# CrowdSec — Open-Source Collaborative IPS/IDPS/WAF Deploy, configure, and manage CrowdSec — the open-source security engine that detects and blocks malicious actors using behavior-based patterns and community blocklists. ## Why Install This Skill When your agent loads this skill, it becomes a **CrowdSec security engineer** who can: - **Install and configure** — Security Engine on Linux or Docker, remediation components - **Manage with cscli** — hub collections, parsers, scenarios, and bouncers - **Set up the AppSec WAF** — HTTP request inspection for web applications - **Configure profiles and notifications** — tailored response and alerting - **Monitor and troubleshoot** — metrics, alerts, decisions, and health checks ## What You Get | Directory | Purpose | |-----------|---------| | `SKILL.md` | Architecture overview, installation guide, quick reference | | `references/` | 7 reference files: config deep dive, AppSec WAF, Docker deployment, Traefik integration, database backends, hub collections, troubleshooting | ## Quick Start Start with the setup and first workflow in SKILL.md, then use the linked resources for the specific task you need to complete. ## Triggers Load this when setting up or troubleshooting CrowdSec, or when you need an IPS/IDPS/WAF for your infrastructure. ## Requirements Linux server for installation. Docker for containerized deployment. Standard shell tools.