Manage CrowdSec security stack: install, configure, operate, and debug cscli, LAPI, bouncers, and WAF/AppSec across systemd, Docker, and Kubernetes, including fail2ban migration.
Install, configure, operate, and debug CrowdSec — straight from your terminal, with Claude doing the heavy lifting.
This is an Agent Skill that turns Claude/Codex/... into a
hands-on CrowdSec operator. Ask it to stand up an engine, wire a bouncer, enable
the WAF, or figure out why nothing's getting blocked — it knows the cscli
commands, the config layout, the failure modes, and the safe way through each of
them across bare-metal/systemd, Docker, OpnSense and Kubernetes/Helm.
| Area | Covered |
|---|---|
| Install | bare-metal/systemd · Docker · Kubernetes/Helm · OpnSense · Console enrollment |
| Bouncers | firewall (iptables/nftables/ipset) · nginx · traefik · caddy · apache · and more |
| WAF / AppSec | deploy · configure · troubleshoot the AppSec component |
| Hub | install collections/parsers/scenarios · update · debug |
| Configure | acquisition · profiles & ban durations · notifications · allowlists |
| Operate | health checks & smoke tests · upgrades & rollback · multi-server / remote LAPI / mTLS |
| Debug | logs not parsing · no alerts firing · bouncer not blocking · specific errors |
The skill loads automatically once installed. Just talk to Claude about CrowdSec.
On Claude
/plugin marketplace add crowdsecurity/crowdsec-skill
/plugin install crowdsec@crowdsecurity
Update later with:
/plugin marketplace update crowdsecurity
On Codex: install the skill with:
skill-installer crowdsecurity/crowdsec-skill
On Claude.ai (web)
Download crowdsec-skill-vX.Y.Z.zip from the
latest release
and upload it in the web skill uploader.
Or directly with skills.sh
npx skills add crowdsecurity/crowdsec-skill
Once installed, Claude picks the skill up whenever your prompt involves CrowdSec:
This is an operational skill. It deploys, configures, and debugs CrowdSec — it does not author detection content. Writing a parser, scenario, or WAF (AppSec) rule is out of scope.
For authoring, head to the CrowdSec Hub and the detection-engineering docs.
Issues and PRs welcome. Improvements to the reference docs and new environment coverage are appreciated. If you see anything missing or wrong, don't hesitate to open a PR.
MIT — see LICENSE.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
claude plugin install crowdsec@claude-plugins-officialEditorial "Security Engineer" bundle for Claude Code from Agentic Awesome Skills.
Sysdig's cloud security expertise, packaged as agent skills that work natively in your AI environment.
Create, validate, import, execute, and export CrowdStrike Falcon Fusion SOAR workflows using natural language.
Find security misconfigurations
Server security auditing, hardening, and fleet management. Runtime-derived audit catalog, CIS/PCI-DSS/HIPAA compliance, production hardening workflows, and first-party MCP tools. Supports Hetzner, DigitalOcean, Vultr, Linode with Coolify, Dokploy, and bare VPS modes.
Cybersecurity skills for AI agents — code audit, cloud, recon, IR, AI security, and more