Official agent skill

Redis Security

by redis in redis/agent-skills

Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules…

OfficialMITAuto-check passedDatabases

Install Redis Security

skills CLI
$ npx skills add redis/agent-skills --skill redis-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install redis/agent-skills redis-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/redis/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/redis-security .claude/skills/redis-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
redis-security
GitHub stars
165
Used in
1 other repo
Token cost
~918 tokens
SKILL.md length
263 words
Files
4 (incl. references)
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules…

  • Works in 3 steps: Always authenticate (and use TLS) → ACLs for least-privilege access → Restrict network access
  • Deploying Redis to production
  • SKILL.md covers When to apply, 1. Always authenticate (and…, 2. ACLs for least-privilege… and 3. Restrict network access, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Redis Security is an agent skill from redis/agent-skills, published by the product's own GitHub organization. Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules, and disabling dangerous commands. Use when deploying Redis to production, defining ACL users for an application, configuring TLS connections, locking down a Redis instance behind a firewall, or auditing a Redis deployment for security hardening.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/acls.md`, `references/auth.md` and `references/network.md`).

It sits in Databases, covering Authorization and RBAC, Security review and Cloud networking. It works with Redis. The repository describes itself as: Redis' official collection of agent skills. The licence is MIT.

When your agent uses it

  • Deploying Redis to production
  • Defining ACL users for an application
  • Configuring TLS connections
  • Locking down a Redis instance behind a firewall

Example prompts

  • “/redis-security”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Always authenticate (and use TLS)
  2. ACLs for least-privilege access
  3. Restrict network access

What it can do on your machine

Read from SKILL.md and the folder at commit a84871d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • redis.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Redis Security loads about 918 tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 263 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~918
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from redis/agent-skills at commit a84871d, republished under its MIT licence (© redis). 263 words, ~918 tokens.

Download SKILL.mdSave it as .claude/skills/redis-security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
redis-security
description
Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules, and disabling dangerous commands. Use when deploying Redis to production, defining ACL users for an application, configuring TLS connections, locking down a Redis instance behind a firewall, or auditing a Redis deployment for security hardening.
license
MIT
metadata.author
Redis, Inc.
metadata.version
0.1.0

Redis Security

Production hardening for Redis: authentication, ACL-based access control, and network exposure. Cover all three together — any one of them on its own leaves an exploitable gap.

When to apply

  • Deploying or reviewing a Redis instance destined for production.
  • Setting up application credentials beyond a shared password.
  • Auditing a Redis deployment against a security checklist.
  • Receiving "Redis exposed to the internet" findings from a scanner.

1. Always authenticate (and use TLS)

Never run a production Redis without a password. Pair authentication with TLS so credentials and data aren't sent in clear text.

# redis.conf
requirepass your-strong-password
tls-port 6380
tls-cert-file /path/to/redis.crt
tls-key-file  /path/to/redis.key
python
r = redis.Redis(
    host="localhost",
    port=6380,
    password="your-strong-password",
    ssl=True,
    ssl_cert_reqs="required",
)

If you can use ACL users (next section) instead of the single requirepass, do — requirepass is effectively the legacy "default user" shortcut.

See references/auth.md.

2. ACLs for least-privilege access

The default user with a shared password is fine for development. For production, give each application a dedicated ACL user with only the commands and key patterns it actually needs.

# Cache-only reader
ACL SETUSER app_readonly on >password ~cache:* +get +mget +scan

# Writer that can't run dangerous ops
ACL SETUSER app_writer   on >password ~*        +@all -@dangerous

# Admin (use sparingly, never for application traffic)
ACL SETUSER admin        on >strong-password ~* +@all

Useful command categories:

CategoryWhat it covers
@readRead commands (GET, MGET, HGET, ...)
@writeWrite commands (SET, DEL, XADD, ...)
@dangerousFLUSHALL, DEBUG, KEYS, etc.
@adminAdministrative commands

If app credentials leak, a tight ACL bounds the blast radius — the attacker can't FLUSHALL your DB just because they grabbed a cache reader's password.

See references/acls.md.

3. Restrict network access

The most common Redis breach is a public-internet Redis with no auth. Avoid that with three layers:

# redis.conf — bind to specific interfaces, keep protected-mode on
bind 127.0.0.1 192.168.1.100
protected-mode yes
bash
# Firewall — allow only application subnets
iptables -A INPUT -p tcp --dport 6379 -s 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 6379 -j DROP

Anti-pattern: bind 0.0.0.0 + protected-mode no — exposes Redis to the whole network without protection.

Optional but recommended: rename or disable destructive commands so a compromised client can't trash the DB:

rename-command FLUSHALL ""
rename-command DEBUG ""
rename-command CONFIG ""

See references/network.md.

References

© redis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/redis-security of redis/agent-skills.

  • SKILL.md
  • references/acls.md
  • references/auth.md
  • references/network.md

Open the folder on GitHubat commit a84871d

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in redis/agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Redis Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Redis Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Redis Security this skillredis/agent-skills1651 repos~918Automated safety check: PassMIT
Cb Security HardeningBlkLeg/CircuitBreaker201—~2.1kAutomated safety check: PassMIT
Recon NmapAgentSecOps/SecOpsAgentKit2191 repos~4.6kAutomated safety check: NotesCustom licence
Auth Store Debugvercel-labs/vercel-openclaw-archived117—~465Automated safety check: PassMIT
Azure Resource Manager Redis Dotnetmicrosoft/skills3.1k5 repos~3kAutomated safety check: PassMIT
Add Componentlbedner/aegis-stack143—~5.3kAutomated safety check: PassMIT

Similar skills

  • Cb Security Hardening

    BlkLeg/CircuitBreaker

    Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

    201 GitHub stars~2.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Recon Nmap

    AgentSecOps/SecOpsAgentKit

    Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.

    219 GitHub starsUsed in 1 repo~4.6k tokens
    SecurityAuto-check: notes
  • Auth Store Debug

    vercel-labs/vercel-openclaw-archived

    Official

    Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCALREADONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations.

    117 GitHub stars~465 tokensUpdated 4 mo ago
    DatabasesAuto-check passed
  • Official

    Azure Resource Manager SDK for Redis in .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~3k tokens
    DatabasesAuto-check passed
  • Add Component

    lbedner/aegis-stack

    A skill your agent uses when adding a new infrastructure component (worker, scheduler, database, redis, ingress, observability) to the Aegis Stack framework itself, or adding a new variant axis…

    143 GitHub stars~5.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azure Cache Redis

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Cache for Redis development including troubleshooting, best practices, decision making, architecture & design patterns, security, configuration, and deployment.

    775 GitHub stars~2.9k tokensUpdated yesterday
    DatabasesAuto-check passed

More from redis/agent-skills

All 8 skills in this repo
  • Redis Core

    redis/agent-skills

    Official

    Core Redis modeling guidance — choose the right data structure (String, Hash, List, Set, Sorted Set, JSON, Stream, Vector Set) and use consistent colon-separated key names.

    165 GitHub starsUsed in 2 repos~759 tokens
    Auto-check passed
  • Redis Observability

    redis/agent-skills

    Official

    Redis observability guidance — which metrics to monitor (memory, connections, hit ratio, ops/sec, rejected connections), which built-in commands to reach for during incident triage (SLOWLOG, INFO…

    165 GitHub starsUsed in 2 repos~911 tokens
    Auto-check passed
  • Redis Clustering

    redis/agent-skills

    Official

    Redis Cluster and replication guidance covering hash tags for multi-key operations, avoiding CROSSSLOT errors, and reading from replicas to scale read-heavy workloads.

    165 GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Redis Connections

    redis/agent-skills

    Official

    Redis client and connection guidance covering connection pooling, multiplexing, pipelining, client-side caching with RESP3, avoiding slow commands (KEYS, SMEMBERS, HGETALL), and tuning socket…

    165 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Redis Search

    redis/agent-skills

    Official

    Redis Search guidance covering FT.CREATE schema design, field type selection (TEXT, TAG, NUMERIC, GEO, GEOSHAPE, VECTOR, JSON path), DIALECT 2 query syntax, FT.SEARCH / FT.AGGREGATE / FT.HYBRID…

    165 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Redis Semantic Cache

    redis/agent-skills

    Official

    Redis LangCache guidance for semantic caching of LLM responses on Redis Cloud — calling search/set via the SDK or REST API, tuning the similarity threshold, separating caches per task type, and…

    165 GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed

Works with

Categories

Questions about Redis Security

What does Redis Security do?

Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules…. Redis Security is an agent skill from redis/agent-skills, published by the product's own GitHub organization. Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules, and disabling dangerous commands.

When should I use Redis Security?

Redis Security fits situations like: deploying Redis to production; defining ACL users for an application; configuring TLS connections; locking down a Redis instance behind a firewall.

How do I install Redis Security in Claude Code?

Run `npx skills add redis/agent-skills --skill redis-security -a claude-code`. Or copy the skill folder (skills/redis-security in redis/agent-skills) into .claude/skills/redis-security in your project. Claude Code loads it when a task matches its description.

How do I install Redis Security in Codex?

Run `npx skills add redis/agent-skills --skill redis-security -a codex`. Or copy the skill folder (skills/redis-security in redis/agent-skills) into .agents/skills/redis-security in your project. Codex loads it when a task matches its description.

Can I use Redis Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redis/agent-skills --skill redis-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/redis-security, .gemini/skills/redis-security, .github/skills/redis-security and .opencode/skills/redis-security in your project.

What does Redis Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Redis Security is instructions for the agent only. Our summary lists: Python 3.

Does Redis Security access the network?

SKILL.md names 1 domain. As links in the text: redis.io. This is read from the text; nothing was executed.

Is Redis Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Redis Security use?

Redis Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Redis Security use?

About 918 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 854 tokens, read only when the agent opens those files.

What are the alternatives to Redis Security?

Skills that share tags, products or a category with Redis Security: Cb Security Hardening (BlkLeg/CircuitBreaker, 201 stars), Recon Nmap (AgentSecOps/SecOpsAgentKit, 219 stars), Auth Store Debug (vercel-labs/vercel-openclaw-archived, 117 stars) and Azure Resource Manager Redis Dotnet (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Redis Security?

redis (a GitHub organization, an official publisher) maintains it in redis/agent-skills, which has 165 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on September 8, 2026.

Source: redis/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.