Skip to content

Latest commit

 

History

71 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CrowdSec

CrowdSec skills

Install, configure, operate, and debug CrowdSec — straight from your terminal, with your coding agent doing the heavy lifting.

Version License: MIT Agent Skills CrowdSec


This plugin bundles two Agent Skills:

  • crowdsec — a hands-on CrowdSec operator. Stand up an engine, wire a bouncer, enable the WAF, or figure out why nothing's getting blocked. It knows the cscli commands, the config layout, the failure modes, and the safe way through each across bare-metal/systemd, Docker, OpnSense and Kubernetes/Helm.
  • crowdsec-service-api — drives the premium Console Service API (cloud) on your behalf with your API key: create and populate blocklists/allowlists, wire firewall/appliance integrations, pull remediation ROI metrics, and manage org-level decisions — every state change gated behind an explicit confirmation.

What it covers

crowdsec (operational):

Area Covered
Install bare-metal/systemd · Docker · Kubernetes/Helm · OpnSense · Console enrollment
Bouncers firewall (iptables/nftables/ipset) · nginx · traefik · caddy · apache · and more
WAF / AppSec deploy · configure · troubleshoot the AppSec component
Hub install collections/parsers/scenarios · update · debug
Configure acquisition · profiles & ban durations · notifications · allowlists
Operate health checks & smoke tests · upgrades & rollback · multi-server / remote LAPI / mTLS
Debug logs not parsing · no alerts firing · bouncer not blocking · specific errors

crowdsec-service-api (premium cloud API):

Area Covered
Blocklists create · add/remove/bulk IPs (with expiry) · download · share across orgs · subscribe engines/bouncers
Allowlists create · items with expiry · subscribe by engine/tag/org
Integrations firewall/appliance feeds (Palo Alto, Fortinet, Cisco, F5, Sophos, pfSense/OPNsense…) · paginated Basic-auth content pull
Metrics remediation ROI (traffic dropped, bytes/egress saved, attacks prevented)
Decisions org-level decisions + aggregated (read/manage)

🚀 Install

The skill loads automatically once installed. Just talk to your agent about CrowdSec.

On Claude Code

/plugin marketplace add crowdsecurity/crowdsec-skill
/plugin install crowdsec@crowdsecurity

Update later with:

/plugin marketplace update crowdsecurity

On Codex: install the skill with:

skill-installer crowdsecurity/crowdsec-skill

On Claude.ai (web)

Download crowdsec-skill-vX.Y.Z.zip from the latest release and upload it in the web skill uploader.

Or directly with skills.sh

npx skills add  crowdsecurity/crowdsec-skill

💬 Example prompts

Once installed, the agent picks the skill up whenever your prompt involves CrowdSec:

  • "Install CrowdSec on this server and set up the nginx bouncer."
  • "Deploy CrowdSec in my Kubernetes cluster and enroll it in the Console."
  • "Enable the WAF / AppSec on my server."
  • "CrowdSec doesn't detect attacks on my nginx server, why?"
  • "There's a decision for this IP but it's not being blocked."
  • "Migrate my fail2ban jails to CrowdSec."
  • "Create a Console blocklist and push these IPs from my SIEM to it." (Service API)
  • "Wire a Palo Alto external dynamic list to my CrowdSec blocklist." (Service API)
  • "Show me the remediation ROI metrics for last month." (Service API)

What it does not do

This is an operational skill. It deploys, configures, and debugs CrowdSec — it does not author detection content. Writing a parser, scenario, or WAF (AppSec) rule is out of scope.

For authoring, head to the CrowdSec Hub and the detection-engineering docs.

🤝 Contributing

Issues and PRs welcome. Improvements to the reference docs and new environment coverage are appreciated. If you see anything missing or wrong, don't hesitate to open a PR.

🔗 Links

📄 License

MIT — see LICENSE.

About

CrowdSec Skill : Install, configure, debug and operate crowdsec

Resources

Stars

23 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages