on GitHubat commit 809887f

Compare with similar skills

Alibabacloud Ecs Sec Userspace next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Alibabacloud Ecs Sec Userspace compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Alibabacloud Ecs Sec Userspace this skillaliyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Security Analyzeraiskillstore/marketplace433—~1.2kAutomated safety check: NotesNone
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider174—~2.6kAutomated safety check: PassCustom licence
DockerEliasOulkadi/shokunin114—~3.8kAutomated safety check: NotesMIT
Container Securityhardw00t/ai-security-arsenal105—~2.8kAutomated safety check: PassNone

Similar skills

  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    433 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    174 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Docker

    EliasOulkadi/shokunin

    Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…

    114 GitHub stars~3.8k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed

More from aliyun/alibabacloud-ecs-troubleshoot-skills

  • Alibabacloud Ecs Sec Kernel

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

    148 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check: notes
  • Alibabacloud Ecs Linux Os Troubleshooting

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Troubleshoot an Alibaba Cloud ECS Linux OS. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

    148 GitHub stars~4.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Alibabacloud Ecs Windows Os Troubleshooting

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Troubleshoot and repair Alibaba Cloud ECS Windows instances from inside the GuestOS or remotely via Cloud Assistant.

    148 GitHub stars~6.1k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Alibabacloud Ecs Sec Userspace

What does Alibabacloud Ecs Sec Userspace do?

Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。. Alibabacloud Ecs Sec Userspace is an agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

When should I use Alibabacloud Ecs Sec Userspace?

Alibabacloud Ecs Sec Userspace fits situations like: tasks that involve Container orchestration; tasks that involve Vulnerability scanning; tasks that involve Containers.

How do I install Alibabacloud Ecs Sec Userspace in Claude Code?

Run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a claude-code`. Or copy the skill folder (skills/alibabacloud-ecs-sec-userspace in aliyun/alibabacloud-ecs-troubleshoot-skills) into .claude/skills/alibabacloud-ecs-sec-userspace in your project. Claude Code loads it when a task matches its description.

How do I install Alibabacloud Ecs Sec Userspace in Codex?

Run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a codex`. Or copy the skill folder (skills/alibabacloud-ecs-sec-userspace in aliyun/alibabacloud-ecs-troubleshoot-skills) into .agents/skills/alibabacloud-ecs-sec-userspace in your project. Codex loads it when a task matches its description.

Can I use Alibabacloud Ecs Sec Userspace in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alibabacloud-ecs-sec-userspace, .gemini/skills/alibabacloud-ecs-sec-userspace, .github/skills/alibabacloud-ecs-sec-userspace and .opencode/skills/alibabacloud-ecs-sec-userspace in your project.

What does Alibabacloud Ecs Sec Userspace need to run?

Going by SKILL.md and its folder, Alibabacloud Ecs Sec Userspace needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and bash). Our summary lists: Python 3; Node.js; Docker. Its frontmatter pre-approves these tools: terminal (sudo required for full scan), file-read, file-write.

Does Alibabacloud Ecs Sec Userspace access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Alibabacloud Ecs Sec Userspace safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Alibabacloud Ecs Sec Userspace use?

Alibabacloud Ecs Sec Userspace is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Alibabacloud Ecs Sec Userspace use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.

What are the alternatives to Alibabacloud Ecs Sec Userspace?

Skills that share tags, products or a category with Alibabacloud Ecs Sec Userspace: Security Analyzer (aiskillstore/marketplace, 433 stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 174 stars) and Docker (EliasOulkadi/shokunin, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Alibabacloud Ecs Sec Userspace?

aliyun (a GitHub organization) maintains it in aliyun/alibabacloud-ecs-troubleshoot-skills, which has 148 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on August 20, 2026.

Source: aliyun/alibabacloud-ecs-troubleshoot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.