Install the "user-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/user-management into .claude/skills/user-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "user-management", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill user-management -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "user-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/user-management into .agents/skills/user-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "user-management", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill user-management -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "user-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/user-management into .cursor/skills/user-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "user-management", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill user-management -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "user-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/user-management into .gemini/skills/user-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "user-management", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill user-management -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "user-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/user-management into .github/skills/user-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "user-management", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill user-management -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "user-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/user-management into .opencode/skills/user-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "user-management", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
user-management
GitHub stars
47k
Used in
2 other repos
Token cost
~2.8k tokens
SKILL.md length
321 words
Files
1
Skills in repo
1,354
Repo updated
First seen
Licence
MIT
At a glance
Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills.
Managing system access
SKILL.md covers When to Use, Prerequisites, User Operations and Group Management, plus 8 more sections
Calls apt, dnf and openssl
Tasks that involve Authorization and RBAC
What it does
User Management is an agent skill from sickn33/agentic-awesome-skills. Manage users, groups, and permissions on Linux systems. Configure sudo and access controls. Use when managing system access.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
It sits in Security, covering Authorization and RBAC. It works with Linux. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
When your agent uses it
Managing system access
Tasks that involve Authorization and RBAC
Example prompts
“/user-management”
Requirements
Docker
Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
What it can do on your machine
Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
apt
dnf
openssl
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Compatibility
Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
From compatibility in the SKILL.md frontmatter.
Context cost
User Management loads about 2.8k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 321 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~35
When it runs· the whole SKILL.md, loaded when a task matches
~2.8k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check: notes
The automated check noted patterns worth knowing about, such as sudo or a known installer.
NoteRuns commands with sudoSKILL.md:22
Manage users, groups, permissions, sudo access, PAM modules, and LDAP integration on Linux systems. Includes practical s
NoteRuns commands with sudoSKILL.md:27
- Configuring sudo access with fine-grained privilege controls
NoteRuns commands with sudoSKILL.md:35
- Root or sudo access on the target system
NoteRuns commands with sudoSKILL.md:69
usermod -aG sudo jsmith
NoteRuns commands with sudoSKILL.md:163
# Allow a deploy user full sudo with no password
NoteRuns commands with sudoSKILL.md:175
# Log all sudo commands to a dedicated file
NoteRuns commands with sudoSKILL.md:183
# Require password for sudo even if user has NOPASSWD elsewhere
NoteRuns commands with sudoSKILL.md:191
# Check what sudo permissions a user has
NoteRuns commands with sudoSKILL.md:192
sudo -l -U jsmith
NoteRuns commands with sudoSKILL.md:194
# Test a specific sudo command as a user
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Manage users, groups, permissions, sudo access, PAM modules, and LDAP integration on Linux systems. Includes practical scripts for bulk user operations and access auditing.
When to Use
Creating and managing local user accounts on Linux servers
Configuring sudo access with fine-grained privilege controls
Setting up group-based access control for teams
Integrating Linux hosts with LDAP or Active Directory for centralized auth
Auditing user accounts, permissions, and access patterns
Automating bulk user provisioning and deprovisioning
Prerequisites
Root or sudo access on the target system
shadow-utils package (provides useradd, usermod, etc.) -- installed by default
libpam-modules for PAM configuration
For LDAP: sssd, realmd, libpam-ldapd, or nslcd packages
For auditing: auditd package
User Operations
Creating Users
bash
# Create a user with home directory, default shell, and comment
useradd -m -s /bin/bash -c "Jane Smith" jsmith
# Set the user's password interactively
passwd jsmith
# Create a user with a specific UID and primary group
useradd -m -s /bin/bash -u 1500 -g developers -c "Deploy Account" deploy
# Create a system account (no home, no login shell) for running services
useradd -r -s /usr/sbin/nologin -d /opt/myapp -c "MyApp Service Account" myapp
# Create a user with an expiration date (contractor access)
useradd -m -s /bin/bash -e 2025-12-31 -c "Contractor - Bob Lee" blee
# Create user and add to multiple supplementary groups at creation time
useradd -m -s /bin/bash -G docker,developers,ssh-users -c "Dev User" devuser
Modifying Users
bash
# Add a user to a supplementary group (preserving existing groups with -a)
usermod -aG sudo jsmith
usermod -aG docker,developers jsmith
# Change the user's login shell
usermod -s /bin/zsh jsmith
# Change the user's home directory and move existing files
usermod -d /home/jsmith-new -m jsmith
# Lock a user account (disable login without deleting)
usermod -L jsmith
# Unlock a user account
usermod -U jsmith
# Set an account expiration date
usermod -e 2025-06-30 blee
# Change a user's login name
usermod -l jsmith-new jsmith
# Force password change on next login
chage -d 0 jsmith
# Set password aging: min 7 days, max 90 days, warn 14 days before
chage -m 7 -M 90 -W 14 jsmith
# View password aging info
chage -l jsmith
Deleting Users
bash
# Remove a user and their home directory
userdel -r jsmith
# Remove a user but keep their home directory (for auditing)
userdel jsmith
# Find and reassign files owned by a deleted user (by UID)
find / -uid 1500 -exec chown newowner:newgroup {} \;
Group Management
bash
# Create a new group
groupadd developers
# Create a group with a specific GID
groupadd -g 2000 devops
# Add a user to a group
usermod -aG developers jsmith
# Alternative using gpasswd
gpasswd -a jsmith developers
# Remove a user from a group
gpasswd -d jsmith developers
# Set group administrators (can add/remove members without root)
gpasswd -A jsmith developers
# Delete a group
groupdel developers
# List all groups a user belongs to
groups jsmith
id jsmith
# List all members of a group
getent group developers
# Show all groups on the system
cat /etc/group | cut -d: -f1 | sort
Sudo Configuration
bash
# Always edit sudoers via visudo (syntax validation prevents lockout)
visudo
# Better: use drop-in files in /etc/sudoers.d/
visudo -f /etc/sudoers.d/developers
/etc/sudoers.d/developers
text
# Allow the developers group to restart specific services
%developers ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart myapp, /usr/bin/systemctl status myapp
# Allow a deploy user full sudo with no password
deploy ALL=(ALL) NOPASSWD: ALL
# Allow ops team to run docker commands only
%ops ALL=(ALL) NOPASSWD: /usr/bin/docker, /usr/bin/docker-compose
# Allow a user to run commands as a specific service account
jsmith ALL=(myapp) NOPASSWD: /opt/myapp/bin/*
# Restrict to specific hosts (useful with centralized sudoers)
jsmith dbservers=(root) /usr/bin/systemctl restart postgresql
# Log all sudo commands to a dedicated file
Defaults log_output
Defaults!/usr/bin/sudoreplay !log_output
Defaults logfile="/var/log/sudo.log"
# Require password re-entry every 5 minutes (default is 15)
Defaults timestamp_timeout=5
# Require password for sudo even if user has NOPASSWD elsewhere
Defaults:jsmith !authenticate
bash
# Validate sudoers syntax without applying
visudo -c
# Check what sudo permissions a user has
sudo -l -U jsmith
# Test a specific sudo command as a user
sudo -u myapp /opt/myapp/bin/healthcheck.sh
File Permissions and ACLs
bash
# Standard permissions
chmod 755 /opt/myapp # rwxr-xr-x
chmod 640 /etc/myapp.conf # rw-r-----
chmod u+x script.sh # Add execute for owner
chmod g+w shared-dir/ # Add write for group
chmod o-rwx private-file # Remove all permissions for others
# Change ownership
chown deploy:developers /opt/myapp
chown -R deploy:developers /opt/myapp/ # Recursive
# Set the SGID bit (new files inherit group ownership)
chmod g+s /opt/shared/
# Set the sticky bit (only owner can delete their files)
chmod +t /tmp/shared/
# Access Control Lists (ACLs) for fine-grained control
# Grant read-execute to a specific user on a directory
setfacl -m u:jsmith:rx /opt/myapp/logs/
# Grant read-write to a group
setfacl -m g:developers:rw /opt/shared/
# Set default ACL (applied to new files created in the directory)
setfacl -d -m g:developers:rw /opt/shared/
# View ACLs
getfacl /opt/shared/
# Remove a specific ACL entry
setfacl -x u:jsmith /opt/myapp/logs/
# Remove all ACLs
setfacl -b /opt/shared/
PAM Configuration
bash
# PAM config files are in /etc/pam.d/
# Each file controls auth for a specific service (sshd, login, sudo, etc.)
# Enforce password complexity via pam_pwquality
# /etc/pam.d/common-password (Debian) or /etc/pam.d/system-auth (RHEL)
password requisite pam_pwquality.so retry=3 minlen=12 dcredit=-1 ucredit=-1 ocredit=-1 lcredit=-1
# Configure /etc/security/pwquality.conf
minlen = 12
dcredit = -1
ucredit = -1
ocredit = -1
lcredit = -1
maxrepeat = 3
dictcheck = 1
# Limit concurrent logins per user
# /etc/security/limits.conf
jsmith hard maxlogins 3
@developers hard maxlogins 5
# Lock account after 5 failed login attempts
# /etc/pam.d/common-auth (Debian)
auth required pam_faillock.so preauth silent deny=5 unlock_time=900
auth required pam_faillock.so authfail deny=5 unlock_time=900
# View failed login attempts
faillock --user jsmith
# Unlock a locked account
faillock --user jsmith --reset
LDAP / Active Directory Integration
bash
# Install SSSD and realmd for AD integration (Ubuntu/Debian)
apt install -y sssd realmd adcli sssd-tools libnss-sss libpam-sss
# Install SSSD and realmd (RHEL/CentOS)
dnf install -y sssd realmd adcli sssd-tools oddjob oddjob-mkhomedir
# Discover and join an Active Directory domain
realm discover corp.example.com
realm join corp.example.com -U admin@CORP.EXAMPLE.COM
# Verify the join
realm list
# Allow specific AD groups to log in
realm permit -g "Linux Admins@corp.example.com"
realm permit -g "Developers@corp.example.com"
# Deny all except permitted groups
realm deny --all
realm permit -g "Linux Admins@corp.example.com"
# Restart SSSD after config changes
systemctl restart sssd
# Test LDAP user lookup
id jsmith
getent passwd jsmith
# Grant sudo to an AD group
echo '%linux\ admins ALL=(ALL) ALL' > /etc/sudoers.d/ad-admins
Bulk User Management Scripts
Bulk User Creation from CSV
bash
#!/bin/bash
# bulk-create-users.sh
# CSV format: username,fullname,groups,shell
# Example: jsmith,Jane Smith,developers;docker,/bin/bash
CSV_FILE="${1:?Usage: $0 <users.csv>}"
while IFS=',' read -r username fullname groups shell; do
# Skip header line
[[ "$username" == "username" ]] && continue
if id "$username" &>/dev/null; then
echo "SKIP: User $username already exists"
continue
fi
# Replace semicolons with commas for -G flag
group_list="${groups//;/,}"
useradd -m -s "$shell" -c "$fullname" -G "$group_list" "$username"
# Generate a random temporary password
temp_pass=$(openssl rand -base64 12)
echo "$username:$temp_pass" | chpasswd
chage -d 0 "$username" # Force password change at first login
echo "CREATED: $username (groups: $group_list) temp-pass: $temp_pass"
done < "$CSV_FILE"
Quick Access Audit Commands
bash
# List non-system users (UID >= 1000)
awk -F: '$3 >= 1000 && $3 < 65534 { printf "%-20s UID=%-6s Shell=%s\n", $1, $3, $7 }' /etc/passwd
# List users with sudo access
getent group sudo wheel 2>/dev/null
# Find accounts that have never logged in
lastlog | awk '$0 ~ /Never logged in/ { print $1 }'
# Find accounts with empty passwords
awk -F: '($2 == "" || $2 == "!") { print $1 }' /etc/shadow 2>/dev/null
Troubleshooting
Symptom
Diagnostic Command
Common Fix
User cannot log in
passwd -S username, faillock --user username
Unlock account, reset password, check shell
"not in sudoers" error
sudo -l -U username
Add user to sudo group or create sudoers.d file
Group membership not applied
id username, groups username
User must log out and back in for new groups
LDAP/AD user not found
id aduser, sssctl user-show aduser
Check SSSD status, clear cache: sss_cache -E
Permission denied on file
ls -la file, getfacl file
Fix ownership/permissions, check SELinux context
PAM lockout after failed attempts
faillock --user username
faillock --user username --reset
Home directory not created
Check /etc/login.defs CREATEHOME
Use useradd -m or enable pam_mkhomedir
Password policy not enforced
Check /etc/pam.d/common-password
Install and configure pam_pwquality
Related Skills
linux-administration -- General Linux server management
ssh-configuration -- SSH key-based authentication for managed users
systemd-services -- Service accounts and systemd user instances
performance-tuning -- Resource limits per user via cgroups and ulimits
Limitations
Infrastructure commands can disrupt services: confirm target host/scope and have backups/snapshots before mutating state.
Docs-only import: upstream scripts and templates not bundled.
We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
User Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
User Management compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
User Management this skillsickn33/agentic-awesome-skills
Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux…
Reviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it.
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.
Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills. User Management is an agent skill from sickn33/agentic-awesome-skills. Manage users, groups, and permissions on Linux systems.
When should I use User Management?
User Management fits situations like: managing system access; tasks that involve Authorization and RBAC.
How do I install User Management in Claude Code?
Run `npx skills add sickn33/agentic-awesome-skills --skill user-management -a claude-code`. Or copy the skill folder (skills/user-management in sickn33/agentic-awesome-skills) into .claude/skills/user-management in your project. Claude Code loads it when a task matches its description.
How do I install User Management in Codex?
Run `npx skills add sickn33/agentic-awesome-skills --skill user-management -a codex`. Or copy the skill folder (skills/user-management in sickn33/agentic-awesome-skills) into .agents/skills/user-management in your project. Codex loads it when a task matches its description.
Can I use User Management in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill user-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/user-management, .gemini/skills/user-management, .github/skills/user-management and .opencode/skills/user-management in your project.
What does User Management need to run?
Going by SKILL.md and its folder, User Management needs the command-line tools its instructions call (apt, dnf and openssl). Our summary lists: Docker. Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled..
Does User Management access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is User Management safe to install?
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
What licence does User Management use?
User Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does User Management use?
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to User Management?
Skills that share tags, products or a category with User Management: Defender For Endpoint (vinayaklatthe/microsoft-security-skills, 175 stars), Detecting Privilege Escalation In Kubernetes Pods (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Configuring Horizon (coollabsio/coolify, 63k stars) and K8s Security Policies (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains User Management?
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.