Healthcheck
understudy-ai/understudy
Host security hardening and risk-tolerance guidance for Understudy deployments.
Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.
$ npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sergei-thinker/vpn-setup vpn-security-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sergei-thinker/vpn-setup.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/vpn-security-check .claude/skills/vpn-security-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vpn-security-check" agent skill from https://github.com/Sergei-thinker/vpn-setup/tree/master/.claude/skills/vpn-security-check into .claude/skills/vpn-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vpn-security-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sergei-thinker/vpn-setup/tree/master/.claude/skills/vpn-security-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sergei-thinker/vpn-setup vpn-security-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sergei-thinker/vpn-setup.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/vpn-security-check .agents/skills/vpn-security-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vpn-security-check" agent skill from https://github.com/Sergei-thinker/vpn-setup/tree/master/.claude/skills/vpn-security-check into .agents/skills/vpn-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vpn-security-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sergei-thinker/vpn-setup vpn-security-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sergei-thinker/vpn-setup.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/vpn-security-check .cursor/skills/vpn-security-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vpn-security-check" agent skill from https://github.com/Sergei-thinker/vpn-setup/tree/master/.claude/skills/vpn-security-check into .cursor/skills/vpn-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vpn-security-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sergei-thinker/vpn-setup.git --path .claude/skills/vpn-security-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sergei-thinker/vpn-setup vpn-security-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sergei-thinker/vpn-setup.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/vpn-security-check .gemini/skills/vpn-security-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vpn-security-check" agent skill from https://github.com/Sergei-thinker/vpn-setup/tree/master/.claude/skills/vpn-security-check into .gemini/skills/vpn-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vpn-security-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sergei-thinker/vpn-setup vpn-security-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sergei-thinker/vpn-setup.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/vpn-security-check .github/skills/vpn-security-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vpn-security-check" agent skill from https://github.com/Sergei-thinker/vpn-setup/tree/master/.claude/skills/vpn-security-check into .github/skills/vpn-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vpn-security-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sergei-thinker/vpn-setup vpn-security-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sergei-thinker/vpn-setup.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/vpn-security-check .opencode/skills/vpn-security-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vpn-security-check" agent skill from https://github.com/Sergei-thinker/vpn-setup/tree/master/.claude/skills/vpn-security-check into .opencode/skills/vpn-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vpn-security-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vpn-security-checkInfrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.
Vpn Security Check is an agent skill from Sergei-thinker/vpn-setup. Infrastructure security audit for VPN server. Use when user asks 'check security', 'is my VPN safe', 'audit security', 'security check'. Also use after deployment when user has security concerns.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review and Deployment. It works with Python. The repository describes itself as: Multi-layer VPN (VLESS Reality + Yandex Cloud Relay + WebRTC) for bypassing Russian internet censorship. Automated deployment via Claude Code. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 486bf50. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pythongitaptFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vpn Security Check loads about 1.5k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 651 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
**6a. .env Not in Git**nd (local): Check `.gitignore` includes `.env` AND `git ls-files .env` returns nothing| .env is gitignored and not tracked | PASS || .env is tracked in git | CRITICAL FAIL — `git rm --cached .env` immediately. Credentials are exposed! |6a. .env в git: [PASS/CRITICAL]Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sergei-thinker/vpn-setup at commit 486bf50, republished under its MIT licence (© Sergei-thinker). 651 words, ~1,548 tokens.
.claude/skills/vpn-security-check/SKILL.md (or your agent's skills folder).Checks that the VPN server is properly hardened. All checks run via ssh_exec.py — no additional tools needed.
EVERY CHECK MUST RUN A COMMAND. NO ASSUMPTIONS."quick-rebuild.sh enables the firewall" is not evidence that the firewall is active. Run the check.
Run ALL checks in order. Report each as PASS/FAIL/WARN with evidence.
1a. SSH Port
Command: python ssh_exec.py exec "grep -E '^Port ' /etc/ssh/sshd_config"
| Result | Rating |
|---|---|
| Port != 22 (e.g., 49152) | PASS |
| Port 22 | FAIL — TSPU scans and blocks port 22 to foreign IPs. Change with: python ssh_exec.py exec "sed -i 's/^Port 22/Port 49152/' /etc/ssh/sshd_config && systemctl restart sshd" |
1b. Root Password Login
Command: python ssh_exec.py exec "grep -E '^PasswordAuthentication' /etc/ssh/sshd_config"
| Result | Rating |
|---|---|
| PasswordAuthentication no | PASS |
| PasswordAuthentication yes | WARN — Key-only auth is more secure. Note: some beginners use password auth intentionally. Inform, don't force change |
| Not set (commented out) | WARN — defaults to yes on most distros |
2a. UFW Status
Command: python ssh_exec.py exec "ufw status verbose"
| Result | Rating |
|---|---|
| Status: active, rules for 443/8443/2053/SSH port | PASS |
| Status: inactive | FAIL — python ssh_exec.py exec "ufw --force enable" |
| Active but missing expected ports | WARN — check if needed ports are open |
2b. Open Ports (reality check)
Command: python ssh_exec.py exec "ss -tnlp | grep -E 'LISTEN' | awk '{print \$4, \$6}'"
Verify only expected services are listening:
Any unexpected service = WARN
3a. fail2ban
Command: python ssh_exec.py exec "systemctl is-active fail2ban && fail2ban-client status sshd 2>/dev/null | grep -E 'Currently|Total'"
| Result | Rating |
|---|---|
| active + shows ban stats | PASS |
| inactive or not installed | FAIL — python ssh_exec.py exec "apt install -y fail2ban && systemctl enable --now fail2ban" |
4a. 3X-UI Panel Access
Command: python ssh_exec.py exec "grep -E 'webPort|webBasePath' /etc/x-ui/x-ui.db 2>/dev/null || echo 'db not readable as text'"
Check:
/ or /panel)If DB not readable as text, try: python ssh_exec.py exec "x-ui settings show 2>/dev/null || echo 'cannot read settings'"
| Result | Rating |
|---|---|
| Non-standard port + randomized path | PASS |
| Default port or path = "/" | WARN — Panel is discoverable. Suggest changing via x-ui settings |
4b. Xray Running with Expected Config
Command: python ssh_exec.py exec "xray version 2>/dev/null || /usr/local/x-ui/bin/xray-linux-amd64 version 2>/dev/null"
| Result | Rating |
|---|---|
| Version >= 24.x | PASS |
| Old version | WARN — Update with python ssh_exec.py update-xray |
5a. Nginx Responding
Command: python ssh_exec.py exec "curl -s -o /dev/null -w '%{http_code}' http://localhost:80"
| Result | Rating |
|---|---|
| 200 | PASS — Camouflage page is active |
| Connection refused / other | WARN — Without nginx, port scanners see an unusual server profile |
6a. .env Not in Git
Command (local): Check .gitignore includes .env AND git ls-files .env returns nothing
| Result | Rating |
|---|---|
| .env is gitignored and not tracked | PASS |
| .env is tracked in git | CRITICAL FAIL — git rm --cached .env immediately. Credentials are exposed! |
6b. Credentials File Permissions (on server)
Command: python ssh_exec.py exec "ls -la /root/vpn-credentials.txt 2>/dev/null || echo 'not found'"
| Result | Rating |
|---|---|
| Permissions -rw------- (600) or not found | PASS |
| World-readable (644, 755, etc.) | WARN — python ssh_exec.py exec "chmod 600 /root/vpn-credentials.txt" |
Command: python ssh_exec.py exec "apt list --upgradable 2>/dev/null | tail -n +2 | wc -l"
| Result | Rating |
|---|---|
| 0 or <5 pending updates | PASS |
| 5+ pending security updates | WARN — python ssh_exec.py exec "apt update && apt upgrade -y" |
Present as a security scorecard (in Russian):
Аудит безопасности VPN-сервера:
SSH:
1a. SSH-порт: [PASS/FAIL]
1b. Парольная авторизация: [PASS/WARN]
Firewall:
2a. UFW: [PASS/FAIL]
2b. Открытые порты: [PASS/WARN]
Защита от вторжений:
3a. fail2ban: [PASS/FAIL]
VPN-сервис:
4a. Панель 3X-UI: [PASS/WARN]
4b. Версия Xray: [PASS/WARN]
Камуфляж:
5a. Nginx: [PASS/WARN]
Секреты:
6a. .env в git: [PASS/CRITICAL]
6b. Файл credentials: [PASS/WARN]
Обновления:
7. Системные: [PASS/WARN]
Итого: X/10 проверок пройденоFor each FAIL/WARN: provide the specific fix command. For CRITICAL: fix immediately before continuing.
© Sergei-thinker, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/vpn-security-check of Sergei-thinker/vpn-setup.
Open the folder on GitHubat commit 486bf50
Vpn Security Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vpn Security Check this skillSergei-thinker/vpn-setup | 189 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Healthcheckunderstudy-ai/understudy | 462 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Healthchecktrpc-group/trpc-agent-go | 1.9k | 9 repos | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Security Setupluongnv89/skills | 131 | — | ~4.5k | Automated safety check: Pass | MIT | |
| Security AuditaAAaqwq/AGI-Super-Team | 105 | 2 repos | ~619 | Automated safety check: Notes | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT |
understudy-ai/understudy
Host security hardening and risk-tolerance guidance for Understudy deployments.
trpc-group/trpc-agent-go
Host security hardening and risk-tolerance configuration for OpenClaw deployments.
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
aAAaqwq/AGI-Super-Team
Comprehensive security auditing for Clawdbot deployments. An agent skill from aAAaqwq/AGI-Super-Team.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
arpitg1304/robotics-agent-skills
Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.
Sergei-thinker/vpn-setup
Guided VPN deployment wizard. An agent skill from Sergei-thinker/vpn-setup.
Sergei-thinker/vpn-setup
VPN troubleshooting decision tree. An agent skill from Sergei-thinker/vpn-setup.
Sergei-thinker/vpn-setup
Post-deployment verification checklist for VPN. An agent skill from Sergei-thinker/vpn-setup.
Works with
Categories
Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup. Vpn Security Check is an agent skill from Sergei-thinker/vpn-setup. Infrastructure security audit for VPN server.
Vpn Security Check fits situations like: user asks check security; has security concerns.
Run `npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a claude-code`. Or copy the skill folder (.claude/skills/vpn-security-check in Sergei-thinker/vpn-setup) into .claude/skills/vpn-security-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a codex`. Or copy the skill folder (.claude/skills/vpn-security-check in Sergei-thinker/vpn-setup) into .agents/skills/vpn-security-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sergei-thinker/vpn-setup --skill vpn-security-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vpn-security-check, .gemini/skills/vpn-security-check, .github/skills/vpn-security-check and .opencode/skills/vpn-security-check in your project.
Going by SKILL.md and its folder, Vpn Security Check needs the command-line tools its instructions call (python, git and apt). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Vpn Security Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vpn Security Check: Healthcheck (understudy-ai/understudy, 462 stars), Healthcheck (trpc-group/trpc-agent-go, 1.9k stars), Security Setup (luongnv89/skills, 131 stars) and Security Audit (aAAaqwq/AGI-Super-Team, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sergei-thinker (a GitHub user) maintains it in Sergei-thinker/vpn-setup, which has 189 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on April 17, 2026.
Source: Sergei-thinker/vpn-setup on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.