# Ros2 Security

> SROS2: ros2 security CLI, PKI keystore, enclaves, access-control XML, DDS Security.

- **Type:** Skill
- **Install:** `agentstack add skill-leehyunbin0131-claude-ros2-skills-ros2-security`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Leehyunbin0131](https://agentstack.voostack.com/s/leehyunbin0131)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Leehyunbin0131](https://github.com/Leehyunbin0131)
- **Source:** https://github.com/Leehyunbin0131/claude-ros2-skills/tree/main/skills/ros2-security

## Install

```sh
agentstack add skill-leehyunbin0131-claude-ros2-skills-ros2-security
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# ROS 2 Security (SROS2) Instructions (Ubuntu 24.04 LTS & ROS 2 Jazzy)

## 1. Core Principles & Architecture
- **Target OS & ROS Distro**: **Ubuntu 24.04 LTS & ROS 2 Jazzy Jalisco**.
- **Cyber-Physical Security**: SROS2 integrates OMG DDS-Security standards (Fast DDS, Cyclone DDS) to enforce node authentication (X.509 PKI), access control (Governance/Permissions XML), and topic/service encryption (AES-GCM-GMAC 128/256-bit).
- **Zero-Hallucination Policy**: Always verify `ros2 security` CLI subcommands, environment variable names (`ROS_SECURITY_ENABLE`, `ROS_SECURITY_STRATEGY`, `ROS_SECURITY_KEYSTORE`), and policy XML tags against official documentation.

## 2. Official Documentation Catalog

### A. Master Documentation & Tutorials
- **ROS 2 Security Concepts**: `https://docs.ros.org/en/jazzy/Concepts/Intermediate/About-Security.html`
- **Introducing ros2-security Tutorial**: `https://docs.ros.org/en/jazzy/Tutorials/Advanced/Security/Introducing-ros2-security.html`
- **Setting Access Control Policies**: `https://docs.ros.org/en/jazzy/Tutorials/Advanced/Security/Access-Controls.html`

## 3. Key Concepts & Workflows

### A. SROS2 CLI Commands
```bash
# 1. Create root keystore
ros2 security create_keystore ~/my_keystore

# 2. Create security enclave for node
ros2 security create_enclave ~/my_keystore /talker_listener/talker

# 3. Launch node inside enclave
export ROS_SECURITY_ENABLE=true
export ROS_SECURITY_STRATEGY=Enforce
export ROS_SECURITY_KEYSTORE=~/my_keystore

ros2 run demo_nodes_cpp talker --ros-args --enclave /talker_listener/talker
```

### B. High-Level Access Control Policy (`policy.xml`)
```xml

  
    
      
        
          
            chatter
          
        
      
    
  

```

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Leehyunbin0131](https://github.com/Leehyunbin0131)
- **Source:** [Leehyunbin0131/claude-ros2-skills](https://github.com/Leehyunbin0131/claude-ros2-skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-leehyunbin0131-claude-ros2-skills-ros2-security
- Seller: https://agentstack.voostack.com/s/leehyunbin0131
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
