Security Analyzer
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-userspace --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-userspace .claude/skills/alibabacloud-ecs-sec-userspace && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "alibabacloud-ecs-sec-userspace" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-userspace into .claude/skills/alibabacloud-ecs-sec-userspace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-userspace", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-userspaceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-userspace --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-userspace .agents/skills/alibabacloud-ecs-sec-userspace && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "alibabacloud-ecs-sec-userspace" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-userspace into .agents/skills/alibabacloud-ecs-sec-userspace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-userspace", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-userspace --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-userspace .cursor/skills/alibabacloud-ecs-sec-userspace && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "alibabacloud-ecs-sec-userspace" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-userspace into .cursor/skills/alibabacloud-ecs-sec-userspace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-userspace", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git --path skills/alibabacloud-ecs-sec-userspace--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-userspace --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-userspace .gemini/skills/alibabacloud-ecs-sec-userspace && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "alibabacloud-ecs-sec-userspace" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-userspace into .gemini/skills/alibabacloud-ecs-sec-userspace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-userspace", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-userspaceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-userspace .github/skills/alibabacloud-ecs-sec-userspace && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "alibabacloud-ecs-sec-userspace" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-userspace into .github/skills/alibabacloud-ecs-sec-userspace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-userspace", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-userspace --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-userspace .opencode/skills/alibabacloud-ecs-sec-userspace && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "alibabacloud-ecs-sec-userspace" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-userspace into .opencode/skills/alibabacloud-ecs-sec-userspace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-userspace", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
alibabacloud-ecs-sec-userspaceLinux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。
Alibabacloud Ecs Sec Userspace is an agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。 与 sec-kernel(内核态 CVE 漏洞检测)互补,共同构成完整的 ECS 安全评估方案。 当用户询问服务器安全、入侵检测、系统审计、恶意软件检测、安全事件响应时使用。 每当需要判断服务器是否被入侵、检查后门木马、分析安全事件时,优先使用此技能。 务必在发现安全异常时主动调用此技能,即使用户没有明确要求安全检查。
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 407 other files, including scripts, reference files and assets (for example `CONTRIBUTOR.md`, `__init__.py` and `assets-origin/ioc/manifest.json`).
It sits in DevOps & Cloud, covering Container orchestration, Vulnerability scanning and Containers. It works with Alibaba Cloud, Linux, Kubernetes and Docker. The repository describes itself as: Troubleshooting skills for Alibaba Cloud ECS. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 809887f. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
terminal (sudo required for full scan)file-readfile-writeFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
python3bashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Alibabacloud Ecs Sec Userspace loads about 2.6k tokens when it runs, and up to ~26k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 756 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- terminal (sudo required for full scan)cd /data/sec-userspace && sudo python3 scripts/setup_permissions.py --autocd /data/sec-userspace && sudo bash scripts/setup.shcd /data/sec-userspace && sudo python3 -m scripts.main --output-dir /data/sec-userspace/workspacecd /data/sec-userspace && sudo python3 scripts/main.pyz --output-dir /data/sec-userspace/workspacecd /data/sec-userspace && sudo python3 -m scripts.main --output-dir /data/sec-userspace/workspacecd /data/sec-userspace && sudo python3 -m scripts.main --format bothcd /data/sec-userspace && sudo python3 -m scripts.main --full-reportcd /data/sec-userspace && sudo python3 -m scripts.main --force| 隐藏进程 | `sudo ls /proc/{pid}/exe -la` |Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from aliyun/alibabacloud-ecs-troubleshoot-skills at commit 809887f, republished under its Apache-2.0 licence (© aliyun). 756 words, ~2,560 tokens.
.claude/skills/alibabacloud-ecs-sec-userspace/SKILL.md (or your agent's skills folder). This skill also uses 402 other files; get the full folder from GitHub.Linux 服务器安全入侵检测与取证工具 | Linux Server Security Intrusion Detection & Forensics Tool
AI Agent 首次使用本 Skill 时,MUST 执行以下权限申请(一次性,后续无需重复):
cd /data/sec-userspace && sudo python3 scripts/setup_permissions.py --auto这将自动:
配置完成后重启 AI 工具即可永久生效。验证权限:
cd /data/sec-userspace && python3 scripts/setup_permissions.py --verify完整流程: 权限申请 → 环境初始化 → 执行扫描 → 反思验证 → 输出结果
cd /data/sec-userspace && sudo bash scripts/setup.sh自动完成:检测/安装 Python >= 3.11、创建 workspace、安装 Skill 到 AI 工具目录。
# 推荐(源码模式)
cd /data/sec-userspace && sudo python3 -m scripts.main --output-dir /data/sec-userspace/workspace
# 编译版(需 Python 3.11 精确匹配)
cd /data/sec-userspace && sudo python3 scripts/main.pyz --output-dir /data/sec-userspace/workspacepyz 失败处理:若出现
bad magic number错误,详见 references/python-runtime.md
报告输出到 /data/sec-userspace/workspace/{YYYY-MM-DD}/report/:
| 文件 | 格式 | 用途 |
|---|---|---|
sec-report-{date}.md | Markdown | 主报告:结论、证据、时间线、修复建议 |
sec-report-{date}.json | JSON | 结构化数据,便于程序化处理 |
attack-chain-{date}.md | Markdown | 攻击链分析 |
sec-userspace-log-{date}.log | Log | 执行日志 |
扫描完成后,必须先执行反思流程,再向用户汇报结果。 详见 Post-Scan Reflection。
覆盖 12 大检测类别、51 个安全分析器、10 个数据采集器,映射 103+ MITRE ATT&CK 技术。
| 检测类别 | 核心能力 |
|---|---|
| 进程异常 | 隐藏进程、反弹 Shell、进程树异常、代码注入 |
| 网络异常 | C2 通信、DNS 隧道、DGA 域名、威胁情报匹配 |
| 认证与凭据 | SSH 后门密钥、暴力破解、PAM 后门、凭据泄露 |
| 持久化机制 | Crontab/Systemd/Shell 配置后门 |
| Rootkit | 内核模块异常、LD_PRELOAD 劫持、io_uring/eBPF Rootkit |
| 恶意软件 | 挖矿、勒索软件、RAT、无文件恶意软件 |
| 内存取证 | 内存注入、RWX 异常、memfd 无文件攻击 |
| 文件系统 | SUID/SGID 异常、Webshell、隐藏文件 |
| 横向移动 | SSH 横向、端口转发、时序关联分析 |
| 容器/K8s | 容器逃逸、RBAC 风险、运行时行为异常 |
完整检测能力列表(含全部分析器和采集器详情)见 references/detection-capabilities.md
MITRE ATT&CK 技术映射详表(80+ 技术编号、14 个战术阶段)见 references/technique-mappings.md
| 项目 | 要求 |
|---|---|
| 架构 | x86_64 (AMD64) |
| 操作系统 | Linux (glibc 2.17+: Ubuntu 14.04+, CentOS 7+, Debian 8+) |
| Python | >= 3.11(setup.sh 可自动安装) |
| 权限 | root (sudo) |
| 网络 | 扫描无需联网;缺少 Python 3.11 时需网络下载 (~30MB) |
{
"permissions": {
"allow": [
"Bash(sudo:*)",
"Bash(python3:*)",
"Read(**)",
"Write(/data/sec-userspace/workspace/**)",
"Write(workspace/**)"
]
}
}支持的 AI 工具:Claude Code、QoderCLI、OpenCode、Windsurf、Cursor、Gemini CLI、Trae。详见 references/permissions.md。
# 基本扫描
cd /data/sec-userspace && sudo python3 -m scripts.main --output-dir /data/sec-userspace/workspace
# 指定输出格式
cd /data/sec-userspace && sudo python3 -m scripts.main --format both
# 完整报告(含时间线、攻击链、交叉关联)
cd /data/sec-userspace && sudo python3 -m scripts.main --full-report
# 高负载时强制执行
cd /data/sec-userspace && sudo python3 -m scripts.main --force
# 列出所有分析器
cd /data/sec-userspace && python3 -m scripts.main --list-analyzers
# 查看资产数据
cd /data/sec-userspace && python3 -m scripts.main --show-assets all
# K8s 部署
cd /data/sec-userspace && python3 -m scripts.main k8s-deploy| 参数 | 说明 | 默认值 |
|---|---|---|
--output-dir PATH | 报告输出目录 | from config |
--format {markdown,json,both} | 输出格式 | both |
--quiet | 静默模式,适合 crontab | from config |
--force | 跳过负载保护,强制执行 | — |
--list-analyzers | 列出全部分析器及耗时 | — |
--show-assets [{all,ioc,whitelist}] | 显示解码后的资产数据 | all |
--no-fp-suppression | 禁用误报抑制(审计模式) | — |
--force-json | 强制生成 JSON 报告 | — |
--full-report | 启用完整报告:时间线、攻击链、交叉关联、覆盖率 | — |
--lang {auto,en,zh,both} | 报告语言 | auto |
--env {auto,development,production,ci,container} | 环境上下文 | auto |
--retention-days N | 报告保留天数 | 180 |
--dry-run | 仅预览,不上报 | — |
| 子命令 | 用途 |
|---|---|
standalone | 独立模式运行(含内置 LLM 客户端) |
k8s-deploy | K8s CronJob 部署、执行、收集结果 |
whitelist | 白名单管理(学习 + 用户自定义) |
perf | 性能监控与分析 |
| 模式 | 路径 | 说明 |
|---|---|---|
| standalone | deploy/standalone/ | 单机直接运行 |
| docker | deploy/docker/ | Docker 容器,含 Dockerfile + compose |
| k8s | deploy/k8s/ | CronJob + RBAC + ConfigMap |
| 结论 | 含义 | 建议操作 |
|---|---|---|
| Compromised | 确认被入侵 | 立即隔离,执行 P0 修复 |
| Highly Suspicious | 高度可疑 | 深入调查,准备 P1 修复 |
| At Risk | 存在风险 | 计划修复,加强监控 |
| No Intrusion | 未发现入侵 | 保持警惕,定期扫描 |
| 级别 | 响应时间 | 说明 |
|---|---|---|
| P0-Critical | 立即 | 确认的入侵,需紧急处理 |
| P1-High | 24h 内 | 高度可疑,需验证和修复 |
| P2-Medium | 1 周内 | 潜在风险,建议优化 |
| P3-Low | 计划内 | 改进建议,安全加固 |
| 指标 | 约束 |
|---|---|
| Quick scan 执行时间 | < 90s |
| Full scan 执行时间 | < 10 min |
| CPU 占用(单核) | < 50% (nice(19) + 自适应节流) |
| 内存占用 | < 200 MB |
| 负载保护 | CPU > 70% 或内存 < 500MB 时自动退出 (--force 跳过) |
扫描完成后,AI Agent 必须先执行反思流程,才能向用户输出结果。
完整流程见 references/post-run-reflection.md。
| 步骤 | 操作 | 要点 |
|---|---|---|
| 0 | 查阅 references/lessons-learned.md | 已知误报直接跳过 |
| 1 | 识别运行环境 | WSL2/K8s/容器/开发机 |
| 2 | 逐条工具验证 | 每条告警执行验证命令 |
| 3 | 汇总判定 | 区分真实告警 vs 误报 |
| 告警类型 | 验证命令 |
|---|---|
| 隐藏进程 | sudo ls /proc/{pid}/exe -la |
| 可疑端口 | sudo ss -tlnp | grep {port} |
| 异常文件 | sudo stat {path} && sudo file {path} |
| SSH 密钥 | sudo cat /root/.ssh/authorized_keys |
| Crontab | sudo crontab -l && sudo ls /etc/cron.d/ |
| Systemd 服务 | sudo systemctl cat {service} |
| 内核模块 | sudo lsmod | grep {module} |
| 网络连接 | sudo ss -anp | grep {ip/port} |
| 环境 | 常见误报 | 判断依据 |
|---|---|---|
| WSL2 | 内核模块告警 | uname -r 含 microsoft |
| 开发机 | Node.js/Python 进程告警 | AI 工具自身进程 |
| Docker Host | overlay 文件系统告警 | /var/lib/docker/overlay2 路径 |
| K8s Node | kubelet 网络告警 | kube-system 命名空间 |
| CI/CD | 临时文件告警 | /tmp 或 /workspace 路径 |
| 规则 | 说明 |
|---|---|
| 验证优先于汇报 | 未用工具验证过的告警,禁止报给用户 |
| 禁止凭经验分类 | 必须有命令输出作为判定依据 |
| 禁止"建议用户检查" | 必须自己执行命令并给出确定结论 |
| 发现新误报必须记录 | 追加到 lessons-learned.md |
当用户询问系统整体安全性时,AI Agent MUST 联动所有可用安全 Skill。
详细协议见 references/call-other-sec-skills.md。
| Skill | 维度 | 调用条件 |
|---|---|---|
| sec-userspace | 用户态入侵检测 | 始终调用 |
| sec-kernel | 内核 CVE 漏洞检测 + PoC 验证 | available_skills 含 sec-kernel 时 MUST 调用 |
结论合成规则(取最严重):
| sec-userspace | sec-kernel | 最终结论 |
|---|---|---|
| No Intrusion | 无漏洞 | Safe |
| No Intrusion | VULNERABLE | At Risk |
| No Intrusion | EXPLOITABLE | At Risk (Critical) |
| At Risk+ | EXPLOITABLE | Highly Suspicious |
| Compromised | 任意 | Compromised |
当以下场景出现时,务必主动调用此技能:
| 问题 | 原因 | 解决方法 |
|---|---|---|
| 权限不足 | 未使用 sudo | sudo python3 -m scripts.main |
| 扫描超时 | 系统负载过高 | 添加 --force |
| 无输出文件 | 输出目录不存在 | mkdir -p /data/sec-userspace/workspace |
| pyz bad magic number | Python 版本不兼容 | 见 references/python-runtime.md |
| Python 版本不足 | < 3.11 | sudo bash scripts/setup.sh |
| 资产数据加载失败 | assets/ 异常 | python3 -m scripts.main --show-assets all |
CONTRIBUTOR.md© aliyun, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 402 other files (scripts, references, assets) in skills/alibabacloud-ecs-sec-userspace of aliyun/alibabacloud-ecs-troubleshoot-skills.
Open the folder on GitHubat commit 809887f
Alibabacloud Ecs Sec Userspace next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Alibabacloud Ecs Sec Userspace this skillaliyun/alibabacloud-ecs-troubleshoot-skills | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Security Analyzeraiskillstore/marketplace | 433 | — | ~1.2k | Automated safety check: Notes | None | |
| Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | |
| Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider | 174 | — | ~2.6k | Automated safety check: Pass | Custom licence | |
| DockerEliasOulkadi/shokunin | 114 | — | ~3.8k | Automated safety check: Notes | MIT | |
| Container Securityhardw00t/ai-security-arsenal | 105 | — | ~2.8k | Automated safety check: Pass | None |
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
microsoft/Docker-Provider
Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.
EliasOulkadi/shokunin
Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…
hardw00t/ai-security-arsenal
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
aliyun/alibabacloud-ecs-troubleshoot-skills
Troubleshoot an Alibaba Cloud ECS Linux OS. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
aliyun/alibabacloud-ecs-troubleshoot-skills
Troubleshoot and repair Alibaba Cloud ECS Windows instances from inside the GuestOS or remotely via Cloud Assistant.
Works with
Categories
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。. Alibabacloud Ecs Sec Userspace is an agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
Alibabacloud Ecs Sec Userspace fits situations like: tasks that involve Container orchestration; tasks that involve Vulnerability scanning; tasks that involve Containers.
Run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a claude-code`. Or copy the skill folder (skills/alibabacloud-ecs-sec-userspace in aliyun/alibabacloud-ecs-troubleshoot-skills) into .claude/skills/alibabacloud-ecs-sec-userspace in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a codex`. Or copy the skill folder (skills/alibabacloud-ecs-sec-userspace in aliyun/alibabacloud-ecs-troubleshoot-skills) into .agents/skills/alibabacloud-ecs-sec-userspace in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-userspace -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alibabacloud-ecs-sec-userspace, .gemini/skills/alibabacloud-ecs-sec-userspace, .github/skills/alibabacloud-ecs-sec-userspace and .opencode/skills/alibabacloud-ecs-sec-userspace in your project.
Going by SKILL.md and its folder, Alibabacloud Ecs Sec Userspace needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and bash). Our summary lists: Python 3; Node.js; Docker. Its frontmatter pre-approves these tools: terminal (sudo required for full scan), file-read, file-write.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Alibabacloud Ecs Sec Userspace is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Alibabacloud Ecs Sec Userspace: Security Analyzer (aiskillstore/marketplace, 433 stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 174 stars) and Docker (EliasOulkadi/shokunin, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aliyun (a GitHub organization) maintains it in aliyun/alibabacloud-ecs-troubleshoot-skills, which has 148 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on August 20, 2026.
Source: aliyun/alibabacloud-ecs-troubleshoot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.