agentsclimarketplace

Linux patterns

Skill Mattakushi432/Claude-Code-Skills-Custom-DevTools-Pack/plugins/devtools-pack/skills/linux-patterns

When to activate: Linux, systemd, cron, shell, process management, networking, performance tuning, security hardening, ufw, fail2banFrom its SKILL.md

Install
npx -y skills add Mattakushi432/Claude-Code-Skills-Custom-DevTools-Pack --skill linux-patterns

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

3.5 KB, 944 tokens by cl100k_base, as published. Nobody here has run it

Linux Patterns

systemd Service Unit

[Unit]
Description=MyApp Service
After=network.target postgresql.service
Requires=postgresql.service

[Service]
Type=simple
User=myapp
Group=myapp
WorkingDirectory=/opt/myapp
ExecStart=/opt/myapp/bin/myapp --config /etc/myapp/config.yaml
ExecReload=/bin/kill -HUP $MAINPID
Restart=on-failure
RestartSec=5s
StandardOutput=journal
StandardError=journal
SyslogIdentifier=myapp
Environment=LOG_LEVEL=info
EnvironmentFile=-/etc/myapp/env

# Security hardening
NoNewPrivileges=yes
PrivateTmp=yes
ProtectSystem=full
ReadOnlyPaths=/

[Install]
WantedBy=multi-user.target
systemctl daemon-reload
systemctl enable --now myapp
journalctl -u myapp -f --since "10 min ago"

cron (with flock to prevent overlap)

# /etc/cron.d/myapp
# Run report every hour, skip if previous run still active
0 * * * * myapp /usr/bin/flock -n /tmp/myapp-report.lock /opt/myapp/bin/report.sh >> /var/log/myapp/report.log 2>&1

Performance Diagnostics

# CPU — who's using it
top -b -n 1 -o %CPU | head -20
pidstat -u 1 5              # per-process CPU usage over 5s

# Memory
free -h
vmstat 1 5                  # memory, swap, I/O
cat /proc/meminfo | grep -E "MemAvailable|Cached|Buffers"

# Disk I/O
iostat -xz 1 5              # per-device utilization
iotop -o                    # which process is doing I/O

# Network
ss -tunapl                  # all TCP/UDP with process info
netstat -s | grep -E "failed|error|reset"
sar -n DEV 1 5              # per-interface throughput

# Load average context
uptime                      # 1/5/15 min load averages
nproc                       # number of CPU cores (load > nproc = overloaded)

File Descriptor and Connection Limits

# Check current limits
ulimit -n
cat /proc/sys/fs/file-max

# Increase for a process (in systemd unit)
[Service]
LimitNOFILE=65536

# System-wide (sysctl)
sysctl -w fs.file-max=2097152
echo "fs.file-max = 2097152" >> /etc/sysctl.d/99-myapp.conf
sysctl -p /etc/sysctl.d/99-myapp.conf

Security Hardening

# UFW firewall
ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp comment 'SSH'
ufw allow 443/tcp comment 'HTTPS'
ufw enable

# fail2ban for SSH
apt install fail2ban
cat > /etc/fail2ban/jail.local << 'EOF'
[sshd]
enabled = true
port = 22
maxretry = 5
bantime = 3600
findtime = 600
EOF
systemctl enable --now fail2ban

# Disable root SSH login
sed -i 's/^PermitRootLogin yes/PermitRootLogin no/' /etc/ssh/sshd_config
sed -i 's/^#PasswordAuthentication yes/PasswordAuthentication no/' /etc/ssh/sshd_config
systemctl reload sshd

Log Rotation

# /etc/logrotate.d/myapp
/var/log/myapp/*.log {
    daily
    rotate 14
    compress
    delaycompress
    missingok
    notifempty
    postrotate
        systemctl kill -s HUP myapp.service
    endscript
}

Key Rules

  • Use journalctl for systemd services — not raw log files
  • ss replaces netstat on modern Linux (faster, same syntax)
  • Always set resource limits in unit files: LimitNOFILE, MemoryMax
  • nohup and screen/tmux for long-running manual tasks; prefer systemd for daemons
  • Run logwatch or lynis weekly for security audit baseline

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 326,851. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.