Agent skill

User Management

by sickn33 in sickn33/agentic-awesome-skills

Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check: notesSecurity

Install User Management

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill user-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills user-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/user-management .claude/skills/user-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
user-management
GitHub stars
47k
Used in
2 other repos
Token cost
~2.8k tokens
SKILL.md length
321 words
Files
1
Skills in repo
1,354
Repo updated
First seen
Licence
MIT

At a glance

Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills.

  • Managing system access
  • SKILL.md covers When to Use, Prerequisites, User Operations and Group Management, plus 8 more sections
  • Calls apt, dnf and openssl
  • Tasks that involve Authorization and RBAC

What it does

User Management is an agent skill from sickn33/agentic-awesome-skills. Manage users, groups, and permissions on Linux systems. Configure sudo and access controls. Use when managing system access.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

It sits in Security, covering Authorization and RBAC. It works with Linux. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Managing system access
  • Tasks that involve Authorization and RBAC

Example prompts

  • “/user-management”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • dnf
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

User Management loads about 2.8k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 321 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:22
    Manage users, groups, permissions, sudo access, PAM modules, and LDAP integration on Linux systems. Includes practical s
  • NoteRuns commands with sudoSKILL.md:27
    - Configuring sudo access with fine-grained privilege controls
  • NoteRuns commands with sudoSKILL.md:35
    - Root or sudo access on the target system
  • NoteRuns commands with sudoSKILL.md:69
    usermod -aG sudo jsmith
  • NoteRuns commands with sudoSKILL.md:163
    # Allow a deploy user full sudo with no password
  • NoteRuns commands with sudoSKILL.md:175
    # Log all sudo commands to a dedicated file
  • NoteRuns commands with sudoSKILL.md:183
    # Require password for sudo even if user has NOPASSWD elsewhere
  • NoteRuns commands with sudoSKILL.md:191
    # Check what sudo permissions a user has
  • NoteRuns commands with sudoSKILL.md:192
    sudo -l -U jsmith
  • NoteRuns commands with sudoSKILL.md:194
    # Test a specific sudo command as a user

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 321 words, ~2,773 tokens.

Download SKILL.mdSave it as .claude/skills/user-management/SKILL.md (or your agent's skills folder).
name
user-management
description
Manage users, groups, and permissions on Linux systems. Configure sudo and access controls. Use when managing system access.
compatibility
Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
category
devops
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

User Management

Manage users, groups, permissions, sudo access, PAM modules, and LDAP integration on Linux systems. Includes practical scripts for bulk user operations and access auditing.

When to Use

  • Creating and managing local user accounts on Linux servers
  • Configuring sudo access with fine-grained privilege controls
  • Setting up group-based access control for teams
  • Integrating Linux hosts with LDAP or Active Directory for centralized auth
  • Auditing user accounts, permissions, and access patterns
  • Automating bulk user provisioning and deprovisioning

Prerequisites

  • Root or sudo access on the target system
  • shadow-utils package (provides useradd, usermod, etc.) -- installed by default
  • libpam-modules for PAM configuration
  • For LDAP: sssd, realmd, libpam-ldapd, or nslcd packages
  • For auditing: auditd package

User Operations

Creating Users
bash
# Create a user with home directory, default shell, and comment
useradd -m -s /bin/bash -c "Jane Smith" jsmith

# Set the user's password interactively
passwd jsmith

# Create a user with a specific UID and primary group
useradd -m -s /bin/bash -u 1500 -g developers -c "Deploy Account" deploy

# Create a system account (no home, no login shell) for running services
useradd -r -s /usr/sbin/nologin -d /opt/myapp -c "MyApp Service Account" myapp

# Create a user with an expiration date (contractor access)
useradd -m -s /bin/bash -e 2025-12-31 -c "Contractor - Bob Lee" blee

# Create user and add to multiple supplementary groups at creation time
useradd -m -s /bin/bash -G docker,developers,ssh-users -c "Dev User" devuser
Modifying Users
bash
# Add a user to a supplementary group (preserving existing groups with -a)
usermod -aG sudo jsmith
usermod -aG docker,developers jsmith

# Change the user's login shell
usermod -s /bin/zsh jsmith

# Change the user's home directory and move existing files
usermod -d /home/jsmith-new -m jsmith

# Lock a user account (disable login without deleting)
usermod -L jsmith

# Unlock a user account
usermod -U jsmith

# Set an account expiration date
usermod -e 2025-06-30 blee

# Change a user's login name
usermod -l jsmith-new jsmith

# Force password change on next login
chage -d 0 jsmith

# Set password aging: min 7 days, max 90 days, warn 14 days before
chage -m 7 -M 90 -W 14 jsmith

# View password aging info
chage -l jsmith
Deleting Users
bash
# Remove a user and their home directory
userdel -r jsmith

# Remove a user but keep their home directory (for auditing)
userdel jsmith

# Find and reassign files owned by a deleted user (by UID)
find / -uid 1500 -exec chown newowner:newgroup {} \;

Group Management

bash
# Create a new group
groupadd developers

# Create a group with a specific GID
groupadd -g 2000 devops

# Add a user to a group
usermod -aG developers jsmith
# Alternative using gpasswd
gpasswd -a jsmith developers

# Remove a user from a group
gpasswd -d jsmith developers

# Set group administrators (can add/remove members without root)
gpasswd -A jsmith developers

# Delete a group
groupdel developers

# List all groups a user belongs to
groups jsmith
id jsmith

# List all members of a group
getent group developers

# Show all groups on the system
cat /etc/group | cut -d: -f1 | sort

Sudo Configuration

bash
# Always edit sudoers via visudo (syntax validation prevents lockout)
visudo

# Better: use drop-in files in /etc/sudoers.d/
visudo -f /etc/sudoers.d/developers
/etc/sudoers.d/developers
text
# Allow the developers group to restart specific services
%developers ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart myapp, /usr/bin/systemctl status myapp

# Allow a deploy user full sudo with no password
deploy ALL=(ALL) NOPASSWD: ALL

# Allow ops team to run docker commands only
%ops ALL=(ALL) NOPASSWD: /usr/bin/docker, /usr/bin/docker-compose

# Allow a user to run commands as a specific service account
jsmith ALL=(myapp) NOPASSWD: /opt/myapp/bin/*

# Restrict to specific hosts (useful with centralized sudoers)
jsmith dbservers=(root) /usr/bin/systemctl restart postgresql

# Log all sudo commands to a dedicated file
Defaults log_output
Defaults!/usr/bin/sudoreplay !log_output
Defaults logfile="/var/log/sudo.log"

# Require password re-entry every 5 minutes (default is 15)
Defaults timestamp_timeout=5

# Require password for sudo even if user has NOPASSWD elsewhere
Defaults:jsmith !authenticate
bash
# Validate sudoers syntax without applying
visudo -c

# Check what sudo permissions a user has
sudo -l -U jsmith

# Test a specific sudo command as a user
sudo -u myapp /opt/myapp/bin/healthcheck.sh

File Permissions and ACLs

bash
# Standard permissions
chmod 755 /opt/myapp           # rwxr-xr-x
chmod 640 /etc/myapp.conf      # rw-r-----
chmod u+x script.sh            # Add execute for owner
chmod g+w shared-dir/          # Add write for group
chmod o-rwx private-file       # Remove all permissions for others

# Change ownership
chown deploy:developers /opt/myapp
chown -R deploy:developers /opt/myapp/   # Recursive

# Set the SGID bit (new files inherit group ownership)
chmod g+s /opt/shared/

# Set the sticky bit (only owner can delete their files)
chmod +t /tmp/shared/

# Access Control Lists (ACLs) for fine-grained control
# Grant read-execute to a specific user on a directory
setfacl -m u:jsmith:rx /opt/myapp/logs/

# Grant read-write to a group
setfacl -m g:developers:rw /opt/shared/

# Set default ACL (applied to new files created in the directory)
setfacl -d -m g:developers:rw /opt/shared/

# View ACLs
getfacl /opt/shared/

# Remove a specific ACL entry
setfacl -x u:jsmith /opt/myapp/logs/

# Remove all ACLs
setfacl -b /opt/shared/

PAM Configuration

bash
# PAM config files are in /etc/pam.d/
# Each file controls auth for a specific service (sshd, login, sudo, etc.)

# Enforce password complexity via pam_pwquality
# /etc/pam.d/common-password (Debian) or /etc/pam.d/system-auth (RHEL)
password requisite pam_pwquality.so retry=3 minlen=12 dcredit=-1 ucredit=-1 ocredit=-1 lcredit=-1

# Configure /etc/security/pwquality.conf
minlen = 12
dcredit = -1
ucredit = -1
ocredit = -1
lcredit = -1
maxrepeat = 3
dictcheck = 1

# Limit concurrent logins per user
# /etc/security/limits.conf
jsmith hard maxlogins 3
@developers hard maxlogins 5

# Lock account after 5 failed login attempts
# /etc/pam.d/common-auth (Debian)
auth required pam_faillock.so preauth silent deny=5 unlock_time=900
auth required pam_faillock.so authfail deny=5 unlock_time=900

# View failed login attempts
faillock --user jsmith

# Unlock a locked account
faillock --user jsmith --reset

LDAP / Active Directory Integration

bash
# Install SSSD and realmd for AD integration (Ubuntu/Debian)
apt install -y sssd realmd adcli sssd-tools libnss-sss libpam-sss

# Install SSSD and realmd (RHEL/CentOS)
dnf install -y sssd realmd adcli sssd-tools oddjob oddjob-mkhomedir

# Discover and join an Active Directory domain
realm discover corp.example.com
realm join corp.example.com -U admin@CORP.EXAMPLE.COM

# Verify the join
realm list

# Allow specific AD groups to log in
realm permit -g "Linux Admins@corp.example.com"
realm permit -g "Developers@corp.example.com"

# Deny all except permitted groups
realm deny --all
realm permit -g "Linux Admins@corp.example.com"

# Restart SSSD after config changes
systemctl restart sssd

# Test LDAP user lookup
id jsmith
getent passwd jsmith

# Grant sudo to an AD group
echo '%linux\ admins ALL=(ALL) ALL' > /etc/sudoers.d/ad-admins

Bulk User Management Scripts

Bulk User Creation from CSV
bash
#!/bin/bash
# bulk-create-users.sh
# CSV format: username,fullname,groups,shell
# Example: jsmith,Jane Smith,developers;docker,/bin/bash

CSV_FILE="${1:?Usage: $0 <users.csv>}"

while IFS=',' read -r username fullname groups shell; do
  # Skip header line
  [[ "$username" == "username" ]] && continue

  if id "$username" &>/dev/null; then
    echo "SKIP: User $username already exists"
    continue
  fi

  # Replace semicolons with commas for -G flag
  group_list="${groups//;/,}"

  useradd -m -s "$shell" -c "$fullname" -G "$group_list" "$username"
  # Generate a random temporary password
  temp_pass=$(openssl rand -base64 12)
  echo "$username:$temp_pass" | chpasswd
  chage -d 0 "$username"   # Force password change at first login

  echo "CREATED: $username (groups: $group_list) temp-pass: $temp_pass"
done < "$CSV_FILE"
Quick Access Audit Commands
bash
# List non-system users (UID >= 1000)
awk -F: '$3 >= 1000 && $3 < 65534 { printf "%-20s UID=%-6s Shell=%s\n", $1, $3, $7 }' /etc/passwd

# List users with sudo access
getent group sudo wheel 2>/dev/null

# Find accounts that have never logged in
lastlog | awk '$0 ~ /Never logged in/ { print $1 }'

# Find accounts with empty passwords
awk -F: '($2 == "" || $2 == "!") { print $1 }' /etc/shadow 2>/dev/null

Troubleshooting

SymptomDiagnostic CommandCommon Fix
User cannot log inpasswd -S username, faillock --user usernameUnlock account, reset password, check shell
"not in sudoers" errorsudo -l -U usernameAdd user to sudo group or create sudoers.d file
Group membership not appliedid username, groups usernameUser must log out and back in for new groups
LDAP/AD user not foundid aduser, sssctl user-show aduserCheck SSSD status, clear cache: sss_cache -E
Permission denied on filels -la file, getfacl fileFix ownership/permissions, check SELinux context
PAM lockout after failed attemptsfaillock --user usernamefaillock --user username --reset
Home directory not createdCheck /etc/login.defs CREATEHOMEUse useradd -m or enable pam_mkhomedir
Password policy not enforcedCheck /etc/pam.d/common-passwordInstall and configure pam_pwquality
  • linux-administration -- General Linux server management
  • ssh-configuration -- SSH key-based authentication for managed users
  • systemd-services -- Service accounts and systemd user instances
  • performance-tuning -- Resource limits per user via cgroups and ulimits

Limitations

  • Infrastructure commands can disrupt services: confirm target host/scope and have backups/snapshots before mutating state.
  • Docs-only import: upstream scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/user-management of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit ec02547

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

User Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

User Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
User Management this skillsickn33/agentic-awesome-skills47k2 repos~2.8kAutomated safety check: NotesMIT
Defender For Endpointvinayaklatthe/microsoft-security-skills175—~2.3kAutomated safety check: PassMIT
Detecting Privilege Escalation In Kubernetes Podsmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0
Iamitsmostafa/aws-agent-skills1.2k—~1.8kAutomated safety check: PassMIT

Similar skills

  • Defender For Endpoint

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation…

    175 GitHub stars~2.3k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Detecting Privilege Escalation In Kubernetes Pods

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Iam

    itsmostafa/aws-agent-skills

    AWS Identity and Access Management for users, roles, policies, and permissions.

    1.2k GitHub stars~1.8k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Reviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it.

    2k GitHub stars~1.1k tokensUpdated 21 days ago
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Works with

Questions about User Management

What does User Management do?

Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills. User Management is an agent skill from sickn33/agentic-awesome-skills. Manage users, groups, and permissions on Linux systems.

When should I use User Management?

User Management fits situations like: managing system access; tasks that involve Authorization and RBAC.

How do I install User Management in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill user-management -a claude-code`. Or copy the skill folder (skills/user-management in sickn33/agentic-awesome-skills) into .claude/skills/user-management in your project. Claude Code loads it when a task matches its description.

How do I install User Management in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill user-management -a codex`. Or copy the skill folder (skills/user-management in sickn33/agentic-awesome-skills) into .agents/skills/user-management in your project. Codex loads it when a task matches its description.

Can I use User Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill user-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/user-management, .gemini/skills/user-management, .github/skills/user-management and .opencode/skills/user-management in your project.

What does User Management need to run?

Going by SKILL.md and its folder, User Management needs the command-line tools its instructions call (apt, dnf and openssl). Our summary lists: Docker. Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled..

Does User Management access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is User Management safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does User Management use?

User Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does User Management use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to User Management?

Skills that share tags, products or a category with User Management: Defender For Endpoint (vinayaklatthe/microsoft-security-skills, 175 stars), Detecting Privilege Escalation In Kubernetes Pods (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Configuring Horizon (coollabsio/coolify, 63k stars) and K8s Security Policies (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains User Management?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.