Install
$ agentstack add skill-scoobydont-666-shared-claude-skills-ansible-hardening ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Ansible Hardening
Codify manual security work into idempotent Ansible roles. Every hardening step performed by hand should eventually become a role in this collection.
Roles Needed (from manual work done 2026-03-21)
crowdsec
Installs CrowdSec agent + firewall bouncer, configures collections, whitelists LAN.
# defaults
crowdsec_lapi_port: 8088 # moved from 8080 for OpenShell
crowdsec_collections:
- crowdsecurity/sshd
- crowdsecurity/linux
crowdsec_whitelist_cidrs:
- "{{ lan_subnet }}"
fail2ban
Installs fail2ban, configures SSH jail.
# defaults
fail2ban_maxretry: 3
fail2ban_bantime: 3600
fail2ban_findtime: 600
auditd
Installs auditd, deploys audit rules for sensitive files.
# defaults
auditd_watch_paths:
- { path: /etc/sudoers, key: sudoers_changes }
- { path: /etc/sudoers.d/, key: sudoers_changes }
- { path: /etc/ssh/sshd_config, key: ssh_config }
- { path: /etc/monero/, key: monero_config }
tailscale
Installs Tailscale, configures serve endpoints.
# defaults
tailscale_serve_ports: [] # list of {local_port, description}
tailscale_funnel: false # never enable funnel by default
Note: tailscale up requires interactive auth — role should detect and prompt.
semaphore
Installs Semaphore binary, creates config + systemd unit.
# defaults
semaphore_version: "2.17.27"
semaphore_port: 3001
semaphore_bind: "127.0.0.1"
semaphore_db: bolt # bolt or postgres
sudoers-scope
Replaces blanket NOPASSWD with scoped command list.
# defaults
sudoers_nopasswd_commands:
- /usr/bin/systemctl
- /usr/bin/journalctl
- /usr/bin/apt
- /usr/bin/apt-get
# ... full list from /etc/sudoers.d/admin_user
Implementation Pattern
Each role follows monero-farm conventions:
defaults/main.yml— all variables with safe defaultstasks/main.yml— idempotent taskshandlers/main.yml— restart/reload handlerstemplates/— config file templates (Jinja2)
Rules
- Always
--check --diffbefore real runs - Never remove existing security controls — only add/tighten
- Whitelist LAN subnet before enabling firewall bouncers
- Tailscale auth is interactive — can't be fully automated
- Test on a primary host first, then roll to fleet
Where To Build
These roles belong in your project's ansible/roles/ directory alongside existing roles (base, application-specific, monitoring). The security roles extend the base role's hardening.
Alternatively, create a standalone ansible-hardening collection at /ansible-hardening/ if the scope grows and needs to be reused across multiple projects.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: scoobydont-666
- Source: scoobydont-666/shared-claude-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.