{
  "markdown": "<div align=\"center\">\n\n<img src=\"https://raw.githubusercontent.com/crowdsecurity/crowdsec-docs/main/crowdsec-docs/static/img/crowdsec_logo.png\" alt=\"CrowdSec\" width=\"280\">\n\n# CrowdSec skills\n\n**Install, configure, operate, and debug [CrowdSec](https://doc.crowdsec.net) — straight from your terminal, with your coding agent doing the heavy lifting.**\n\n[![Version](https://img.shields.io/badge/version-0.2.3-blue)](.claude-plugin/plugin.json)\n[![License: MIT](https://img.shields.io/badge/license-MIT-green)](LICENSE)\n[![Agent Skills](https://img.shields.io/badge/Agent-Skills-8A2BE2)](https://docs.claude.com/en/docs/claude-code/skills)\n[![CrowdSec](https://img.shields.io/badge/CrowdSec-docs-orange)](https://docs.crowdsec.net)\n\n</div>\n\n---\n\nThis plugin bundles **two [Agent Skills](https://docs.claude.com/en/docs/claude-code/skills)**:\n\n- **`crowdsec`** — a hands-on CrowdSec operator. Stand up an engine, wire a\n  bouncer, enable the WAF, or figure out why nothing's getting blocked. It knows\n  the `cscli` commands, the config layout, the failure modes, and the safe way\n  through each across **bare-metal/systemd, Docker, OpnSense and Kubernetes/Helm**.\n- **`crowdsec-service-api`** — drives the premium **Console Service API** (cloud)\n  on your behalf with your API key: create and populate blocklists/allowlists,\n  wire firewall/appliance integrations, pull remediation ROI metrics, and manage\n  org-level decisions — every state change gated behind an explicit confirmation.\n\n\n## What it covers\n\n**`crowdsec` (operational):**\n\n| Area | Covered |\n|---|---|\n| **Install** | bare-metal/systemd · Docker · Kubernetes/Helm · OpnSense · Console enrollment |\n| **Bouncers** | firewall (iptables/nftables/ipset) · nginx · traefik · caddy · apache · and more |\n| **WAF / AppSec** | deploy · configure · troubleshoot the AppSec component |\n| **Hub** | install collections/parsers/scenarios · update · debug |\n| **Configure** | acquisition · profiles & ban durations · notifications · allowlists |\n| **Operate** | health checks & smoke tests · upgrades & rollback · multi-server / remote LAPI / mTLS |\n| **Debug** | logs not parsing · no alerts firing · bouncer not blocking · specific errors |\n\n**`crowdsec-service-api` (premium cloud API):**\n\n| Area | Covered |\n|---|---|\n| **Blocklists** | create · add/remove/bulk IPs (with expiry) · download · share across orgs · subscribe engines/bouncers |\n| **Allowlists** | create · items with expiry · subscribe by engine/tag/org |\n| **Integrations** | firewall/appliance feeds (Palo Alto, Fortinet, Cisco, F5, Sophos, pfSense/OPNsense…) · paginated Basic-auth content pull |\n| **Metrics** | remediation ROI (traffic dropped, bytes/egress saved, attacks prevented) |\n| **Decisions** | org-level decisions + aggregated (read/manage) |\n\n## 🚀 Install\n\nThe skill loads automatically once installed. Just talk to\nyour agent about CrowdSec.\n\n**On Claude Code**\n\n```text\n/plugin marketplace add crowdsecurity/crowdsec-skill\n/plugin install crowdsec@crowdsecurity\n```\n\nUpdate later with:\n\n```text\n/plugin marketplace update crowdsecurity\n```\n\n**On Codex:** install the skill with:\n\n```text\nskill-installer crowdsecurity/crowdsec-skill\n```\n\n**On Claude.ai (web)**\n\nDownload `crowdsec-skill-vX.Y.Z.zip` from the\n[latest release](https://github.com/crowdsecurity/crowdsec-skill/releases/latest)\nand upload it in the web skill uploader.\n\n**Or directly with skills.sh**\n\n```bash\nnpx skills add  crowdsecurity/crowdsec-skill\n```\n\n## 💬 Example prompts\n\nOnce installed, the agent picks the skill up whenever your prompt involves CrowdSec:\n\n- _\"Install CrowdSec on this server and set up the nginx bouncer.\"_\n- _\"Deploy CrowdSec in my Kubernetes cluster and enroll it in the Console.\"_\n- _\"Enable the WAF / AppSec on my server.\"_\n- _\"CrowdSec doesn't detect attacks on my nginx server, why?\"_\n- _\"There's a decision for this IP but it's not being blocked.\"_\n- _\"Migrate my fail2ban jails to CrowdSec.\"_\n- _\"Create a Console blocklist and push these IPs from my SIEM to it.\"_ (Service API)\n- _\"Wire a Palo Alto external dynamic list to my CrowdSec blocklist.\"_ (Service API)\n- _\"Show me the remediation ROI metrics for last month.\"_ (Service API)\n\n## What it does **not** do\n\nThis is an **operational** skill. It deploys, configures, and debugs CrowdSec —\nit does **not author** detection content. Writing a parser, scenario, or WAF\n(AppSec) rule is out of scope.\n\nFor authoring, head to the [CrowdSec Hub](https://hub.crowdsec.net) and the\n[detection-engineering docs](https://docs.crowdsec.net/docs/next/local_api/intro).\n\n## 🤝 Contributing\n\nIssues and PRs welcome. Improvements to the reference docs and new environment\ncoverage are appreciated. If you see anything missing or wrong, don't hesitate to open a PR.\n\n## 🔗 Links\n\n- CrowdSec: <https://www.crowdsec.net>\n- Documentation: <https://docs.crowdsec.net>\n- Hub: <https://hub.crowdsec.net>\n- Console: <https://app.crowdsec.net>\n\n## 📄 License\n\nMIT — see [LICENSE](LICENSE).\n",
  "bytes": 4958,
  "sha": "9aca0fd674bda3d439284ed1aacc6d2fa0183e1288ed96a7777705210f1981b3",
  "repo_slug": "crowdsecurity/crowdsec-skill",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/plg_crowdsecurity_crowdsec_skill_crowdsec_c82a2ef9/readme"
}