What problem does it solve? Servers often have security tools installed but misconfigured, inactive, or silently broken, and entire defense classes like brute-force protection or file-integrity monitoring may be missing without anyone noticing. This Skill inventories the host's own defensive tooling, verifies each tool is actually working, and surfaces gaps before they become incidents. ## Core Features & Use Cases - Tool Discovery: Detects fail2ban, sshguard, CrowdSec, rkhunter, chkrootkit, auditd, ClamAV, AIDE, debsecan/arch-audit, and wazuh/ossec, reporting presence and live status. - Health Verification: Flags degraded defenses such as inactive services, fail2ban with no jails, or auditd with zero rules, as review-tier findings. - Gap Detection: Emits findings for entire missing defense classes (brute-force protection, rootkit checking, host audit, file-integrity baseline), with profile-aware severity so rootkit and audit gaps only apply to servers. - Use Case: During a scheduled security audit of a public Debian server, the Skill finds CrowdSec installed but its service inactive, and no file-integrity tool at all, journaling both as findings that regress loudly if they recur. ## Quick Start Ask the AI to run the watchman audit to inventory this machine's defensive security tools and report which are healthy and which defense classes are missing.