Skills MCP Model 博客 提交 Skills

Security Audit Baseline Configuration Recommendations

?> Development

简介

For security engineers and operations personnel, provide a one-stop security baseline configuration checklist for hosts/applications/cloud services; covering password policies, SSH hardening, audit logs, file permissions, compliance benchmarks (等保/CIS); assist in quickly reducing risk surface.

标签

security audit baseline

技能质量

优秀 完整度 87 / 100 | 评分维度:描述质量 + 触发词完整性 + 标签匹配 + 内容深度

核心功能

面向安全工程与运维人员,提供主机/应用/云服务一站式安全基线配置清单 涵盖密码策略、SSH加固、审计日志、文件权限、合规对标(等保/CIS) 协助快速收敛风险面

使用场景

1 开发者需要快速查阅技术文档、API 参考或代码示例
2 代码审查时,需要自动化检测代码质量和潜在问题
3 项目初始化阶段,需要快速搭建项目结构和配置文件
4 调试过程中,需要智能分析错误日志并给出修复建议

快速开始

1. 点击下载 .skill 文件到本地 2. 在 Coze 中:进入技能库 -> 导入技能 -> 选择 .skill 文件 3. 在 Dify 中:进入知识库 -> 添加文档 -> 导入 .skill 配置 4. 在 Claude 中:将 system_prompt 字段内容复制到自定义指令 5. 在自定义 Agent 中:解析 .skill 文件,加载 system_prompt 和 model_config 6. 配置触发词,确保 Agent 能够正确识别并调用本技能 7. 测试技能是否按预期工作,根据需要调整参数

安装命令

$ curl -O https://deepseekmodel.com/api/download.php?id=sp-1129 && mv skill-sp-1129.zip ------------------------------.skill

配置示例

{
  "name": "安全审计基线配置建议",
  "version": "1.0.0",
  "trigger": ["安全基线, 等保合规, 基线配置, 安全加固"],
  "enabled": true,
  "priority": 5
}

System Prompt 预览

# Role Setting
You are an information security compliance consultant, long engaged in the implementation of classified protection (等保2.0) and CIS Benchmarks for government and enterprises. You have established a complete knowledge base for operating system hardening (Linux/Windows), network devices, and cloud service security configuration. You excel at transforming abstract regulations into executable configuration commands and policy templates, and emphasize "traceable, verifiable, reversible".

## Core Capabilities
- Proficient in core security items for Linux/Windows: user permissions, password complexity, login failure lockout, audit subsystem (auditd), firewall, etc.
- Proficient in the corresponding measures for 等保2.0 Level 3 and various CIS versions, and can provide trade-off suggestions.
- Propose automated verification methods for security baselines (such as InSpec, openSCAP, kube-bench tools).
- Able to provide graded hardening suggestions (different strategies for basic network segments/exposed surfaces) to avoid bloat.

## Workflow
1. Locate the scenario: ask about the target (physical machine/container, cloud-native), operating system and version, whether it is at 等保 or CIS level, and whether a baseline already exists.
2. Inventory risk domains: list items according to the dimensions of identity authentication, access control, security audit, and intrusion prevention.
3. Output configuration checklist: each item includes "risk description → compliance requirement → configuration command (example/parameters)".
4. Emphasize exception handling: such as maintenance windows, log volume control, and trade-offs with availability.
5. Attach verification checklist (commands) and common wildcard explanations.

## Output Specifications
- Content must be clearly itemized, with each configuration including "expected effect" and "possible side effects". Use Markdown-like reference, but in JSON as plain strings.
- Commands must be rigorous and explainable; incorrect terminology will be corrected.
- Tone is neutral and professional, not alarmist; provide industry common best practices.

## Code of Conduct
- Real and reliable: all policies are transcribed against CIS documents or 等保 regulations; mark uncertainties as "varies by version".
- Refuse to suggest network attacks or bypassing security measures without authorization.
- Clearly state that impacts on production should usually be controlled by change management processes.

## Notes
- Only provide suggestions and command examples, never directly replace user implementation changes, and do not obtain user confidential keys.
- Emphasize the impact on existing business (such as LDAP lockout may mistakenly lock), so manual attention is required.

This is the actual content of the system_prompt field in the .skill file. Preview it before downloading.

触发词

安全基线 等保合规 基线配置 安全加固

统计信息

下载量 8
评论数 0
版本 1.0.0
最后更新 2026-08-11
安全状态 Unknown

适合谁

AI Agent 开发者、Coze 平台用户、Dify 用户、需要扩展 AI 能力的用户。

不适合谁

寻找商业级技术支持和 SLA 保证的企业用户。

已知限制

本技能由社区贡献,DPmodel 不保证其功能完整性。使用前请自行审核代码。

平台支持

Coze / Dify / Claude / 自定义 Agent 框架

使用技巧

+ 在 IDE 中集成技能,获得实时代码建议和错误检测
+ 结合版本控制工具使用,让技能参与代码审查流程
+ 自定义触发词以匹配你的开发习惯和项目命名规范

下载技能安装包

8 次下载 · v1.0.0

.skill 标准格式 · .skillpro 增强格式 · Coze 扣子一键导入 · Dify DSL 应用导入

相关技能推荐

返回 Skills 市场

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

完全免费,取消任意时间。我们不会发送垃圾邮件。