@cyberstrikeus/cis-ubuntu-14-04-lts-1-2-2-ensure-gpg-keys-are-configured
BVerify that GPG keys are configured for package manager to ensure package integrity
Install
agr install @cyberstrikeus/cis-ubuntu-14-04-lts-1-2-2-ensure-gpg-keys-are-configured --target claudeWrites 1 file into .claude/skills/, pinned to git-22078e7d.
- .claude/skills/cis-ubuntu-14-04-lts-1-2-2-ensure-gpg-keys-are-configured/SKILL.md
Document
name: "CIS Ubuntu 14.04 LTS - 1.2.2 Ensure GPG keys are configured" description: "Verify that GPG keys are configured for package manager to ensure package integrity" category: "cis-os-hardening" version: "2.1.0" author: "cyberstrike-official" tags:
- cis
- ubuntu
- ubuntu-14.04
- level-1
- not-scored
- software-updates cis_id: "1.2.2" cis_benchmark: "CIS Ubuntu Linux 14.04 LTS Benchmark v2.1.0" tech_stack:
- ubuntu
- linux cwe_ids: [] chains_with: [] prerequisites: [] severity_boost: "medium"
1.2.2 Ensure GPG keys are configured (Not Scored)
Profile Applicability
- Level 1 - Server
- Level 1 - Workstation
Description
Most packages managers implement GPG key signing to verify package integrity during installation.
Rationale
It is important to ensure that updates are obtained from a valid source to protect against spoofing that could lead to the inadvertent installation of malware on the system.
Audit Procedure
Run the following command and verify GPG keys are configured correctly for your package manager:
apt-key list
Expected Result
Verify that GPG keys are configured according to site policy.
Remediation
Update your package manager GPG keys in accordance with site policy.
Default Value
Not applicable. Configuration varies by site policy.
References
- CIS Controls: 4.5 Use Automated Patch Management And Software Update Tools
Profile
- Level 1 - Server
- Level 1 - Workstation
Trustgrade B
- passBody integrity
Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.
- passType matchnot applicable to this artifact type
Whether the artifact is really the kind of thing its metadata claims it is.
- passFreshness
How long since the source repository was last pushed to.
- passPrompt injection
Scans the artifact's own text for instructions aimed at your agent rather than at you.
- warnLicensecopyleft/unknown — index-and-link only
Whether the source repository declares an SPDX license permissive enough to redistribute.
How the grade is calculated
Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:
- Aevery check passed
- Bone warning
- Ctwo warnings
- Dprompt injection or body integrity failed, or three warnings
- Fone of those failed, and something else is wrong
These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.
Versions
git-22078e7db7b42026-07-31