Ama Logs Update Charts Release Notes
microsoft/Docker-Provider
Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.
Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF.
$ npx skills add magnus919/agent-skills --skill crowdsec -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install magnus919/agent-skills crowdsec --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crowdsec .claude/skills/crowdsec && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "crowdsec" agent skill from https://github.com/magnus919/agent-skills/tree/main/crowdsec into .claude/skills/crowdsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crowdsec", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/magnus919/agent-skills/tree/main/crowdsecType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add magnus919/agent-skills --skill crowdsec -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install magnus919/agent-skills crowdsec --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/crowdsec .agents/skills/crowdsec && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "crowdsec" agent skill from https://github.com/magnus919/agent-skills/tree/main/crowdsec into .agents/skills/crowdsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crowdsec", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add magnus919/agent-skills --skill crowdsec -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install magnus919/agent-skills crowdsec --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/crowdsec .cursor/skills/crowdsec && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "crowdsec" agent skill from https://github.com/magnus919/agent-skills/tree/main/crowdsec into .cursor/skills/crowdsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crowdsec", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/magnus919/agent-skills.git --path crowdsec--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add magnus919/agent-skills --skill crowdsec -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install magnus919/agent-skills crowdsec --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/crowdsec .gemini/skills/crowdsec && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "crowdsec" agent skill from https://github.com/magnus919/agent-skills/tree/main/crowdsec into .gemini/skills/crowdsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crowdsec", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install magnus919/agent-skills crowdsecInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add magnus919/agent-skills --skill crowdsec -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/crowdsec .github/skills/crowdsec && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "crowdsec" agent skill from https://github.com/magnus919/agent-skills/tree/main/crowdsec into .github/skills/crowdsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crowdsec", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add magnus919/agent-skills --skill crowdsec -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install magnus919/agent-skills crowdsec --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/crowdsec .opencode/skills/crowdsec && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "crowdsec" agent skill from https://github.com/magnus919/agent-skills/tree/main/crowdsec into .opencode/skills/crowdsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crowdsec", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
crowdsecDeploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF.
Crowdsec is an agent skill from magnus919/agent-skills. Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF. Use for Linux or Docker installation, detection-to-blocking design, incident review, and safe changes. Do not use for generic firewall, Kubernetes, or reverse-proxy design; route those to the named platform skill and use this skill for CrowdSec integration.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including reference files (for example `README.md`, `evals/evals.json` and `references/appsec-deep-dive.md`). Compatibility notes: Requires CrowdSec/cscli for live operations; Docker is optional for container deployment.
It sits in DevOps & Cloud, covering Cloud networking, Containers and Container orchestration. It works with Docker, Linux and Kubernetes. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c545c2b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires CrowdSec/cscli for live operations; Docker is optional for container deployment.
From compatibility in the SKILL.md frontmatter.
Crowdsec loads about 1.7k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 695 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from magnus919/agent-skills at commit c545c2b, republished under its MIT licence (© magnus919). 695 words, ~1,730 tokens.
.claude/skills/crowdsec/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.CrowdSec detects hostile behavior from logs and HTTP requests, then exposes alerts and decisions through LAPI. The engine alone does not block traffic: install and verify at least one remediation component (bouncer) before claiming protection.
Before any mutation, confirm the target host/container, scope, backup or rollback,
and maintenance window. Prefer read-only inspection and simulation first. Never
manually delete decisions, collections, or data without recording the reason and
an undo path. Save bouncer keys when created; they are shown once. Use
simulation: true while tuning scenarios so detections are observed without
enforcement, then verify allowlists before live blocking.
For Debian/Ubuntu, add the CrowdSec repository, install crowdsec, then install
a remediation package such as crowdsec-firewall-bouncer-iptables or
-nftables. For Docker Compose, expose LAPI (127.0.0.1:8080), metrics
(127.0.0.1:6060), and AppSec (127.0.0.1:7422) only to required networks,
mount /etc/crowdsec, /var/lib/crowdsec/data, and logs read-only, and pin a
reviewed image version. Persist the data directory, mandatory for v1.7.0+.
Load the Docker deployment guide for a full
compose example and remote-agent caveats.
After installation, verify systemctl status crowdsec (or container health),
then cscli version, cscli collections list, acquisition metrics, and
bouncer connectivity. Do not expose LAPI or AppSec publicly without an explicit
network and authentication design.
crowdsecurity/linux, sshd, nginx, traefik, or base-http-scenarios./etc/crowdsec/acquis.yaml or acquis.d/; every
source needs labels.type so the correct parser runs. Use
poll_without_inotify: true for unreliable NFS/SMB or bind mounts and
use_time_machine: true for buffered logs.cscli metrics -o json.profiles.yaml.local and
remember YAML sequences replace rather than merge.cscli bouncers add NAME, store its one-time key securely,
and verify cscli bouncers list plus a harmless test decision.For complete configuration directives, database choices, and hardening, read config-reference, database-config, and production-hardening.
Use cscli -o json for automation and capture command output, version, host,
and time as evidence. Read-only triage commonly uses:
cscli version
cscli hub list
cscli collections list
cscli alerts list --contain "scenario:ssh-bf"
cscli decisions list -o json
cscli metrics -o json
cscli explain --file /path/to/sample.logcscli hub update refreshes the local hub index and can change local state. It
is optional, not part of the read-only triage path, and requires the safety gate
above before running it. Manage hub items with
collections|parsers|scenarios install/list/upgrade/inspect; those install,
upgrade, and delete operations also require the safety gate. Manage alerts and
decisions with alerts list/inspect and decisions add/list/delete; mutation
commands require the safety gate above.
Manage bouncers and machines with bouncers add/list/delete and
machines add/list/delete. Use console status, console enroll, and
lapi register only after confirming the destination and credentials. Load the
full cscli reference for flags,
output modes, and less common commands.
A minimal file acquisition entry is:
filenames: [/var/log/nginx/*.log]
labels: {type: nginx}For AppSec, install the relevant virtual-patching/CRS collections and add an
appsec acquisition source listening on 7422 with
appsec_config: crowdsecurity/appsec-default and labels.type: appsec. Route
requests from the proxy to AppSec and decide failure behavior deliberately:
fail-open preserves availability but can bypass protection; fail-closed protects
more strongly but can cause an outage. Test with benign fixtures and inspect
AppSec metrics before enabling blocking. In-band rules block or captcha the
current request; out-of-band rules emit events for later scenarios. Load
the AppSec deep dive and the relevant
bouncer guide or
nginx-bouncer.
Check service logs, cscli metrics, parser/unparsed counts, scenario hits,
active decisions, and bouncer last-pull time in that order. Distinguish “no
logs acquired”, “logs acquired but unparsed”, “parsed but no scenario hit”,
“decision exists but bouncer is stale”, and “bouncer enforced but proxy routing
is wrong”. Do not interpret an empty alert query as proof of safety. Use
the troubleshooting guide and the
operations checklist for a bounded
verification packet.
Use profiles and notifications deliberately. Test notification plugins with
cscli notifications test NAME; never place webhook secrets or CTI keys in
examples. Enable TLS/mTLS for LAPI across trust boundaries and review
community/blocklist pulls before relying on them.
© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 13 other files (references) in crowdsec of magnus919/agent-skills.
Open the folder on GitHubat commit c545c2b
Crowdsec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Crowdsec this skillmagnus919/agent-skills | 116 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider | 174 | — | ~2.6k | Automated safety check: Pass | Custom licence | |
| Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Tao Setup Nvidia GPU HostNVIDIA/skills | 3.5k | — | ~3.4k | Automated safety check: Notes | Apache-2.0 | |
| Dotnet Debuggingnovotnyllc/dotnet-artisan | 233 | — | ~2.1k | Automated safety check: Pass | MIT | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 |
microsoft/Docker-Provider
Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。
NVIDIA/skills
Host setup for TAO GPU backends. An agent skill from NVIDIA/skills.
novotnyllc/dotnet-artisan
Debugs Windows and Linux/macOS applications (native, .NET/CLR, mixed-mode) with WinDbg MCP (crash dumps, !analyze, !syncblk, !dlk, !runaway, !dumpheap, !gcroot, BSOD), dotnet-dump, lldb with SOS…
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
NVIDIA/OpenShell
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.
magnus919/agent-skills
Organize durable agent research outputs as summaries, analysis, and evidence dossiers.
magnus919/agent-skills
Build portable, first-person colored ASCII city engines and small GIS-derived city packs.
magnus919/agent-skills
Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.
magnus919/agent-skills
A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…
magnus919/agent-skills
Use Docker Compose to define, run, debug, and harden multi-container applications.
magnus919/agent-skills
Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.
Works with
Categories
Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF. Crowdsec is an agent skill from magnus919/agent-skills. Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF.
Crowdsec fits situations like: Docker installation; detection-to-blocking design; incident review; generic firewall.
Run `npx skills add magnus919/agent-skills --skill crowdsec -a claude-code`. Or copy the skill folder (crowdsec in magnus919/agent-skills) into .claude/skills/crowdsec in your project. Claude Code loads it when a task matches its description.
Run `npx skills add magnus919/agent-skills --skill crowdsec -a codex`. Or copy the skill folder (crowdsec in magnus919/agent-skills) into .agents/skills/crowdsec in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill crowdsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crowdsec, .gemini/skills/crowdsec, .github/skills/crowdsec and .opencode/skills/crowdsec in your project.
SKILL.md names no scripts, command-line tools or credentials: Crowdsec is instructions for the agent only. Our summary lists: Docker. Compatibility (from SKILL.md): Requires CrowdSec/cscli for live operations; Docker is optional for container deployment..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Crowdsec is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Crowdsec: Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 174 stars), Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Tao Setup Nvidia GPU Host (NVIDIA/skills, 3.5k stars) and Dotnet Debugging (novotnyllc/dotnet-artisan, 233 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 116 GitHub stars. The repository holds 130 skills in this directory. The repository was last updated on October 8, 2026.
Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.