Agent skill

Harden

by alsk1992 in alsk1992/CloddsBot

“VPS security auditing and hardening”

— description from SKILL.md by alsk1992
MITAuto-check: notes

Install Harden

skills CLI
$ npx skills add alsk1992/CloddsBot --skill harden -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alsk1992/CloddsBot harden --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alsk1992/CloddsBot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/skills/bundled/harden .claude/skills/harden && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
harden
GitHub stars
3k
Token cost
~423 tokens
SKILL.md length
160 words
Files
2
Skills in repo
116
Repo updated
First seen
Licence
MIT

At a glance

  • SKILL.md covers Commands, Options, Examples and Security Checks
  • Runs TypeScript scripts from its folder

About this skill

Harden is a skill in alsk1992/CloddsBot (3k stars). Its SKILL.md is about 423 tokens, with 1 other file in the folder. Licence: MIT.

What it can do on your machine

Read from SKILL.md and the folder at commit c930628. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Harden loads about 423 tokens when it runs. Until then it costs about 11 tokens; SKILL.md has 160 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~11
When it runs · the whole SKILL.md, loaded when a task matches
~423

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:73
    | Sudo Users | At least one non-root sudo user |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alsk1992/CloddsBot at commit c930628, republished under its MIT licence (© alsk1992). 160 words, ~423 tokens.

Download SKILL.mdSave it as .claude/skills/harden/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
harden
description
VPS security auditing and hardening
emoji
🔒
commands
/harden

VPS Hardening

Security auditing and automated hardening for remote servers.

Commands

/harden audit <host>

Run security audit against a server. Checks:

  • System updates
  • Auto-updates configuration
  • SSH root login status
  • Password authentication
  • Firewall status
  • Fail2ban status
  • System uptime
  • Listening services
  • Sudo user configuration
/harden fix <host>

Apply safe fixes that won't lock you out:

  • Install system updates
  • Enable unattended-upgrades
  • Configure UFW firewall
  • Install and enable fail2ban
  • Set SSH MaxAuthTries
/harden emergency <host>

Quick 10-minute hardening for new servers:

  • Full system update
  • Firewall setup
  • Fail2ban installation
  • Root password lock
/harden report <host>

Generate markdown security report.

Options

OptionDescription
--user=NAMESSH user (default: root)
--dry-runPreview changes without applying

Examples

/harden audit 192.168.1.100
/harden fix myserver.com --user=admin
/harden emergency vps.example.com --dry-run
/harden report server.io > security-report.md

Security Checks

CheckPass Criteria
System Updates0 pending updates
Auto Updatesunattended-upgrades installed
Root LoginPermitRootLogin no
Password AuthPasswordAuthentication no
FirewallUFW active or iptables configured
Fail2banService running
Uptime< 90 days
Services< 10 listening ports
Sudo UsersAt least one non-root sudo user
MaxAuthTriesSet to 3 or less

© alsk1992, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in src/skills/bundled/harden of alsk1992/CloddsBot.

  • SKILL.md
  • index.ts

Open the folder on GitHubat commit c930628

Compare with similar skills

Harden next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Harden compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Harden this skillalsk1992/CloddsBot3k—~423Automated safety check: NotesMIT
Production Auditaffaan-m/ECC276k1 repos~1.9kAutomated safety check: PassMIT
Aims Auditalirezarezvani/claude-skills28k—~1.3kAutomated safety check: PassMIT
Geo Auditsickn33/agentic-awesome-skills47k1 repos~3.4kAutomated safety check: NotesMIT
OmniRoute Audit and Policy CLIdiegosouzapw/OmniRoute75k—~733Automated safety check: PassMIT
Audit Preparationsickn33/agentic-awesome-skills47k1 repos~5.3kAutomated safety check: PassMIT

Similar skills

  • Production Audit

    affaan-m/ECC

    Local-evidence production readiness audit for shipped apps, pre-launch reviews, post-merge checks, and "what breaks in prod?" questions without sending repo data to an external audit service.

    276k GitHub starsUsed in 1 repo~1.9k tokens
    Product & Project ManagementAuto-check passed
  • Aims Audit

    alirezarezvani/claude-skills

    /cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation.

    28k GitHub stars~1.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Geo Audit

    sickn33/agentic-awesome-skills

    Full website GEO+SEO audit with parallel subagent delegation.

    47k GitHub starsUsed in 1 repo~3.4k tokens
    Marketing & SEOAuto-check: notes
  • OmniRoute Audit and Policy CLI

    diegosouzapw/OmniRoute

    Command reference for omniroute's audit, logs, policy and telemetry commands: search and export audit trails, manage access policies and review request history for compliance work.

    75k GitHub stars~733 tokensUpdated today
    SecurityAuto-check passed
  • Audit Preparation

    sickn33/agentic-awesome-skills

    Audit preparation register: required document, period covered, request and receipt dates, preparer and reviewer, auditor queries and adjustments.

    47k GitHub starsUsed in 1 repo~5.3k tokens
    Legal & ComplianceAuto-check passed
  • Qms Audit Expert

    davila7/claude-code-templates

    Senior QMS Audit Expert for internal and external quality management system auditing.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed

More from alsk1992/CloddsBot

All 116 skills in this repo
  • Qmd

    alsk1992/CloddsBot

    Local hybrid search for markdown notes and docs. An agent skill from alsk1992/CloddsBot.

    3k GitHub starsUsed in 3 repos~1.2k tokens
    Auto-check passed
  • AI Strategy

    alsk1992/CloddsBot

    AI Strategy - natural language to trades. An agent skill from alsk1992/CloddsBot.

    3k GitHub stars~670 tokensUpdated 7 days ago
    Auto-check passed
  • Alerts

    alsk1992/CloddsBot

    Create and manage price alerts for prediction markets. An agent skill from alsk1992/CloddsBot.

    3k GitHub stars~460 tokensUpdated 7 days ago
    Auto-check passed
  • Analytics

    alsk1992/CloddsBot

    Performance attribution, trade analytics, and strategy optimization

    3k GitHub stars~1.6k tokensUpdated 7 days ago
    Auto-check passed
  • Arbitrage

    alsk1992/CloddsBot

    Automated cross-platform arbitrage detection and monitoring. An agent skill from alsk1992/CloddsBot.

    3k GitHub stars~1.7k tokensUpdated 7 days ago
    Auto-check passed
  • Auto Reply

    alsk1992/CloddsBot

    Automatic response rules, patterns, and scheduled messages. An agent skill from alsk1992/CloddsBot.

    3k GitHub stars~1.5k tokensUpdated 7 days ago
    Auto-check passed

Questions about Harden

How do I install Harden in Claude Code?

Run `npx skills add alsk1992/CloddsBot --skill harden -a claude-code`. Or copy the skill folder (src/skills/bundled/harden in alsk1992/CloddsBot) into .claude/skills/harden in your project. Claude Code loads it when a task matches its description.

How do I install Harden in Codex?

Run `npx skills add alsk1992/CloddsBot --skill harden -a codex`. Or copy the skill folder (src/skills/bundled/harden in alsk1992/CloddsBot) into .agents/skills/harden in your project. Codex loads it when a task matches its description.

Can I use Harden in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alsk1992/CloddsBot --skill harden -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/harden, .gemini/skills/harden, .github/skills/harden and .opencode/skills/harden in your project.

What does Harden need to run?

Going by SKILL.md and its folder, Harden needs TypeScript for the scripts in its folder.

Does Harden access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Harden safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Harden use?

Harden is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Harden use?

About 423 tokens (SKILL.md is roughly 1.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Harden?

Skills that share tags, products or a category with Harden: Production Audit (affaan-m/ECC, 276k stars), Aims Audit (alirezarezvani/claude-skills, 28k stars), Geo Audit (sickn33/agentic-awesome-skills, 47k stars) and OmniRoute Audit and Policy CLI (diegosouzapw/OmniRoute, 75k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Harden?

alsk1992 (a GitHub user) maintains it in alsk1992/CloddsBot, which has 2,951 GitHub stars. The repository holds 116 skills in this directory. The repository was last updated on October 2, 2026.

Source: alsk1992/CloddsBot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.