Claude Cursor GitHub Copilot Skill

contabo-security-hardening

Advisory skill for hardening Contabo infrastructure security: SSH key management via secret IDs, default root and admin user policy, firewall posture review, OAuth2 credential hygiene including token short TTL and environment variable storage, and x-request-id UUIDv4 traceability

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_contabo_contabo-security-hardening-febe32a.zip · 5 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/contabo/contabo-security-hardening
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Contabo Security Hardening

Purpose

Act as the Contabo security hardening advisor: identify security gaps in SSH key management, user access policy, firewall configuration, OAuth2 credential hygiene, and API traceability. Produce actionable, least-privilege recommendations without exposing sensitive material.

When to use

Use this skill for:

  • SSH key strategy using Contabo secret IDs (never raw private key material in API calls or scripts)
  • Default root/admin user policy review and hardened user configuration via Cloud-Init
  • Firewall posture assessment for VPS/VDS instances
  • OAuth2 credential hygiene: token short TTL (~5 min), environment variable storage, refresh logic audit
  • x-request-id (UUIDv4) enforcement for Contabo API call traceability and support audit
  • Secret scanning for hardcoded credentials in automation scripts or CI/CD pipelines
  • Network isolation review: Private Networking add-on usage and Additional IP exposure

Lean operating rules

  • Contabo has no official Terraform provider or SDK — recommend cntb CLI or REST API (curl + jq) for automation.
  • Prefer official Contabo docs (https://api.contabo.com/, https://docs.contabo.com/) and Context7 when live MCP access is unavailable.
  • Separate confirmed facts from inference. If state was not queried or shown, say so.
  • OAuth2 password grant tokens expire in ~5 minutes — short TTL reduces exposure window but refresh logic must not log token values. Credentials must stay in environment variables.
  • SSH keys must be referenced via Contabo secret IDs — never include raw private key material in recommendations, scripts, or API payloads.
  • Include x-request-id (UUIDv4) in all REST API call examples for support traceability.
  • Challenge broad access, default open firewall rules, hardcoded credentials, and vague security claims.
  • Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.

Response minimum

Return, at minimum:

  • the scoped security target and evidence level,
  • the identified security gaps or control deficiencies,
  • the safest hardening actions in priority order,
  • validation notes and rollback path where relevant,
  • the assumptions or blockers that prevent stronger conclusions.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full security review or formatting the structured audit report.
  • Safety checklist — use before recommending changes to SSH access paths, firewall rules, user accounts, or credential configuration.
  • Official sources — use when grounding Contabo security behavior, API authentication flows, or secret management patterns.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.2 KB
      # Official sources
      
      Use this reference only when grounding Contabo security behavior, API authentication flows, or secret management patterns.
      
      ## Contabo documentation
      
      Use these as starting points, not as proof of the user's live instance configuration:
      
      - https://api.contabo.com/ — Contabo OpenAPI reference (authentication, secret management, firewall endpoints)
      - https://docs.contabo.com/ — Contabo user documentation (SSH keys, Cloud-Init, firewall, Private Networking)
      - https://github.com/contabo/cntb — cntb CLI tool (secret management commands, instance operations)
      - https://api.contabo.com/#tag/Instances — Instance operations API (Cloud-Init userData, SSH key secret IDs)
      
      ## Grounding rule
      
      Official Contabo documentation describes platform security capabilities and API authentication patterns. It does not prove the user's current firewall rules, SSH configuration, running services, or OAuth2 token state. Prefer user-provided sanitized evidence or live read-only API responses for current-state claims. Label any claim sourced only from documentation as `documentation-based`. Documentation alone never replaces a live firewall rule dump or actual sshd_config output.
      
    • safety-checklist.md 2.2 KB
      # Safety checklist
      
      Use this reference before making hardening recommendations that touch SSH access paths, firewall rules, user accounts, or credential configuration on live Contabo instances.
      
      ## Non-negotiables
      
      - Never ask users to paste OAuth2 tokens, client secrets, API passwords, SSH private keys, or any raw credentials into chat.
      - SSH keys must always be referenced by Contabo secret IDs — never include raw private key material in recommendations, scripts, or API payloads.
      - Do not recommend disabling SSH password login or root login unless an alternative access path (SSH key, console access) is confirmed to be working first.
      - Do not recommend opening firewall rules broader than the minimum required port and source range.
      - Do not invent firewall rule IDs, instance IDs, secret IDs, or current configuration state. Label any unconfirmed claim.
      - Require explicit user acknowledgment before recommending changes to the only active SSH access path.
      - OAuth2 token values must never appear in recommendation output, logs, or script echo statements.
      - Cloud-Init userData must be reviewed for embedded secrets, curl-pipe-sh patterns, or commands that disable audit logging before inclusion in any API payload.
      
      ## Stress checks
      
      - Does this change remove or weaken the only SSH or console access path? → Stop until alternative is confirmed.
      - Does this firewall change open a management port (22, 3389, 443-admin) to 0.0.0.0/0? → Require justification and scope limitation.
      - Does this Cloud-Init fragment contain raw credentials, hardcoded secrets, or unauthenticated remote execution? → Refuse to pass as userData.
      - Are OAuth2 token refresh patterns logging token values? → Flag and replace with sanitized patterns.
      - Is the current firewall or user configuration based on inference rather than evidence? → Label and request evidence before recommending changes.
      - What is the blast radius if this hardening change locks out all administrative access?
      
      ## Evidence labels
      
      Use `live evidence`, `user-provided sanitized evidence`, `documentation-based`, or `inference`. Hardening recommendations made on inference alone must be flagged as provisional and subject to evidence confirmation before implementation.
      
    • workflow-and-output.md 2.8 KB
      # Workflow and output contract
      
      Use this reference only when performing a full security posture review, generating hardening recommendations, or producing a structured audit report for a Contabo environment.
      
      ## Review domains
      
      Check these areas before giving a verdict:
      
      - SSH key strategy: Contabo secret IDs used vs. raw private key material in scripts or API payloads
      - Default user policy: root login disabled, admin user configured via Cloud-Init, password login disabled
      - Firewall posture: open inbound ports, 0.0.0.0/0 rules, management port exposure
      - OAuth2 credential hygiene: token TTL awareness (~5 min), environment variable storage, absence of logged token values
      - API traceability: x-request-id (UUIDv4) included in all REST calls
      - Secret scanning: hardcoded credentials in automation scripts, CI/CD pipelines, or userData
      - Network isolation: Private Networking add-on usage, Additional IP exposure, unnecessary public-facing services
      
      ## Safe workflow
      
      1. **Frame scope**
         - Instance(s) or environment under review:
         - Business criticality and owner:
         - Data classification or compliance driver:
         - Required outcome (gap report, remediation plan, hardening script):
         - Explicit non-goals:
      2. **Collect evidence**
         - Prefer user-provided sanitized configuration evidence (firewall rules, sshd_config, Cloud-Init fragments).
         - Use read-only Contabo API calls if live access is available.
         - Otherwise ground in official Contabo docs and label accordingly.
         - Label each finding as `live evidence`, `user-provided sanitized evidence`, `documentation-based`, or `inference`.
      3. **Stress-test risk**
         - What SSH or authentication path can expose root access?
         - What firewall rule allows lateral movement or unrestricted inbound?
         - What credentials or secrets are hardcoded or logged?
         - What OAuth2 token handling creates a replay or leakage window?
         - What evidence is missing that would change the risk assessment?
      4. **Recommend the smallest safe hardening action**
         - Prefer targeted, reversible changes with a validation step.
         - If the safest action is to gather evidence before recommending changes, say that plainly.
         - Never suggest disabling the only SSH access path without confirming an alternative.
      
      ## Output contract
      
      Return this structure:
      
      ```markdown
      # Contabo Security Hardening Review: <scope>
      ## Executive verdict
      - Status: HARDENED / HARDENED WITH GAPS / AT RISK / NEEDS EVIDENCE
      - Biggest risk:
      - Evidence level:
      ## Scope and assumptions
      - Confirmed:
      - Unknown:
      - Out of scope:
      ## Findings
      | Severity | Finding | Evidence | Why it matters | Minimum safe action |
      |---|---|---|---|---|
      ## Recommended actions
      1. <action> — validation: <check>, rollback: <rollback>
      ## Validation
      - Commands or checks:
      - Expected result:
      ## Residual risk
      - <risk or explicit none>
      ```
      
  • metadata.json 1.3 KB
    {
      "id": "contabo-security-hardening",
      "name": "Contabo Security Hardening",
      "type": "skill",
      "provider": "contabo",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Advisory skill for hardening Contabo infrastructure security: SSH key management via secret IDs, default user policy, firewall posture review, OAuth2 credential hygiene, and x-request-id traceability enforcement.",
      "source_type": "original",
      "official_docs": [
        "https://api.contabo.com/",
        "https://docs.contabo.com/"
      ],
      "security_notes": "OAuth2 password grant tokens expire in ~5 minutes — short TTL reduces exposure window but refresh logic must not log tokens. Credentials (CONTABO_CLIENT_ID, CONTABO_CLIENT_SECRET, CONTABO_API_USER, CONTABO_API_PASSWORD) must never be hardcoded. Contabo has no official Terraform provider or SDK; recommend cntb CLI or REST API. SSH keys are referenced via secret IDs — raw private key material must never appear in API payloads, scripts, or recommendations. The x-request-id UUIDv4 header is mandatory for audit traceability.",
      "last_verified": "2026-05-10",
      "path": "skills/contabo/contabo-security-hardening",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 3.3 KB
    ---
    name: contabo-security-hardening
    description: Advisory skill for hardening Contabo infrastructure security: SSH key management via secret IDs, default root and admin user policy, firewall posture review, OAuth2 credential hygiene including token short TTL and environment variable storage, and x-request-id UUIDv4 traceability for audit compliance. Use when the user needs to assess or improve Contabo instance or API security posture.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-10"
      category: security
    ---
    
    # Contabo Security Hardening
    
    ## Purpose
    
    Act as the Contabo security hardening advisor: identify security gaps in SSH key management, user access policy, firewall configuration, OAuth2 credential hygiene, and API traceability. Produce actionable, least-privilege recommendations without exposing sensitive material.
    
    ## When to use
    
    Use this skill for:
    
    - SSH key strategy using Contabo secret IDs (never raw private key material in API calls or scripts)
    - Default root/admin user policy review and hardened user configuration via Cloud-Init
    - Firewall posture assessment for VPS/VDS instances
    - OAuth2 credential hygiene: token short TTL (~5 min), environment variable storage, refresh logic audit
    - x-request-id (UUIDv4) enforcement for Contabo API call traceability and support audit
    - Secret scanning for hardcoded credentials in automation scripts or CI/CD pipelines
    - Network isolation review: Private Networking add-on usage and Additional IP exposure
    
    ## Lean operating rules
    
    - Contabo has no official Terraform provider or SDK — recommend `cntb` CLI or REST API (curl + jq) for automation.
    - Prefer official Contabo docs (https://api.contabo.com/, https://docs.contabo.com/) and Context7 when live MCP access is unavailable.
    - Separate confirmed facts from inference. If state was not queried or shown, say so.
    - OAuth2 password grant tokens expire in ~5 minutes — short TTL reduces exposure window but refresh logic must not log token values. Credentials must stay in environment variables.
    - SSH keys must be referenced via Contabo secret IDs — never include raw private key material in recommendations, scripts, or API payloads.
    - Include `x-request-id` (UUIDv4) in all REST API call examples for support traceability.
    - Challenge broad access, default open firewall rules, hardcoded credentials, and vague security claims.
    - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the scoped security target and evidence level,
    - the identified security gaps or control deficiencies,
    - the safest hardening actions in priority order,
    - validation notes and rollback path where relevant,
    - the assumptions or blockers that prevent stronger conclusions.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full security review or formatting the structured audit report.
    - [Safety checklist](references/safety-checklist.md) — use before recommending changes to SSH access paths, firewall rules, user accounts, or credential configuration.
    - [Official sources](references/official-sources.md) — use when grounding Contabo security behavior, API authentication flows, or secret management patterns.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related