Agent skill

Kernel Security

by mohitmishra786 in mohitmishra786/low-level-dev-skills

Linux kernel security skill for LSM, hardening, and exploit mitigations.

MITAuto-check passedSecurity

Install Kernel Security

skills CLI
$ npx skills add mohitmishra786/low-level-dev-skills --skill kernel-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitmishra786/low-level-dev-skills kernel-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/kernel-security .claude/skills/kernel-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kernel-security
GitHub stars
253
Token cost
~1.6k tokens
SKILL.md length
310 words
Files
1
Skills in repo
138
Repo updated
First seen
Licence
MIT

At a glance

Linux kernel security skill for LSM, hardening, and exploit mitigations.

  • Works in 9 steps: LSM framework overview → SELinux policy → AppArmor profiles → …
  • Writing SELinux/AppArmor policies
  • SKILL.md covers Purpose, When to Use, Workflow and Common Problems, plus 1 more section
  • Calls make; reaches nvd.nist.gov

What it does

Kernel Security is an agent skill from mohitmishra786/low-level-dev-skills. Linux kernel security skill for LSM, hardening, and exploit mitigations. Use when writing SELinux/AppArmor policies, seccomp-bpf filters, configuring KASLR/CET/PAC, or triaging kernel CVEs. Activates on queries about SELinux, AppArmor, seccomp, KASLR, CET, PAC, BTI, KASAN, or kernel CVE.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. It works with Linux. The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.

When your agent uses it

  • Writing SELinux/AppArmor policies
  • Seccomp-bpf filters
  • Configuring KASLR/CET/PAC
  • Triaging kernel CVEs

Example prompts

  • “/kernel-security”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. LSM framework overview
  2. SELinux policy
  3. AppArmor profiles
  4. seccomp-bpf with libseccomp
  5. KASLR
  6. Intel CET
  7. ARM PAC and BTI
  8. Kernel memory tagging
  9. CVE triage workflow

What it can do on your machine

Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • nvd.nist.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kernel Security loads about 1.6k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 310 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 310 words, ~1,556 tokens.

Download SKILL.mdSave it as .claude/skills/kernel-security/SKILL.md (or your agent's skills folder).
name
kernel-security
description
Linux kernel security skill for LSM, hardening, and exploit mitigations. Use when writing SELinux/AppArmor policies, seccomp-bpf filters, configuring KASLR/CET/PAC, or triaging kernel CVEs. Activates on queries about SELinux, AppArmor, seccomp, KASLR, CET, PAC, BTI, KASAN, or kernel CVE.

Kernel Security

Purpose

Guide agents through Linux kernel security: LSM frameworks (SELinux, AppArmor), seccomp-bpf with libseccomp, KASLR and bypass mitigations, Intel CET (Shadow Stack + IBT), ARM PAC and BTI, kernel sanitizers (KASAN, KMSAN), and CVE triage for kernel vulnerabilities.

When to Use

  • Writing SELinux or AppArmor policies for confined services
  • Sandboxing processes with seccomp-bpf filters
  • Hardening binaries with CET, PAC, or BTI
  • Enabling KASAN on kernel builds for vulnerability research
  • Triaging kernel CVE impact on your distro/kernel version
  • Designing container or microservice security boundaries

Workflow

1. LSM framework overview
Application syscall
    → DAC (uid/gid, file mode)
    → LSM hook (SELinux/AppArmor/Yama/...)
    → Capability check
    → seccomp filter
    → Kernel
bash
# Active LSM
cat /sys/kernel/security/lsm
# common: lockdown,capability,yama,apparmor,safesetid
2. SELinux policy
bash
# Check SELinux status
getenforce
sestatus

# Context of file/process
ls -Z /usr/sbin/nginx
ps -eZ | grep nginx

# Audit denials
ausearch -m avc -ts recent
sealert -a /var/log/audit/audit.log

Policy module example:

te
# myapp.te
policy_module(myapp, 1.0.0)

type myapp_t;
type myapp_exec_t;
type myapp_log_t;

init_daemon_domain(myapp_t, myapp_exec_t)

allow myapp_t myapp_log_t:file { create write append open };
allow myapp_t self:tcp_socket { create bind listen accept };
bash
checkmodule -M -m -o myapp.mod myapp.te
semodule_package -o myapp.pp -m myapp.mod
semodule -i myapp.pp
3. AppArmor profiles
bash
# Generate complain-mode profile
aa-genprof /usr/bin/myapp

# Enforce
aa-enforce /etc/apparmor.d/usr.bin.myapp

# Check status
aa-status
apparmor
# /etc/apparmor.d/usr.bin.myapp
#include <tunables/global>

/usr/bin/myapp {
  #include <abstractions/base>

  /usr/bin/myapp mr,
  /var/log/myapp.log w,
  /etc/myapp/config r,
  network bind tcp,
  deny /etc/shadow r,
}
4. seccomp-bpf with libseccomp
c
#include <seccomp.h>

int sandbox(void) {
    scmp_filter_ctx ctx = seccomp_init(SCMP_ACT_KILL_PROCESS);

    // Allow read/write/exit/mmap
    seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(read), 0);
    seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(write), 0);
    seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(exit_group), 0);
    seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(mmap), 0);
    seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(brk), 0);

    // Return EPERM instead of kill for open
    seccomp_rule_add(ctx, SCMP_ACT_ERRNO(EPERM), SCMP_SYS(open), 0);
    seccomp_rule_add(ctx, SCMP_ACT_ERRNO(EPERM), SCMP_SYS(openat), 0);

    return seccomp_load(ctx);
}
bash
# Export BPF filter for audit
scmp_filter_ctx ctx = ...;
seccomp_export_bpf(ctx, fd);

# strace to find needed syscalls before tightening
strace -c ./myapp
5. KASLR
bash
# Check KASLR enabled
cat /proc/sys/kernel/randomize_va_space   # 2 = full
dmesg | grep KASLR

# Kernel cmdline
grep kaslr /proc/cmdline

Mitigations against KASLR leaks:

  • No /proc/<pid>/maps to untrusted
  • Pointer hashing in %pK printk
  • eBPF restricted on unprivileged
6. Intel CET
bash
# Compile with CET
gcc -fcf-protection=full -o app app.c

# Verify shadow stack and IBT
readelf -n app | grep -E 'SHSTK|IBT'
readelf --notes app | grep -A2 GNU_PROPERTY
FeatureProtects against
SHSTK (Shadow Stack)ROP return address overwrites
IBT (Indirect Branch Tracking)CALL/JMP to non-ENDBR targets

Requires CPU with CET (Intel Tiger Lake+; AMD Zen 3+ on CPUs with shadow-stack support) and kernel CET support.

7. ARM PAC and BTI
bash
# GCC/Clang branch protection
gcc -mbranch-protection=standard -o app app.c
# PAC (pointer authentication) + BTI (branch target identification)

# Verify
readelf -n app | grep -E 'GNU_PROPERTY_AARCH64_FEATURE_1'
llvm-objdump -d app | grep bti

PAC signs return addresses and pointers with cryptographic keys (ARMv8.3+). BTI marks valid branch targets — invalid jumps fault.

8. Kernel memory tagging
bash
# KASAN kernel build
# CONFIG_KASAN=y in kernel .config
make menuconfig  # Kernel hacking → KASAN

# Boot with KASAN kernel
# Reports use-after-free, OOB with stack trace

# KMSAN (uninitialized memory)
# CONFIG_KMSAN=y — kernel equivalent of MSan
bash
# KASAN report example fields
# BUG: KASAN: slab-out-of-bounds in ...
# Call trace: ...
9. CVE triage workflow
bash
# Check kernel version
uname -r

# Distro security tracker
# Ubuntu: ubuntu-security-notices
# RHEL: errata

# NVD lookup
# https://nvd.nist.gov/vuln/detail/CVE-XXXX-XXXXX

# Is patch backported?
zgrep -l CVE-2024-XXXX /usr/share/doc/linux-*/changelog.Debian.gz

Triage checklist:

  1. Affected subsystem (net, fs, drivers)?
  2. Local or remote exploit?
  3. Fixed in your kernel version?
  4. Mitigation without patch (disable module, sysctl)?

Common Problems

SymptomCauseFix
SELinux denialsMissing allow ruleaudit2allow; refine policy
AppArmor profile breakPath mismatchUpdate profile paths; use globs
seccomp kills appMissing syscallstrace; add allow rule
CET not activeOld CPU/kernelCheck /proc/cpuinfo flags
KASAN kernel slow2-5x overheadUse only in test VMs
False sense of securityLSM bypass via kernel bugDefense in depth; keep kernel updated
  • skills/virtualization/containers-internals — container seccomp and caps
  • skills/runtimes/binary-hardening — userspace CET, RELRO, PIE
  • skills/runtimes/sanitizers — ASan/HWASan userspace counterparts
  • skills/observability/ebpf — LSM BPF programs
  • skills/kernel/kernel-debugging — analyze KASAN reports
  • skills/security/reverse-engineering — exploit analysis

© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security/kernel-security of mohitmishra786/low-level-dev-skills.

Open the folder on GitHubat commit bdc5847

Compare with similar skills

Kernel Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kernel Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kernel Security this skillmohitmishra786/low-level-dev-skills253—~1.6kAutomated safety check: PassMIT
Write Cve Ruleevdenis/cvehound138—~2.5kAutomated safety check: PassGPL-3.0
Performing Agentless Vulnerability Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: PassApache-2.0
Performing Authenticated Scan With Openvasmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: WarnApache-2.0
Host Cve Validatorinfometa/workbuddyskills342—~1.8kAutomated safety check: NotesProprietary
Alibabacloud Ecs Sec Kernelaliyun/alibabacloud-ecs-troubleshoot-skills148—~2.4kAutomated safety check: NotesApache-2.0

Similar skills

  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Performing Agentless Vulnerability Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.

    34k GitHub stars~3.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Authenticated Scan With Openvas

    mukul975/Anthropic-Cybersecurity-Skills

    Configure and execute authenticated (credentialed) vulnerability scans using OpenVAS/Greenbone Vulnerability Management (GVM) with SSH, SMB, or ESXi credentials to detect local vulnerabilities…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Host Cve Validator

    infometa/workbuddyskills

    主机安全CVE漏洞修复验证引擎。从主机漏扫报告(Excel)或CVE编号自动提取漏洞,查询威胁情报(NVD/EPSS/MSRC/OVAL),生成修复脚本(fix.sh/fix.ps1),SSH验证脚本可执行性,产出修复验证报告。覆盖 Linux(centos/ubuntu/debian/suse/amazon/fedora/alpine/arch) + Windows + Web-CMS…

    342 GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Alibabacloud Ecs Sec Kernel

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

    148 GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from mohitmishra786/low-level-dev-skills

All 138 skills in this repo
  • ARM and AArch64 Assembly

    mohitmishra786/low-level-dev-skills

    Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.

    253 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • RISC-V Assembly Guide

    mohitmishra786/low-level-dev-skills

    Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.

    253 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • x86-64 Assembly Reference

    mohitmishra786/low-level-dev-skills

    Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Bazel for C and C++

    mohitmishra786/low-level-dev-skills

    Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Binary Hardening

    mohitmishra786/low-level-dev-skills

    Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Binutils

    mohitmishra786/low-level-dev-skills

    GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Kernel Security

What does Kernel Security do?

Linux kernel security skill for LSM, hardening, and exploit mitigations. Kernel Security is an agent skill from mohitmishra786/low-level-dev-skills. Linux kernel security skill for LSM, hardening, and exploit mitigations.

When should I use Kernel Security?

Kernel Security fits situations like: writing SELinux/AppArmor policies; seccomp-bpf filters; configuring KASLR/CET/PAC; triaging kernel CVEs.

How do I install Kernel Security in Claude Code?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill kernel-security -a claude-code`. Or copy the skill folder (skills/security/kernel-security in mohitmishra786/low-level-dev-skills) into .claude/skills/kernel-security in your project. Claude Code loads it when a task matches its description.

How do I install Kernel Security in Codex?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill kernel-security -a codex`. Or copy the skill folder (skills/security/kernel-security in mohitmishra786/low-level-dev-skills) into .agents/skills/kernel-security in your project. Codex loads it when a task matches its description.

Can I use Kernel Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill kernel-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kernel-security, .gemini/skills/kernel-security, .github/skills/kernel-security and .opencode/skills/kernel-security in your project.

What does Kernel Security need to run?

Going by SKILL.md and its folder, Kernel Security needs the command-line tools its instructions call (make).

Does Kernel Security access the network?

SKILL.md names 1 domain. In commands or code: nvd.nist.gov; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Kernel Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kernel Security use?

Kernel Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kernel Security use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kernel Security?

Skills that share tags, products or a category with Kernel Security: Write Cve Rule (evdenis/cvehound, 138 stars), Performing Agentless Vulnerability Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Authenticated Scan With Openvas (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Host Cve Validator (infometa/workbuddyskills, 342 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kernel Security?

mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 253 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.

Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.