Agent skill

Crowdsec

by magnus919 in magnus919/agent-skills

Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF.

MITAuto-check passedDevOps & Cloud

Install Crowdsec

skills CLI
$ npx skills add magnus919/agent-skills --skill crowdsec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills crowdsec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crowdsec .claude/skills/crowdsec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
crowdsec
GitHub stars
116
Token cost
~1.7k tokens
SKILL.md length
695 words
Files
14 (incl. references)
Skills in repo
130
Repo updated
First seen
Licence
MIT

At a glance

Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF.

  • Works in 6 steps: Select collections for the actual log… → Configure acquisition in… → Check parser/scenario hits and unparsed… → …
  • Docker installation
  • SKILL.md covers Safety Gate, Choose a Deployment, The Detection-to-Blocking… and cscli Essentials, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Crowdsec is an agent skill from magnus919/agent-skills. Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF. Use for Linux or Docker installation, detection-to-blocking design, incident review, and safe changes. Do not use for generic firewall, Kubernetes, or reverse-proxy design; route those to the named platform skill and use this skill for CrowdSec integration.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including reference files (for example `README.md`, `evals/evals.json` and `references/appsec-deep-dive.md`). Compatibility notes: Requires CrowdSec/cscli for live operations; Docker is optional for container deployment.

It sits in DevOps & Cloud, covering Cloud networking, Containers and Container orchestration. It works with Docker, Linux and Kubernetes. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • Docker installation
  • Detection-to-blocking design
  • Incident review
  • Generic firewall

Example prompts

  • “/crowdsec”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires CrowdSec/cscli for live operations; Docker is optional for container deployment.

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Select collections for the actual log format, for example
  2. Configure acquisition in /etc/crowdsec/acquis.yaml or acquis.d/; every
  3. Check parser/scenario hits and unparsed lines with cscli metrics -o json.
  4. Use profiles to map alerts to decisions. Keep profiles.yaml.local and
  5. Add a bouncer with cscli bouncers add NAME, store its one-time key securely,
  6. Confirm the reverse proxy/firewall is actually enforcing decisions; an alert

What it can do on your machine

Read from SKILL.md and the folder at commit c545c2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires CrowdSec/cscli for live operations; Docker is optional for container deployment.

    From compatibility in the SKILL.md frontmatter.

Context cost

Crowdsec loads about 1.7k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 695 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit c545c2b, republished under its MIT licence (© magnus919). 695 words, ~1,730 tokens.

Download SKILL.mdSave it as .claude/skills/crowdsec/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
crowdsec
description
Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF. Use for Linux or Docker installation, detection-to-blocking design, incident review, and safe changes. Do not use for generic firewall, Kubernetes, or reverse-proxy design; route those to the named platform skill and use this skill for CrowdSec integration.
compatibility
Requires CrowdSec/cscli for live operations; Docker is optional for container deployment.
license
MIT
metadata.source
https://docs.crowdsec.net
metadata.version
0.0.3

CrowdSec

CrowdSec detects hostile behavior from logs and HTTP requests, then exposes alerts and decisions through LAPI. The engine alone does not block traffic: install and verify at least one remediation component (bouncer) before claiming protection.

Safety Gate

Before any mutation, confirm the target host/container, scope, backup or rollback, and maintenance window. Prefer read-only inspection and simulation first. Never manually delete decisions, collections, or data without recording the reason and an undo path. Save bouncer keys when created; they are shown once. Use simulation: true while tuning scenarios so detections are observed without enforcement, then verify allowlists before live blocking.

Choose a Deployment

For Debian/Ubuntu, add the CrowdSec repository, install crowdsec, then install a remediation package such as crowdsec-firewall-bouncer-iptables or -nftables. For Docker Compose, expose LAPI (127.0.0.1:8080), metrics (127.0.0.1:6060), and AppSec (127.0.0.1:7422) only to required networks, mount /etc/crowdsec, /var/lib/crowdsec/data, and logs read-only, and pin a reviewed image version. Persist the data directory, mandatory for v1.7.0+. Load the Docker deployment guide for a full compose example and remote-agent caveats.

After installation, verify systemctl status crowdsec (or container health), then cscli version, cscli collections list, acquisition metrics, and bouncer connectivity. Do not expose LAPI or AppSec publicly without an explicit network and authentication design.

The Detection-to-Blocking Workflow

  1. Select collections for the actual log format, for example crowdsecurity/linux, sshd, nginx, traefik, or base-http-scenarios.
  2. Configure acquisition in /etc/crowdsec/acquis.yaml or acquis.d/; every source needs labels.type so the correct parser runs. Use poll_without_inotify: true for unreliable NFS/SMB or bind mounts and use_time_machine: true for buffered logs.
  3. Check parser/scenario hits and unparsed lines with cscli metrics -o json.
  4. Use profiles to map alerts to decisions. Keep profiles.yaml.local and remember YAML sequences replace rather than merge.
  5. Add a bouncer with cscli bouncers add NAME, store its one-time key securely, and verify cscli bouncers list plus a harmless test decision.
  6. Confirm the reverse proxy/firewall is actually enforcing decisions; an alert or LAPI decision alone is not proof of a blocked request.

For complete configuration directives, database choices, and hardening, read config-reference, database-config, and production-hardening.

cscli Essentials

Use cscli -o json for automation and capture command output, version, host, and time as evidence. Read-only triage commonly uses:

bash
cscli version
cscli hub list
cscli collections list
cscli alerts list --contain "scenario:ssh-bf"
cscli decisions list -o json
cscli metrics -o json
cscli explain --file /path/to/sample.log

cscli hub update refreshes the local hub index and can change local state. It is optional, not part of the read-only triage path, and requires the safety gate above before running it. Manage hub items with collections|parsers|scenarios install/list/upgrade/inspect; those install, upgrade, and delete operations also require the safety gate. Manage alerts and decisions with alerts list/inspect and decisions add/list/delete; mutation commands require the safety gate above. Manage bouncers and machines with bouncers add/list/delete and machines add/list/delete. Use console status, console enroll, and lapi register only after confirming the destination and credentials. Load the full cscli reference for flags, output modes, and less common commands.

Show full SKILL.md (228 more words)Show less

Acquisition and AppSec WAF

A minimal file acquisition entry is:

yaml
filenames: [/var/log/nginx/*.log]
labels: {type: nginx}

For AppSec, install the relevant virtual-patching/CRS collections and add an appsec acquisition source listening on 7422 with appsec_config: crowdsecurity/appsec-default and labels.type: appsec. Route requests from the proxy to AppSec and decide failure behavior deliberately: fail-open preserves availability but can bypass protection; fail-closed protects more strongly but can cause an outage. Test with benign fixtures and inspect AppSec metrics before enabling blocking. In-band rules block or captcha the current request; out-of-band rules emit events for later scenarios. Load the AppSec deep dive and the relevant bouncer guide or nginx-bouncer.

Operations and Troubleshooting

Check service logs, cscli metrics, parser/unparsed counts, scenario hits, active decisions, and bouncer last-pull time in that order. Distinguish “no logs acquired”, “logs acquired but unparsed”, “parsed but no scenario hit”, “decision exists but bouncer is stale”, and “bouncer enforced but proxy routing is wrong”. Do not interpret an empty alert query as proof of safety. Use the troubleshooting guide and the operations checklist for a bounded verification packet.

Use profiles and notifications deliberately. Test notification plugins with cscli notifications test NAME; never place webhook secrets or CTI keys in examples. Enable TLS/mTLS for LAPI across trust boundaries and review community/blocklist pulls before relying on them.

References

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (references) in crowdsec of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • references/appsec-deep-dive.md
  • references/config-reference.md
  • references/cscli-command-reference.md
  • references/database-config.md
  • references/docker-deployment.md
  • references/hub-collections.md
  • references/nginx-bouncer.md
  • references/operations-checklist.md
  • references/production-hardening.md
  • references/traefik-bouncer.md
  • references/troubleshooting.md

Open the folder on GitHubat commit c545c2b

Compare with similar skills

Crowdsec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Crowdsec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Crowdsec this skillmagnus919/agent-skills116—~1.7kAutomated safety check: PassMIT
Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider174—~2.6kAutomated safety check: PassCustom licence
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Tao Setup Nvidia GPU HostNVIDIA/skills3.5k—~3.4kAutomated safety check: NotesApache-2.0
Dotnet Debuggingnovotnyllc/dotnet-artisan233—~2.1kAutomated safety check: PassMIT
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    174 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Official

    Host setup for TAO GPU backends. An agent skill from NVIDIA/skills.

    3.5k GitHub stars~3.4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Dotnet Debugging

    novotnyllc/dotnet-artisan

    Debugs Windows and Linux/macOS applications (native, .NET/CLR, mixed-mode) with WinDbg MCP (crash dumps, !analyze, !syncblk, !dlk, !runaway, !dumpheap, !gcroot, BSOD), dotnet-dump, lldb with SOS…

    233 GitHub stars~2.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    16k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from magnus919/agent-skills

All 130 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    116 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    116 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    116 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    116 GitHub stars~2k tokensUpdated yesterday
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Crowdsec

What does Crowdsec do?

Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF. Crowdsec is an agent skill from magnus919/agent-skills. Deploy, configure, and operate CrowdSec Security Engine, cscli, remediation components, acquisition pipelines, and AppSec WAF.

When should I use Crowdsec?

Crowdsec fits situations like: Docker installation; detection-to-blocking design; incident review; generic firewall.

How do I install Crowdsec in Claude Code?

Run `npx skills add magnus919/agent-skills --skill crowdsec -a claude-code`. Or copy the skill folder (crowdsec in magnus919/agent-skills) into .claude/skills/crowdsec in your project. Claude Code loads it when a task matches its description.

How do I install Crowdsec in Codex?

Run `npx skills add magnus919/agent-skills --skill crowdsec -a codex`. Or copy the skill folder (crowdsec in magnus919/agent-skills) into .agents/skills/crowdsec in your project. Codex loads it when a task matches its description.

Can I use Crowdsec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill crowdsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crowdsec, .gemini/skills/crowdsec, .github/skills/crowdsec and .opencode/skills/crowdsec in your project.

What does Crowdsec need to run?

SKILL.md names no scripts, command-line tools or credentials: Crowdsec is instructions for the agent only. Our summary lists: Docker. Compatibility (from SKILL.md): Requires CrowdSec/cscli for live operations; Docker is optional for container deployment..

Does Crowdsec access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Crowdsec safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Crowdsec use?

Crowdsec is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Crowdsec use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.5k tokens, read only when the agent opens those files.

What are the alternatives to Crowdsec?

Skills that share tags, products or a category with Crowdsec: Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 174 stars), Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Tao Setup Nvidia GPU Host (NVIDIA/skills, 3.5k stars) and Dotnet Debugging (novotnyllc/dotnet-artisan, 233 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Crowdsec?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 116 GitHub stars. The repository holds 130 skills in this directory. The repository was last updated on October 8, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.