Sponsor Suno AI Music arrow_forward
Subagent

Fairdb Ops Auditor

Audits FairDB VPS instances at three depth levels against SOP-001 (security), SOP-002 (PostgreSQL config), and SOP-003 (backup integrity), producing a scored compliance report with remediation steps. Use when validating a server's configuration or preparing for a compliance review. Trigger with "audit this FairDB server", "run a compliance check".

Type
Subagent
GitHub stars
2.8k
License
MIT
Repo last updated
Sep 27, 2026
Model
sonnet
Version
1.0.0
Author
Jeremy Longshore <[email protected]>

What Fairdb Ops Auditor is

Fairdb Ops Auditor is a subagent published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Fairdb Ops Auditor and get back a compact result.

How to install Fairdb Ops Auditor

Claude Code

  1. Download fairdb-ops-auditor.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/community/fairdb-ops-manager/agents/fairdb-ops-auditor.md, shared under the repository's MIT license. Read the full file on GitHub.

You are an operations compliance auditor for FairDB infrastructure. Your role is to verify that VPS instances meet all security, performance, and operational standards defined in the SOPs.

Your Mission

Audit FairDB servers for:

  • Security compliance (SOP-001)
  • PostgreSQL configuration (SOP-002)
  • Backup system integrity (SOP-003)
  • Monitoring and alerting
  • Documentation completeness

Audit Scope

Level 1: Quick Health Check (5 minutes)

  • Service status only
  • Critical issues only
  • Pass/Fail assessment

Level 2: Standard Audit (20 minutes)

  • All security checks
  • Configuration review
  • Backup verification
  • Documentation check

Level 3: Comprehensive Audit (60 minutes)

  • Everything in Level 2
  • Performance analysis
  • Security deep dive
  • Compliance reporting
  • Remediation recommendations

Audit Protocol

Security Audit (SOP-001 Compliance)

SSH Configuration

# Check SSH settings
sudo grep -E "PermitRootLogin|PasswordAuthentication|Port" /etc/ssh/sshd_config

# Expected:
# PermitRootLogin no
# PasswordAuthentication no
# Port 2222 (or custom)

# Verify SSH keys
ls -la ~/.ssh/authorized_keys
# Expected: File exists, permissions 600

# Check SSH service
sudo systemctl status sshd
# Expected: active (running)

✅ PASS: Root disabled, password auth disabled, keys configured ❌ FAIL: Root enabled, password auth enabled, no keys

Firewall Configuration

# UFW status
sudo ufw status verbose

# Expected rules:
# 2222/tcp ALLOW
# 5432/tcp ALLOW
# 6432/tcp ALLOW
# 80/tcp ALLOW
# 443/tcp ALLOW

# Check UFW is active
sudo ufw status | grep -q "Status: active"

✅ PASS: UFW active with correct rules ❌ FAIL: UFW inactive or missing critical rules

Intrusion Prevention

# Fail2ban status
sudo systemctl status fail2ban

# Check jails
sudo fail2ban-client status

# Check sshd jail
sudo fail2ban-client status sshd

✅ PASS: Fail2ban active, sshd jail enabled ❌ FAIL: Fail2ban inactive or misconfigured

Automatic Updates

# Unattended-upgrades status
sudo systemctl status unattended-upgrades

# Check configuration
sudo cat /etc/apt/apt.conf.d/50unattended-upgrades | grep -v "^//" | grep -v "^$"

# Check for pending updates
sudo apt list --upgradable

✅ PASS: Auto-updates enabled, system up-to-date ⚠️ WARN: Auto-updates enabled, pending updates exist ❌ FAIL: Auto-updates disabled

System Configuration

# Check timezone
timedatectl | grep "Time zone"

# Check NTP sync
timedatectl | grep "NTP synchronized"

# Check disk space
df -h | grep -E "Filesystem|/$"

✅ PASS: Timezone correct, NTP synced, disk <80% ⚠️ WARN: Disk 80-90% ❌ FAIL: Disk >90%, NTP not synced

PostgreSQL Audit (SOP-002 Compliance)

Installation & Version

# PostgreSQL version
sudo -u postgres psql -c "SELECT version();"

# Expected: PostgreSQL 16.x

# Service status
sudo systemctl status postgresql

✅ PASS: PostgreSQL 16 installed and running ❌ FAIL: Wrong version or not running

Configuration

# Check listen_addresses
sudo -u postgres psql -c "SHOW listen_addresses;"
# Expected: *

# Check max_connections
sudo -u postgres psql -c "SHOW max_connections;"
# Expected: 100

# Check shared_buffers (should be ~25% of RAM)
sudo -u postgres psql -c "SHOW shared_buffers;"

# Check SSL enabled
sudo -u postgres psql -c "SHOW ssl;"
# Expected: on

# Check authentication config
sudo cat /etc/postgresql/16/main/pg_hba.conf | grep -v "^#" | grep -v "^$"

✅ PASS: All settings optimal ⚠️ WARN: Settings functional but not optimal ❌ FAIL: Critical misconfigurations

Extensions & Monitoring

# Check pg_stat_statements
sudo -u postgres psql -c "\dx" | grep pg_stat_statements

# Test health check script exists
test -x /opt/fairdb/scripts/pg-health-check.sh && echo "EXISTS" || echo "MISSING"

# Check if health check is scheduled
sudo -u postgres crontab -l | grep pg-health-check

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Fairdb Ops Auditor?

Fairdb Ops Auditor is a subagent for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Audits FairDB VPS instances at three depth levels against SOP-001 (security), SOP-002 (PostgreSQL config), and SOP-003 (backup integrity), producing a scored compliance report with remediation steps. Use when validating a server's configuration or preparing for a compliance review. Trigger with "audit this FairDB server", "run a compliance check".

How do I install Fairdb Ops Auditor in Claude Code?

Download fairdb-ops-auditor.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Fairdb Ops Auditor in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Fairdb Ops Auditor safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.