Agent skill

Vpn Security Check

by Sergei-thinker in Sergei-thinker/vpn-setup

Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.

MITAuto-check: notesSecurity

Install Vpn Security Check

skills CLI
$ npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sergei-thinker/vpn-setup vpn-security-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sergei-thinker/vpn-setup.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/vpn-security-check .claude/skills/vpn-security-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vpn-security-check
GitHub stars
189
Token cost
~1.5k tokens
SKILL.md length
651 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.

  • Works in 7 steps: SSH Hardening → Firewall → Intrusion Prevention → …
  • User asks check security
  • SKILL.md covers When to Use, The Iron Law, Security Checks and Report Format, plus 1 more section
  • Calls python, git and apt

What it does

Vpn Security Check is an agent skill from Sergei-thinker/vpn-setup. Infrastructure security audit for VPN server. Use when user asks 'check security', 'is my VPN safe', 'audit security', 'security check'. Also use after deployment when user has security concerns.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review and Deployment. It works with Python. The repository describes itself as: Multi-layer VPN (VLESS Reality + Yandex Cloud Relay + WebRTC) for bypassing Russian internet censorship. Automated deployment via Claude Code. The licence is MIT.

When your agent uses it

  • User asks check security
  • Has security concerns

Example prompts

  • “check security”
  • “is my VPN safe”
  • “audit security”
  • “/vpn-security-check”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. SSH Hardening
  2. Firewall
  3. Intrusion Prevention
  4. VPN Service Security
  5. Camouflage
  6. Secrets Management
  7. System Updates

What it can do on your machine

Read from SKILL.md and the folder at commit 486bf50. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • git
    • apt

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vpn Security Check loads about 1.5k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 651 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:124
    **6a. .env Not in Git**
  • NoteMentions a .env fileSKILL.md:126
    nd (local): Check `.gitignore` includes `.env` AND `git ls-files .env` returns nothing
  • NoteMentions a .env fileSKILL.md:130
    | .env is gitignored and not tracked | PASS |
  • NoteMentions a .env fileSKILL.md:131
    | .env is tracked in git | CRITICAL FAIL — `git rm --cached .env` immediately. Credentials are exposed! |
  • NoteMentions a .env fileSKILL.md:177
    6a. .env в git:            [PASS/CRITICAL]

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sergei-thinker/vpn-setup at commit 486bf50, republished under its MIT licence (© Sergei-thinker). 651 words, ~1,548 tokens.

Download SKILL.mdSave it as .claude/skills/vpn-security-check/SKILL.md (or your agent's skills folder).
name
vpn-security-check
description
Infrastructure security audit for VPN server. Use when user asks 'check security', 'is my VPN safe', 'audit security', 'security check'. Also use after deployment when user has security concerns.

VPN Infrastructure Security Audit

Checks that the VPN server is properly hardened. All checks run via ssh_exec.py — no additional tools needed.

When to Use

  • User asks about security: "check security", "is my VPN safe"
  • After initial deployment (offer proactively)
  • User has security concerns
  • Periodic security checkup

The Iron Law

EVERY CHECK MUST RUN A COMMAND. NO ASSUMPTIONS.

"quick-rebuild.sh enables the firewall" is not evidence that the firewall is active. Run the check.

Security Checks

Run ALL checks in order. Report each as PASS/FAIL/WARN with evidence.

1. SSH Hardening

1a. SSH Port

Command: python ssh_exec.py exec "grep -E '^Port ' /etc/ssh/sshd_config"

ResultRating
Port != 22 (e.g., 49152)PASS
Port 22FAIL — TSPU scans and blocks port 22 to foreign IPs. Change with: python ssh_exec.py exec "sed -i 's/^Port 22/Port 49152/' /etc/ssh/sshd_config && systemctl restart sshd"

1b. Root Password Login

Command: python ssh_exec.py exec "grep -E '^PasswordAuthentication' /etc/ssh/sshd_config"

ResultRating
PasswordAuthentication noPASS
PasswordAuthentication yesWARN — Key-only auth is more secure. Note: some beginners use password auth intentionally. Inform, don't force change
Not set (commented out)WARN — defaults to yes on most distros
2. Firewall

2a. UFW Status

Command: python ssh_exec.py exec "ufw status verbose"

ResultRating
Status: active, rules for 443/8443/2053/SSH portPASS
Status: inactiveFAIL — python ssh_exec.py exec "ufw --force enable"
Active but missing expected portsWARN — check if needed ports are open

2b. Open Ports (reality check)

Command: python ssh_exec.py exec "ss -tnlp | grep -E 'LISTEN' | awk '{print \$4, \$6}'"

Verify only expected services are listening:

  • xray on 443, 8443, 2053 (VPN)
  • x-ui panel (some high port)
  • sshd on configured port
  • nginx on 80 (camouflage)

Any unexpected service = WARN

3. Intrusion Prevention

3a. fail2ban

Command: python ssh_exec.py exec "systemctl is-active fail2ban && fail2ban-client status sshd 2>/dev/null | grep -E 'Currently|Total'"

ResultRating
active + shows ban statsPASS
inactive or not installedFAIL — python ssh_exec.py exec "apt install -y fail2ban && systemctl enable --now fail2ban"
4. VPN Service Security

4a. 3X-UI Panel Access

Command: python ssh_exec.py exec "grep -E 'webPort|webBasePath' /etc/x-ui/x-ui.db 2>/dev/null || echo 'db not readable as text'"

Check:

  • Panel is on non-standard port (not 80, 443, 8080, 2053)
  • Panel base path is randomized (not / or /panel)

If DB not readable as text, try: python ssh_exec.py exec "x-ui settings show 2>/dev/null || echo 'cannot read settings'"

ResultRating
Non-standard port + randomized pathPASS
Default port or path = "/"WARN — Panel is discoverable. Suggest changing via x-ui settings

4b. Xray Running with Expected Config

Command: python ssh_exec.py exec "xray version 2>/dev/null || /usr/local/x-ui/bin/xray-linux-amd64 version 2>/dev/null"

ResultRating
Version >= 24.xPASS
Old versionWARN — Update with python ssh_exec.py update-xray
Show full SKILL.md (240 more words)Show less
5. Camouflage

5a. Nginx Responding

Command: python ssh_exec.py exec "curl -s -o /dev/null -w '%{http_code}' http://localhost:80"

ResultRating
200PASS — Camouflage page is active
Connection refused / otherWARN — Without nginx, port scanners see an unusual server profile
6. Secrets Management

6a. .env Not in Git

Command (local): Check .gitignore includes .env AND git ls-files .env returns nothing

ResultRating
.env is gitignored and not trackedPASS
.env is tracked in gitCRITICAL FAIL — git rm --cached .env immediately. Credentials are exposed!

6b. Credentials File Permissions (on server)

Command: python ssh_exec.py exec "ls -la /root/vpn-credentials.txt 2>/dev/null || echo 'not found'"

ResultRating
Permissions -rw------- (600) or not foundPASS
World-readable (644, 755, etc.)WARN — python ssh_exec.py exec "chmod 600 /root/vpn-credentials.txt"
7. System Updates

Command: python ssh_exec.py exec "apt list --upgradable 2>/dev/null | tail -n +2 | wc -l"

ResultRating
0 or <5 pending updatesPASS
5+ pending security updatesWARN — python ssh_exec.py exec "apt update && apt upgrade -y"

Report Format

Present as a security scorecard (in Russian):

Аудит безопасности VPN-сервера:

  SSH:
    1a. SSH-порт:              [PASS/FAIL]
    1b. Парольная авторизация: [PASS/WARN]
  
  Firewall:
    2a. UFW:                   [PASS/FAIL]
    2b. Открытые порты:        [PASS/WARN]
  
  Защита от вторжений:
    3a. fail2ban:              [PASS/FAIL]
  
  VPN-сервис:
    4a. Панель 3X-UI:          [PASS/WARN]
    4b. Версия Xray:           [PASS/WARN]
  
  Камуфляж:
    5a. Nginx:                 [PASS/WARN]
  
  Секреты:
    6a. .env в git:            [PASS/CRITICAL]
    6b. Файл credentials:     [PASS/WARN]
  
  Обновления:
    7.  Системные:             [PASS/WARN]

Итого: X/10 проверок пройдено

For each FAIL/WARN: provide the specific fix command. For CRITICAL: fix immediately before continuing.

Communication Rules

  • Communicate in Russian
  • Run every check — do not skip "because the deploy script handles it"
  • If a check fails, provide the exact fix command
  • Do not alarm the user unnecessarily — WARN is informational, FAIL needs action, CRITICAL needs immediate action
  • Remind user this is an infrastructure audit, not a guarantee of anonymity (VPN protects from censorship, not from targeted surveillance)

© Sergei-thinker, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/vpn-security-check of Sergei-thinker/vpn-setup.

Open the folder on GitHubat commit 486bf50

Compare with similar skills

Vpn Security Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vpn Security Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vpn Security Check this skillSergei-thinker/vpn-setup189—~1.5kAutomated safety check: NotesMIT
Healthcheckunderstudy-ai/understudy462—~1.2kAutomated safety check: PassMIT
Healthchecktrpc-group/trpc-agent-go1.9k9 repos~2.6kAutomated safety check: PassApache-2.0
Security Setupluongnv89/skills131—~4.5kAutomated safety check: PassMIT
Security AuditaAAaqwq/AGI-Super-Team1052 repos~619Automated safety check: NotesMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT

Similar skills

  • Healthcheck

    understudy-ai/understudy

    Host security hardening and risk-tolerance guidance for Understudy deployments.

    462 GitHub stars~1.2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Healthcheck

    trpc-group/trpc-agent-go

    Host security hardening and risk-tolerance configuration for OpenClaw deployments.

    1.9k GitHub starsUsed in 9 repos~2.6k tokens
    SecurityAuto-check passed
  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    aAAaqwq/AGI-Super-Team

    Comprehensive security auditing for Clawdbot deployments. An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub starsUsed in 2 repos~619 tokens
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Robotics Security

    arpitg1304/robotics-agent-skills

    Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.

    369 GitHub stars~7.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: warnings

More from Sergei-thinker/vpn-setup

  • Vpn Deploy

    Sergei-thinker/vpn-setup

    Guided VPN deployment wizard. An agent skill from Sergei-thinker/vpn-setup.

    189 GitHub stars~1.4k tokensUpdated 5 mo ago
    Auto-check: notes
  • Vpn Troubleshoot

    Sergei-thinker/vpn-setup

    VPN troubleshooting decision tree. An agent skill from Sergei-thinker/vpn-setup.

    189 GitHub stars~2.2k tokensUpdated 5 mo ago
    Auto-check: notes
  • Vpn Verify

    Sergei-thinker/vpn-setup

    Post-deployment verification checklist for VPN. An agent skill from Sergei-thinker/vpn-setup.

    189 GitHub stars~1k tokensUpdated 5 mo ago
    Auto-check: notes

Works with

Questions about Vpn Security Check

What does Vpn Security Check do?

Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup. Vpn Security Check is an agent skill from Sergei-thinker/vpn-setup. Infrastructure security audit for VPN server.

When should I use Vpn Security Check?

Vpn Security Check fits situations like: user asks check security; has security concerns.

How do I install Vpn Security Check in Claude Code?

Run `npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a claude-code`. Or copy the skill folder (.claude/skills/vpn-security-check in Sergei-thinker/vpn-setup) into .claude/skills/vpn-security-check in your project. Claude Code loads it when a task matches its description.

How do I install Vpn Security Check in Codex?

Run `npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a codex`. Or copy the skill folder (.claude/skills/vpn-security-check in Sergei-thinker/vpn-setup) into .agents/skills/vpn-security-check in your project. Codex loads it when a task matches its description.

Can I use Vpn Security Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vpn-security-check, .gemini/skills/vpn-security-check, .github/skills/vpn-security-check and .opencode/skills/vpn-security-check in your project.

What does Vpn Security Check need to run?

Going by SKILL.md and its folder, Vpn Security Check needs the command-line tools its instructions call (python, git and apt). Our summary lists: Python 3.

Does Vpn Security Check access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Vpn Security Check safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Vpn Security Check use?

Vpn Security Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vpn Security Check use?

About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vpn Security Check?

Skills that share tags, products or a category with Vpn Security Check: Healthcheck (understudy-ai/understudy, 462 stars), Healthcheck (trpc-group/trpc-agent-go, 1.9k stars), Security Setup (luongnv89/skills, 131 stars) and Security Audit (aAAaqwq/AGI-Super-Team, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vpn Security Check?

Sergei-thinker (a GitHub user) maintains it in Sergei-thinker/vpn-setup, which has 189 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on April 17, 2026.

Source: Sergei-thinker/vpn-setup on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.