Agent skill

Harden Vps

by danielvm-git in danielvm-git/bigpowers

Harden a production Linux VPS for your application across three layers — application (systemd hardening, monitoring alerts, backup automation), Ubuntu OS (UFW firewall, fail2ban SSH…

MITAuto-check: notesDevOps & Cloud

Install Harden Vps

skills CLI
$ npx skills add danielvm-git/bigpowers --skill harden-vps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install danielvm-git/bigpowers harden-vps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/danielvm-git/bigpowers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/harden-vps .claude/skills/harden-vps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
harden-vps
GitHub stars
257
Token cost
~1.3k tokens
SKILL.md length
176 words
Files
2
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Harden a production Linux VPS for your application across three layers — application (systemd hardening, monitoring alerts, backup automation), Ubuntu OS (UFW firewall, fail2ban SSH…

  • Works in 4 steps: Shell escaping in Orca terminals: $VAR,… → Crontab %: cron interprets % as newline.… → fail2ban exit 255: means a jail… → …
  • The user wants to secure a production server
  • SKILL.md covers Quick start, Layer 1 — Ubuntu OS, Layer 2 — applicationlication and Layer 3 — VPS provider, plus 2 more sections
  • Calls apt, sqlite3 and curl; reaches api.github.com; needs CONTABO_CLIENT_SECRET and CONTABO_API_PASSWORD

What it does

Harden Vps is an agent skill from danielvm-git/bigpowers. Harden a production Linux VPS for your application across three layers — application (systemd hardening, monitoring alerts, backup automation), Ubuntu OS (UFW firewall, fail2ban SSH, unattended-upgrades, SSH hardening), and VPS provider (health checks, daily backups, monthly snapshots). Use when the user wants to secure a production server, harden a VPS, audit server security, or mentions production hardening, VPS security, or harden the server.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `REFERENCE.md`).

It sits in DevOps & Cloud, covering Linux administration and Backup and disaster recovery. It works with Linux. The repository describes itself as: Agent skills synthesizing years of software engineering discipline into a prescriptive methodology for solo developers. The licence is MIT.

When your agent uses it

  • The user wants to secure a production server
  • Audit server security
  • Mentions production hardening
  • Harden the server

Example prompts

  • “/harden-vps”

Requirements

  • A credential in CONTABO_CLIENT_SECRET

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Shell escaping in Orca terminals: $VAR, $(…), and % get eaten by the local shell. Always use base64: echo '' | base64 -d > script.sh
  2. Crontab %: cron interprets % as newline. Escape as \% in $(date +\%Y\%m\%d)
  3. fail2ban exit 255: means a jail references a missing log file. Remove the broken jail, restart.
  4. your application alerts need auth: POST to /api/monitoring/alerts requires Bearer token. Workaround: insert directly into SQLite, then…

What it can do on your machine

Read from SKILL.md and the folder at commit 812d57a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • sqlite3
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CONTABO_CLIENT_SECRET
    • CONTABO_API_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Harden Vps loads about 1.3k tokens when it runs. Until then it costs about 115 tokens; SKILL.md has 176 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:76
    bo-snapshot.sh (reads from /opt/your-app/.env)
  • NoteMentions a .env fileSKILL.md:77
    Credentials as env vars in /opt/your-app/.env (deployed by GitHub Actions):
  • NoteMentions a .env fileSKILL.md:81
    silently fails until env vars are set in .env.
  • NoteMentions a .env fileSKILL.md:83
    GitHub Secrets → deploy → /opt/your-app/.env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from danielvm-git/bigpowers at commit 812d57a, republished under its MIT licence (© danielvm-git). 176 words, ~1,284 tokens.

Download SKILL.mdSave it as .claude/skills/harden-vps/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
harden-vps
description
Harden a production Linux VPS for your application across three layers — application (systemd hardening, monitoring alerts, backup automation), Ubuntu OS (UFW firewall, fail2ban SSH, unattended-upgrades, SSH hardening), and VPS provider (health checks, daily backups, monthly snapshots). Use when the user wants to secure a production server, harden a VPS, audit server security, or mentions production hardening, VPS security, or harden the server.
model
haiku
effort
standard

Harden VPS

Three-layer production hardening for a self-hosted app on any VPS. Each layer independently verifiable. Apply OS first (firewall blocks attacks immediately), then your application (alerts + backups), then your VPS provider (snapshots). See REFERENCE.md for full script bodies, systemd unit template, and gotchas.

Quick start

SSH as root into the VPS. Find credentials in the your VPS provider Customer Control Panel.

HARD GATE — Run ufw status first. No firewall = layer 1 takes priority over everything.

Layer 1 — Ubuntu OS

bash
# UFW
ufw default deny incoming && ufw default allow outgoing
ufw allow 22/tcp && ufw allow 80/tcp && ufw allow 443/tcp && ufw enable
# → verify: ufw status | grep -q active

# fail2ban
apt install -y fail2ban
# Configure /etc/fail2ban/jail.local: sshd, maxretry=3, bantime=3600, findtime=600
systemctl restart fail2ban
# → verify: fail2ban-client status sshd

# unattended-upgrades
apt install -y unattended-upgrades && dpkg-reconfigure -plow unattended-upgrades
# → verify: systemctl is-active unattended-upgrades | grep -q active

# SSH: PermitRootLogin no, PasswordAuthentication no, PubkeyAuthentication yes
# → verify: sshd -T | grep -E 'permitrootlogin no|passwordauthentication no'

# Deploy healthcheck.sh → /opt/your-app/scripts/healthcheck.sh
# Crontab: */5 * * * * /opt/your-app/scripts/healthcheck.sh

Layer 2 — applicationlication

bash
# systemd: User=your-app, NoNewPrivileges=yes, ProtectSystem=full,
#   ProtectKernelTunables=yes, ProtectKernelModules=yes,
#   ProtectControlGroups=yes, RestrictAddressFamilies=AF_INET AF_INET6,
#   RestrictRealtime=yes, PrivateTmp=yes, LimitNOFILE=65536
# → verify: systemctl show your-app -p NoNewPrivileges -p ProtectSystem -p User

# Alerts (your application requires auth; insert via SQLite)
sqlite3 /opt/your-app/data/your-app.db "
INSERT INTO monitoring_alerts (id,name,metric,threshold,operator,enabled,duration_seconds)
VALUES ('a1','Disk >80%','disk_used_percent',80,'gt',1,300);
INSERT INTO monitoring_alerts (id,name,metric,threshold,operator,enabled,duration_seconds)
VALUES ('a2','CPU >90%','cpu_percent',90,'gt',1,60);
INSERT INTO monitoring_alerts (id,name,metric,threshold,operator,enabled,duration_seconds)
VALUES ('a3','RAM >85%','mem_used_percent',85,'gt',1,120);
"
systemctl restart your-app

# Backup crontab (root):
# 0 2 * * * cp /opt/your-app/data/your-app.db /backup/your-app-$(date +\%Y\%m\%d).db
# 0 3 * * * find /backup/ -name "your-app-*.db" -mtime +90 -delete

Layer 3 — VPS provider

bash
# cntb CLI
curl -sL "$(curl -sL https://api.github.com/repos/contabo/cntb/releases/latest \
  | grep browser_download_url.*linux_amd64.tar.gz | head -1 | cut -d'"' -f4)" \
  | tar xz -C /usr/local/bin

# Snapshot script → /opt/your-app/scripts/contabo-snapshot.sh (reads from /opt/your-app/.env)
# Credentials as env vars in /opt/your-app/.env (deployed by GitHub Actions):
#   CONTABO_CLIENT_ID, CONTABO_CLIENT_SECRET, CONTABO_API_USER, CONTABO_API_PASSWORD
# Crontab: 0 4 1 * * /opt/your-app/scripts/contabo-snapshot.sh

# > HARD GATE — Snapshot cron silently fails until env vars are set in .env.
# Credentials source: your VPS provider Customer Panel → API Details.
# Local dev: add to .envrc. Production: GitHub Secrets → deploy → /opt/your-app/.env

CRITICAL GOTCHAS

  1. Shell escaping in Orca terminals: $VAR, $(…), and % get eaten by the local shell. Always use base64: echo '<base64>' | base64 -d > script.sh
  2. Crontab %: cron interprets % as newline. Escape as \% in $(date +\%Y\%m\%d)
  3. fail2ban exit 255: means a jail references a missing log file. Remove the broken jail, restart.
  4. your application alerts need auth: POST to /api/monitoring/alerts requires Bearer token. Workaround: insert directly into SQLite, then restart your application.

Verify all 8 gates

bash
ufw status|grep -q active||echo FAIL:ufw
fail2ban-client status sshd>/dev/null 2>&1||echo FAIL:fail2ban
systemctl is-active unattended-upgrades|grep -q active||echo FAIL:unattended
sshd -T|grep -q 'permitrootlogin no'||echo FAIL:sshd
systemctl show your-app -p NoNewPrivileges|grep -q yes||echo FAIL:systemd
systemctl is-active your-app|grep -q active||echo FAIL:your-app
sqlite3 /opt/your-app/data/your-app.db "SELECT count(*) FROM monitoring_alerts"|grep -q 3||echo FAIL:alerts
crontab -l|grep -q healthcheck&&crontab -l|grep -q your-app.db&&crontab -l|grep -q contabo-snapshot||echo FAIL:crontab
echo ALL 8 GATES PASSED

→ verify: # requires VPS SSH — run the 8-gate one-liner on the VPS manually

© danielvm-git, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/harden-vps of danielvm-git/bigpowers.

  • SKILL.md
  • REFERENCE.md

Open the folder on GitHubat commit 812d57a

Compare with similar skills

Harden Vps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Harden Vps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Harden Vps this skilldanielvm-git/bigpowers257—~1.3kAutomated safety check: NotesMIT
Computer Repair88lin/computer-repair-skill3511 repos~1.2kAutomated safety check: WarnAGPL-3.0
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Openbkn Deployopenbkn-ai/bkn-foundry636—~1.9kAutomated safety check: NotesCustom licence
Aliyun Swas Managecinience/alicloud-skills3971 repos~1.9kAutomated safety check: PassMIT
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only

Similar skills

  • Computer Repair

    88lin/computer-repair-skill

    Diagnoses and repairs Windows, macOS and Linux computers with evidence first, a confirmed plan, minimal changes and verification, using on-demand playbooks.

    351 GitHub starsUsed in 1 repo~1.2k tokens
    DevOps & CloudAuto-check: warnings
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Openbkn Deploy

    openbkn-ai/bkn-foundry

    Deploy or upgrade OpenBKN on a customer-authorized Linux server through the repository's deploy scripts, with preflight checks, explicit confirmation, secret handling, and post-deployment…

    636 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Aliyun Swas Manage

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud Simple Application Server (SWAS OpenAPI 2020-06-01) resources end-to-end, including querying instances, starting/stopping/rebooting, executing…

    397 GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Setup Cpu Proxy Server

    drawthingsai/draw-things-community

    Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

    580 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from danielvm-git/bigpowers

All 39 skills in this repo
  • Extract Design

    danielvm-git/bigpowers

    Extract a Google DESIGN.md file from an HTML prototype (claude.ai/design or any styled page) using Puppeteer, producing machine-readable tokens and AI-generated prose.

    257 GitHub stars~1k tokensUpdated 16 days ago
    Auto-check passed
  • Align Grid

    danielvm-git/bigpowers

    Build editorial/magazine/report webpages on a GENUINE Müller-Brockmann modular grid (International Typographic Style) — not a decorative one.

    257 GitHub stars~3k tokensUpdated 16 days ago
    Auto-check passed
  • Assess Impact

    danielvm-git/bigpowers

    Analyze the blast radius of a proposed change before any code is written.

    257 GitHub stars~766 tokensUpdated 16 days ago
    Auto-check passed
  • Audit Code

    danielvm-git/bigpowers

    Self-review checklist for the coding agent to run before dispatching a reviewer.

    257 GitHub stars~1.6k tokensUpdated 16 days ago
    Auto-check: notes
  • Audit Plan

    danielvm-git/bigpowers

    Evaluate an incoming project plan against bigpowers principles and conventions, surface gaps, and produce a READY/NOT READY verdict before engagement begins.

    257 GitHub stars~880 tokensUpdated 16 days ago
    Auto-check passed
  • Compose Workflow

    danielvm-git/bigpowers

    Chain multiple bigpowers skills into a custom workflow recipe saved in specs/.

    257 GitHub stars~723 tokensUpdated 16 days ago
    Auto-check passed

Works with

Categories

Questions about Harden Vps

What does Harden Vps do?

Harden a production Linux VPS for your application across three layers — application (systemd hardening, monitoring alerts, backup automation), Ubuntu OS (UFW firewall, fail2ban SSH…. Harden Vps is an agent skill from danielvm-git/bigpowers. Harden a production Linux VPS for your application across three layers — application (systemd hardening, monitoring alerts, backup automation), Ubuntu OS (UFW firewall, fail2ban SSH, unattended-upgrades, SSH hardening), and VPS provider (health checks, daily backups, monthly snapshots).

When should I use Harden Vps?

Harden Vps fits situations like: the user wants to secure a production server; audit server security; mentions production hardening; harden the server.

How do I install Harden Vps in Claude Code?

Run `npx skills add danielvm-git/bigpowers --skill harden-vps -a claude-code`. Or copy the skill folder (skills/harden-vps in danielvm-git/bigpowers) into .claude/skills/harden-vps in your project. Claude Code loads it when a task matches its description.

How do I install Harden Vps in Codex?

Run `npx skills add danielvm-git/bigpowers --skill harden-vps -a codex`. Or copy the skill folder (skills/harden-vps in danielvm-git/bigpowers) into .agents/skills/harden-vps in your project. Codex loads it when a task matches its description.

Can I use Harden Vps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add danielvm-git/bigpowers --skill harden-vps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/harden-vps, .gemini/skills/harden-vps, .github/skills/harden-vps and .opencode/skills/harden-vps in your project.

What does Harden Vps need to run?

Going by SKILL.md and its folder, Harden Vps needs the command-line tools its instructions call (apt, sqlite3 and curl) and credentials named CONTABO_CLIENT_SECRET and CONTABO_API_PASSWORD. Our summary lists: A credential in CONTABO_CLIENT_SECRET.

Does Harden Vps access the network?

SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Harden Vps safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Harden Vps use?

Harden Vps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Harden Vps use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Harden Vps?

Skills that share tags, products or a category with Harden Vps: Computer Repair (88lin/computer-repair-skill, 351 stars), Openclaw Live Updater (openclaw/openclaw, 392k stars), Openbkn Deploy (openbkn-ai/bkn-foundry, 636 stars) and Aliyun Swas Manage (cinience/alicloud-skills, 397 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Harden Vps?

danielvm-git (a GitHub user) maintains it in danielvm-git/bigpowers, which has 257 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on September 21, 2026.

Source: danielvm-git/bigpowers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.