| id |
security-audit |
| name |
Defensive security audit |
| when_to_use |
Auditing or hardening a Linux host, Docker/container stack, or network — blue-team review against a baseline. |
| agents |
|
| skills |
hardening-linux-endpoint-with-cis-benchmark |
analyzing-linux-audit-logs-for-intrusion |
detecting-rootkit-activity |
hardening-docker-containers-for-production |
performing-docker-bench-security-assessment |
detecting-container-escape-attempts |
analyzing-network-packets-with-scapy |
configuring-suricata-for-network-monitoring |
building-detection-rules-with-sigma |
performing-nist-csf-maturity-assessment |
implementing-secret-scanning-with-gitleaks |
|
| phases |
| phase |
owner_agent |
skills |
exit_criteria |
failure_modes |
Scope & baseline |
security-auditor |
performing-nist-csf-maturity-assessment |
|
Assets, threat model, and the baseline to audit against are stated. |
Auditing everything at once with no priority. |
|
| phase |
owner_agent |
skills |
exit_criteria |
failure_modes |
Host hardening |
security-auditor |
hardening-linux-endpoint-with-cis-benchmark |
analyzing-linux-audit-logs-for-intrusion |
detecting-rootkit-activity |
|
Host findings ranked by severity with exact remediation commands. |
Applying changes before confirming they are safe on a live machine. |
|
| phase |
owner_agent |
skills |
exit_criteria |
failure_modes |
Container review |
security-auditor |
hardening-docker-containers-for-production |
performing-docker-bench-security-assessment |
detecting-container-escape-attempts |
|
Docker daemon + image + runtime posture assessed (Docker Bench, escape checks). |
Ignoring 0.0.0.0-bound published ports and UFW rule state. |
|
| phase |
owner_agent |
skills |
exit_criteria |
failure_modes |
Network & detection |
security-auditor |
analyzing-network-packets-with-scapy |
configuring-suricata-for-network-monitoring |
building-detection-rules-with-sigma |
|
Traffic/monitoring gaps identified; detection rules proposed. |
Detection without a hypothesis of what you are hunting. |
|
| phase |
owner_agent |
skills |
exit_criteria |
failure_modes |
Supply chain & report |
security-auditor |
implementing-secret-scanning-with-gitleaks |
|
Secret/SBOM findings folded into one prioritized, read-only report. |
Reporting a low score from a tool run without sudo (false negative). |
|
|
Read-only-first posture review: Scope → Host → Container → Network → Supply-chain report. Owned by
the security-auditor agent, drawing on the installed defensive-security skills (and the far larger
cybersecurity set in the library for specialized techniques — forensics, YARA/Zeek, IR playbooks).
Route in: "audit / harden / is this secure / check open ports / container security." Diagnose and
report exact commands; confirm before any system-mutating change on a live host.