Manage CrowdSec security stack across bare-metal, Docker, and Kubernetes: install, configure, operate cscli, LAPI, hub collections, bouncers (firewall, nginx, traefik, caddy), deploy WAF/AppSec, and migrate from fail2ban.
Install, configure, operate, and debug CrowdSec — straight from your terminal, with Claude doing the heavy lifting.
This is an Agent Skill that turns Claude/Codex/... into a
hands-on CrowdSec operator. Ask it to stand up an engine, wire a bouncer, enable
the WAF, or figure out why nothing's getting blocked — it knows the cscli
commands, the config layout, the failure modes, and the safe way through each of
them across bare-metal/systemd, Docker, OpnSense and Kubernetes/Helm.
| Area | Covered |
|---|---|
| Install | bare-metal/systemd · Docker · Kubernetes/Helm · OpnSense · Console enrollment |
| Bouncers | firewall (iptables/nftables/ipset) · nginx · traefik · caddy · apache · and more |
| WAF / AppSec | deploy · configure · troubleshoot the AppSec component |
| Hub | install collections/parsers/scenarios · update · debug |
| Configure | acquisition · profiles & ban durations · notifications · allowlists |
| Operate | health checks & smoke tests · upgrades & rollback · multi-server / remote LAPI / mTLS |
| Debug | logs not parsing · no alerts firing · bouncer not blocking · specific errors |
The skill loads automatically once installed. Just talk to Claude about CrowdSec.
On Claude
/plugin marketplace add crowdsecurity/crowdsec-skill
/plugin install crowdsec@crowdsecurity
Update later with:
/plugin marketplace update crowdsecurity
On Codex: install the skill with:
skill-installer crowdsecurity/crowdsec-skill
On Claude.ai (web)
Download crowdsec-skill-vX.Y.Z.zip from the
latest release
and upload it in the web skill uploader.
Or directly with skills.sh
npx skills add crowdsecurity/crowdsec-skill
Once installed, Claude picks the skill up whenever your prompt involves CrowdSec:
This is an operational skill. It deploys, configures, and debugs CrowdSec — it does not author detection content. Writing a parser, scenario, or WAF (AppSec) rule is out of scope.
For authoring, head to the CrowdSec Hub and the detection-engineering docs.
Issues and PRs welcome. Improvements to the reference docs and new environment coverage are appreciated. If you see anything missing or wrong, don't hesitate to open a PR.
MIT — see LICENSE.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub crowdsecurity/crowdsec-skill --plugin crowdsec872 on-demand security skills for CTF, pentest, bug bounty, DFIR, detection engineering, cloud, identity, and red/blue team work. Skills are plain Markdown and activate by task without permanently consuming context. Bundles vendored skills under mixed licenses (MIT, Apache-2.0, CC-BY-SA-4.0) — see per-source attribution in .claude/skills/SKILLS.md.
Find security misconfigurations
Sysdig's cloud security expertise, packaged as agent skills that work natively in your AI environment.
Editorial "Security Engineer" bundle for Claude Code from Antigravity Awesome Skills.
Cybersecurity skills for AI agents — code audit, cloud, recon, IR, AI security, and more
Server security auditing, hardening, and fleet management. 470+ security checks across 32 categories, CIS/PCI-DSS/HIPAA compliance, 24-step production hardening, and 17 MCP tools. Supports Hetzner, DigitalOcean, Vultr, Linode with Coolify, Dokploy, and bare VPS modes.