Agent skill · redis
redis-security
Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules, and disabling dangerous commands. Use when deploying Redis to production, defining ACL users for an application, configuring TLS connections, locking down a Redis instance behind a firewall, or auditing a Redis deployment for security hardening.
What it needs
About 2k tokens when loaded.
What this skill does
Redis Security Production hardening for Redis: authentication, ACL-based access control, and network exposure. Cover all three together — any one of them on its own leaves an exploitable gap. When to apply Deploying or reviewing a Redis instance destined for production. Setting up application credentials beyond a shared password. Auditing a Redis deployment against a security checklist. Receiving "Redis exposed to the internet" findings from a scanner. 1. Always authenticate (and use TLS) Never run a production Redis without a password. Pair authentication with TLS so credentials and data aren't sent in clear text. If you can use ACL users (next section) instead of the single requirepass, do — requirepass is effectively the legacy "default user" shortcut. See references/auth.md. 2. ACLs for least-privilege access The default user with a shared password is fine for development. For production, give each application a dedicated ACL user with only the commands and key patterns it actually needs. Useful command categories: Category What it covers --- --- @read Read commands (GET, MGET, HGET, ...) @write Write commands (SET, DEL, XADD, ...) @dangerous FLUSHALL, DEBUG, KEYS, etc. @admin Administrative commands If app credentials leak, a tight ACL bounds the blast radius — the attacker can't FLUSHALL your DB just because they grabbed a cache reader's password. See references/acls.md. 3. Restrict network access The most common Redis breach is a public-internet Redis with no auth. Avoid that with three layers: Anti-pattern: bind 0.0.0.0 + protected-mode no — exposes Redis to the whole network without protection. Optional but recommended: rename or disable destructive commands so a compromised client can't trash the DB: See references/network.md. References Redis: Security Redis: ACL
How to use it
Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:
@skills redis/redis-security--f4669c