host-security-audit

Audit and harden Linux host security across firmware and boot components.

Updated Jul 3, 2026
One-click install
npx skills add https://github.com/Toqsick/MaxClaw --skill host-security-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: host-security-audit
Source: https://github.com/Toqsick/MaxClaw/tree/main/.claude/skills/host-security-audit
Command: npx skills add https://github.com/Toqsick/MaxClaw --skill host-security-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires fwupd, mokutil, systemd, grub, gnome-session-binary, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a comprehensive security audit and hardening for Linux laptops and workstations, addressing both hardware and firmware vulnerabilities.

Core Features & Use Cases

  • Comprehensive Audit: Identifies security risks at fwupd HSI levels, TPM/BootGuard, secure boot, kernel lockdown, and power management.
  • Automated Fixing: Applies necessary configurations and fixes for secure boot, kernel parameters, and BIOS settings.
  • Detailed Reporting: Generates detailed audit reports and tracks findings, fixes, and limitations.
  • Use Case: When a user needs a thorough security assessment and hardening of their Linux system, particularly in response to security reports or firmware update notifications.

Quick Start

Perform a security audit on your Linux system using the 'host-security-audit' skill.

Frequently Asked Questions about host-security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a Linux host security audit using fwupd HSI levels?

A Linux host security audit evaluates fwupd HSI levels, TPM/BootGuard, secure boot, kernel lockdown, and power management to identify vulnerabilities. This skill automates the assessment, applies necessary configurations, and generates detailed reports tracking findings and fixes.

What is kernel lockdown and how does it affect secure boot on Linux?

Kernel lockdown is a security mode restricting kernel features to prevent unauthorized modifications when secure boot is active. This skill audits your kernel parameters and boot configuration, applying necessary fixes to ensure your boot process maintains a hardened security baseline.

Do I need fwupd and mokutil installed to audit TPM and BootGuard settings?

Yes, fwupd and mokutil are required dependencies to audit TPM and BootGuard settings. The skill also relies on systemd, grub, and gnome-session-binary to perform the comprehensive security assessment and apply automated hardening configurations.

How can I harden my Linux laptop's firmware and secure boot configuration?

You can harden your Linux laptop's firmware by auditing fwupd HSI levels and secure boot settings. This skill identifies hardware and firmware vulnerabilities, applies automated fixes for boot parameters, and tracks limitations to strengthen your security baseline.

What are the limitations of automating BIOS settings and secure boot fixes on Linux?

Automating secure boot fixes and BIOS settings faces limitations because certain configurations require manual BIOS intervention. This skill details these constraints in its reporting, tracking findings, applied fixes, and specific limitations regarding firmware and power management.

Can I use this security audit skill on a Linux workstation with systemd and grub?

Yes, this security audit skill is designed for Linux laptops and workstations running systemd and grub. It checks your fwupd HSI levels, TPM/BootGuard, and kernel lockdown status to apply necessary hardening configurations for your specific environment.