Skip to content
Back to skills

Linux

FSecurity

Operate Linux systems avoiding permission traps, silent failures, and common admin mistakes.

  • 14 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 7, 2026
devopsrustgonodedockersecurity

Works with

  • terminal

Security analysis

F20/100
  • criticalAccesses sensitive system or user directories
  • highPerforms destructive filesystem operations
  • highCreates or modifies cron jobs for persistent execution
  • criticalModifies startup scripts or system services for persistence

Pro shows the line behind each finding and how to fix it

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill linux --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Linux?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Linux
[![Security: F β€” Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-linux/badge)](https://www.skillsdirectory.com/skills/modbender-linux)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Linux
description: Operate Linux systems avoiding permission traps, silent failures, and common admin mistakes.
metadata: {"clawdbot":{"emoji":"🐧","os":["linux","darwin"]}}
---

# Linux Gotchas

## Permission Traps
- `chmod 777` fixes nothing, breaks everything β€” find the actual owner/group issue
- Setuid on scripts is ignored for security β€” only works on binaries
- `chown -R` follows symlinks outside target directory β€” use `--no-dereference`
- Default umask 022 makes files world-readable β€” set 077 for sensitive systems
- ACLs override traditional permissions silently β€” check with `getfacl`

## Process Gotchas
- `kill` sends SIGTERM by default, not SIGKILL β€” process can ignore it
- `nohup` doesn't work if process already running β€” use `disown` instead
- Background job with `&` still dies on terminal close without `disown` or `nohup`
- Zombie processes can't be killed β€” parent must call wait() or be killed
- `kill -9` skips cleanup handlers β€” data loss possible, use SIGTERM first

## Filesystem Traps
- Deleting open file doesn't free space until process closes it β€” check `lsof +L1`
- `rm -rf /path /` with accidental space = disaster β€” use `rm -rf /path/` trailing slash
- Inodes exhausted while disk shows space free β€” many small files problem
- Symlink loops cause infinite recursion β€” `find -L` follows them
- `/tmp` cleared on reboot β€” don't store persistent data there

## Disk Space Mysteries
- Deleted files held open by processes β€” `lsof +L1` shows them, restart process to free
- Reserved blocks (5% default) only for root β€” `tune2fs -m 1` to reduce
- Journal eating space β€” `journalctl --vacuum-size=500M`
- Docker overlay eating space β€” `docker system prune -a`
- Snapshots consuming space β€” check LVM, ZFS, or cloud provider snapshots

## Networking
- `localhost` and `127.0.0.1` may resolve differently β€” check `/etc/hosts`
- Firewall rules flushed on reboot unless saved β€” `iptables-save` or use firewalld/ufw persistence
- `netstat` deprecated β€” use `ss` instead
- Port below 1024 requires root β€” use `setcap` for capability instead
- TCP TIME_WAIT exhaustion under load β€” tune `net.ipv4.tcp_tw_reuse`

## SSH Traps
- Wrong permissions on ~/.ssh = silent auth failure β€” 700 for dir, 600 for keys
- Agent forwarding exposes your keys to remote admins β€” avoid on untrusted servers
- Known hosts hash doesn't match after server rebuild β€” remove old entry with `ssh-keygen -R`
- SSH config Host blocks: first match wins β€” put specific hosts before wildcards
- Connection timeout on idle β€” add `ServerAliveInterval 60` to config

## Systemd
- `systemctl enable` doesn't start service β€” also need `start`
- `restart` vs `reload`: restart drops connections, reload doesn't (if supported)
- Journal logs lost on reboot by default β€” set `Storage=persistent` in journald.conf
- Failed service doesn't retry by default β€” add `Restart=on-failure` to unit
- Dependency on network: `After=network.target` isn't enough β€” use `network-online.target`

## Cron Pitfalls
- Cron has minimal PATH β€” use absolute paths or set PATH in crontab
- Output goes to mail by default β€” redirect to file or `/dev/null`
- Cron uses system timezone, not user's β€” set TZ in crontab if needed
- Crontab lost if edited incorrectly β€” `crontab -l > backup` before editing
- @reboot runs on daemon restart too, not just system reboot

## Memory and OOM
- OOM killer picks "best" victim, often not the offender β€” check dmesg for kills
- Swap thrashing worse than OOM β€” monitor with `vmstat`
- Memory usage in `free` includes cache β€” "available" is what matters
- Process memory in `/proc/[pid]/status` β€” VmRSS is actual usage
- cgroups limit respected before system OOM β€” containers die first

## Commands That Lie
- `df` shows filesystem capacity, not physical disk β€” check underlying device
- `du` doesn't count sparse files correctly β€” file appears smaller than disk usage
- `ps aux` memory percentage can exceed 100% (shared memory counted multiple times)
- `uptime` load average includes uninterruptible I/O wait β€” not just CPU
- `top` CPU percentage is per-core β€” 400% means 4 cores maxed

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…