Agent skill

Linux Hardening

by BagelHole in BagelHole/DevOps-Security-Agent-Skills

Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

MITAuto-check: notesDevOps & Cloud

Install Linux Hardening

skills CLI
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill linux-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BagelHole/DevOps-Security-Agent-Skills linux-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/hardening/linux-hardening .claude/skills/linux-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
linux-hardening
GitHub stars
1.1k
Token cost
~662 tokens
SKILL.md length
78 words
Files
6 (incl. scripts, references, assets)
Skills in repo
44
Repo updated
First seen
Licence
MIT

At a glance

Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

  • Hardening Linux systems for production
  • SKILL.md covers When to Use This Skill, SSH Hardening, User Security and Firewall Configuration, plus 5 more sections
  • Runs Shell scripts from its folder; calls apt
  • Meeting security compliance requirements

What it does

Linux Hardening is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Apply CIS benchmarks and secure Linux servers. Configure SSH, manage users, implement firewall rules, and enable security features. Use when hardening Linux systems for production or meeting security compliance requirements.

Its SKILL.md is about 660 tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `references/cis-checklist.md`, `scripts/audit-system.sh` and `scripts/harden-system.sh`).

It sits in DevOps & Cloud, covering Linux administration, Cloud networking and SOC 2 and security compliance. It works with Linux. The repository describes itself as: Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container… The licence is MIT.

When your agent uses it

  • Hardening Linux systems for production
  • Meeting security compliance requirements

Example prompts

  • “/linux-hardening”

Requirements

  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 0365f57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • apt

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Linux Hardening loads about 662 tokens when it runs, and up to ~2k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 78 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~662
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:40
    sudo apt install libpam-pwquality
  • NoteRuns commands with sudoSKILL.md:51
    # Audit sudo usage

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from BagelHole/DevOps-Security-Agent-Skills at commit 0365f57, republished under its MIT licence (© BagelHole). 78 words, ~662 tokens.

Download SKILL.mdSave it as .claude/skills/linux-hardening/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
linux-hardening
description
Apply CIS benchmarks and secure Linux servers. Configure SSH, manage users, implement firewall rules, and enable security features. Use when hardening Linux systems for production or meeting security compliance requirements.
license
MIT
metadata.author
devops-skills
metadata.version
1.0

Linux Hardening

Secure Linux servers following CIS benchmarks and security best practices.

When to Use This Skill

Use this skill when:

  • Hardening production servers
  • Meeting compliance requirements
  • Implementing security baselines
  • Configuring secure SSH access

SSH Hardening

bash
# /etc/ssh/sshd_config
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
AllowUsers deploy admin
Protocol 2

User Security

bash
# Password policy
sudo apt install libpam-pwquality
# /etc/security/pwquality.conf
minlen = 14
dcredit = -1
ucredit = -1
ocredit = -1
lcredit = -1

# Lock inactive accounts
useradd -D -f 30

# Audit sudo usage
echo "Defaults logfile=/var/log/sudo.log" >> /etc/sudoers

Firewall Configuration

bash
# UFW setup
ufw default deny incoming
ufw default allow outgoing
ufw allow ssh
ufw allow 443/tcp
ufw enable

# Or iptables
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j ACCEPT

Kernel Hardening

bash
# /etc/sysctl.d/99-security.conf
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.icmp_echo_ignore_broadcasts = 1
kernel.randomize_va_space = 2
fs.suid_dumpable = 0

# Apply
sysctl -p

File Permissions

bash
# Critical files
chmod 600 /etc/shadow
chmod 644 /etc/passwd
chmod 700 /root
chmod 600 /etc/ssh/sshd_config

# Find world-writable files
find / -type f -perm -0002 -ls

# Find SUID files
find / -perm -4000 -type f -ls

Audit Configuration

bash
# Install auditd
apt install auditd

# /etc/audit/rules.d/audit.rules
-w /etc/passwd -p wa -k identity
-w /etc/shadow -p wa -k identity
-w /etc/sudoers -p wa -k actions
-a always,exit -F arch=b64 -S execve -k exec

Best Practices

  • Disable unused services
  • Keep system updated
  • Use fail2ban for intrusion prevention
  • Enable SELinux/AppArmor
  • Regular security audits
  • Monitor log files
  • Implement least privilege

© BagelHole, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in security/hardening/linux-hardening of BagelHole/DevOps-Security-Agent-Skills.

  • SKILL.md
  • assets/ssh-hardening.conf
  • assets/sysctl-hardening.conf
  • references/cis-checklist.md
  • scripts/audit-system.sh
  • scripts/harden-system.sh

Open the folder on GitHubat commit 0365f57

Compare with similar skills

Linux Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Linux Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Linux Hardening this skillBagelHole/DevOps-Security-Agent-Skills1.1k—~662Automated safety check: NotesMIT
Setup Cpu Proxy Serverdrawthingsai/draw-things-community582—~3.8kAutomated safety check: PassGPL-3.0
Aliyun Swas Managecinience/alicloud-skills397—~1.9kAutomated safety check: PassMIT
Linux Service TriageaAAaqwq/AGI-Super-Team1052 repos~799Automated safety check: PassMIT
Ghostmagnus919/agent-skills116—~2.4kAutomated safety check: PassMIT
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Setup Cpu Proxy Server

    drawthingsai/draw-things-community

    Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

    582 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Aliyun Swas Manage

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud Simple Application Server (SWAS OpenAPI 2020-06-01) resources end-to-end, including querying instances, starting/stopping/rebooting, executing…

    397 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Linux Service Triage

    aAAaqwq/AGI-Super-Team

    Diagnoses common Linux service issues using logs, systemd/PM2, file permissions, Nginx reverse proxy checks, and DNS sanity checks.

    105 GitHub starsUsed in 2 repos~799 tokens
    DevOps & CloudAuto-check passed
  • Ghost

    magnus919/agent-skills

    Manage Ghost CMS content over the Admin API — browse posts, pages, and tags, draft and publish content, schedule posts, and inspect site info from the terminal.

    116 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Openbkn Deploy

    openbkn-ai/bkn-foundry

    Deploy or upgrade OpenBKN on a customer-authorized Linux server through the repository's deploy scripts, with preflight checks, explicit confirmation, secret handling, and post-deployment…

    645 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from BagelHole/DevOps-Security-Agent-Skills

All 44 skills in this repo
  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Incident Response

    BagelHole/DevOps-Security-Agent-Skills

    Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~4.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Kubernetes Ops

    BagelHole/DevOps-Security-Agent-Skills

    Deploy, scale, and manage Kubernetes workloads. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Prometheus Grafana

    BagelHole/DevOps-Security-Agent-Skills

    Set up metrics collection and visualization with Prometheus and Grafana.

    1.1k GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Vulnerability Scanning

    BagelHole/DevOps-Security-Agent-Skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    1.1k GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Argocd Gitops

    BagelHole/DevOps-Security-Agent-Skills

    Implement GitOps with ArgoCD for declarative Kubernetes deployments.

    1.1k GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Linux Hardening

What does Linux Hardening do?

Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills. Linux Hardening is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Apply CIS benchmarks and secure Linux servers.

When should I use Linux Hardening?

Linux Hardening fits situations like: hardening Linux systems for production; meeting security compliance requirements.

How do I install Linux Hardening in Claude Code?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill linux-hardening -a claude-code`. Or copy the skill folder (security/hardening/linux-hardening in BagelHole/DevOps-Security-Agent-Skills) into .claude/skills/linux-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Linux Hardening in Codex?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill linux-hardening -a codex`. Or copy the skill folder (security/hardening/linux-hardening in BagelHole/DevOps-Security-Agent-Skills) into .agents/skills/linux-hardening in your project. Codex loads it when a task matches its description.

Can I use Linux Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill linux-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/linux-hardening, .gemini/skills/linux-hardening, .github/skills/linux-hardening and .opencode/skills/linux-hardening in your project.

What does Linux Hardening need to run?

Going by SKILL.md and its folder, Linux Hardening needs a shell for the scripts in its folder and the command-line tools its instructions call (apt). Our summary lists: A Bash shell.

Does Linux Hardening access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Linux Hardening safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Linux Hardening use?

Linux Hardening is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Linux Hardening use?

About 662 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Linux Hardening?

Skills that share tags, products or a category with Linux Hardening: Setup Cpu Proxy Server (drawthingsai/draw-things-community, 582 stars), Aliyun Swas Manage (cinience/alicloud-skills, 397 stars), Linux Service Triage (aAAaqwq/AGI-Super-Team, 105 stars) and Ghost (magnus919/agent-skills, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Linux Hardening?

BagelHole (a GitHub user) maintains it in BagelHole/DevOps-Security-Agent-Skills, which has 1,148 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on May 22, 2026.

Source: BagelHole/DevOps-Security-Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.