DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
killvxk Bundle Securing Container Registry Images通过使用 Trivy 和 Grype 实施漏洞扫描、使用 Cosign 和 Sigstore 强制执行镜像签名、配置镜像仓库访问控制,以及构建阻止部署未扫描或未签名镜像的 CI/CD 流水线,来保护容器仓库(Container Registry)中的镜像安全。
-
killvxk Bundle Implementing GCP Vpc Firewall Rules实施和审计 GCP VPC 防火墙规则,强制执行网络分段,限制入站和出站流量,在整个组织范围内应用分层防火墙策略,并使用 VPC 流日志监控防火墙规则有效性。
-
killvxk Bundle Securing AWS Lambda Execution Roles通过实施最小权限(Least Privilege)IAM 策略、应用权限边界(Permission Boundary)、限制基于资源的策略、使用 IAM Access Analyzer 验证权限,以及通过 SCP 强制执行角色规范,保护 AWS Lambda 执行角色(Execution Role)。
-
killvxk Bundle Analyzing Docker Container Forensics通过分析镜像、层、卷、日志和运行时痕迹,调查受损的 Docker 容器,识别恶意活动和证据。
-
killvxk Bundle Auditing Kubernetes Rbac PermissionsKubernetes 基于角色的访问控制(RBAC)审计,系统性地审查角色、集群角色、绑定关系及服务账户权限,以识别过度宽松的访问配置、权限提升路径及违反最小权限原则的情况。
-
killvxk Bundle Conducting Cloud Penetration Testing本 skill 概述了对 AWS、Azure 和 GCP 云环境进行授权渗透测试的方法论。 涵盖理解测试范围的共享责任模型、利用 Pacu 和 ScoutSuite 等云专用攻击工具、 利用 IAM 错误配置、测试针对云元数据服务的 SSRF, 以及按照 MITRE ATT&CK 云矩阵对发现进行报告。
-
killvxk Bundle Detecting SQL Injection Via Waf Logs分析 WAF(Web 应用防火墙,ModSecurity/AWS WAF/Cloudflare)日志,检测 SQL 注入(SQL Injection)攻击活动。 解析 ModSecurity 审计日志和 JSON WAF 事件日志,识别 SQLi 模式(UNION SELECT、OR 1=1、SLEEP()、BENCHMARK()), 追踪攻击源,关联多阶段注入尝试,并生成带 OWASP 分类的事件报告。
-
killvxk Bundle Performing Cloud Penetration Testing对 AWS、Azure 和 GCP 云环境执行授权渗透测试,识别 IAM 错误配置、暴露的存储桶、过度宽松的安全组、 无服务器函数漏洞以及从初始访问到账户沦陷的云特定攻击路径。测试人员使用云原生工具及 Pacu、 ScoutSuite 等专用框架枚举并利用云基础设施。适用于云渗透测试、AWS 安全评估、Azure 渗透测试 或云基础设施安全测试等请求场景。
-
killvxk Bundle Performing Container Image Hardening本技能涵盖通过最小化攻击面、移除不必要软件包、实施多阶段构建、配置非 root 用户, 以及应用 CIS Docker 基准建议来加固容器镜像,生成安全的生产就绪镜像。
-
openaccountants Skill Global Cloud Infrastructure> Pattern library for cloud, infrastructure, and developer tool vendors that appear on bank statements and ledger detail worldwide. Use when classifying an unknown transaction line. Provides the canonical vendor name, common bank statement variations, default Schedule C / category mapping, VAT treatment (B2B reverse charge for most cross-border digital services), and notes on currency, billing cycle, and any sector-specific gotchas. Covers AWS, Azure, GCP, Cloudflare, DigitalOcean, Linode/Akamai, Hetzner, OVHcloud, Vultr, Render, Vercel, Netlify, Fly.io, Railway, Heroku, Backblaze, Wasabi, Datadog, New Relic, PagerDuty, GitHub, GitLab, Sentry, LaunchDarkly, Twilio, SendGrid, Mailgun, Resend, Postmark. Does NOT cover: SaaS productivity tools (see global-productivity-tools), ad platforms (see global-ad-platforms), or payment processors (see global-payment-processors).
Audited -
openaccountants Skill Global Marketplaces Banking Fees> Pattern library for online marketplaces (Etsy, eBay, Amazon Seller, AliExpress, Mercari, Depop, Vinted, Fiverr, Upwork, Toptal, Catalant, Andela, Patreon, Substack, Gumroad, Lemonsqueezy, Beehiiv, Whop) and recurring bank / payment-platform fees (wire fees, currency conversion, FX spreads, ATM fees, monthly account fees, overdraft, returned cheque). Provides bank-statement variations, classification, VAT/GST treatment, marketplace facilitator collection rules (post-Wayfair US states; EU marketplace deemed-supplier; UK platform reporting under DAC7-equivalent), and the 1099-K threshold reduction for US sellers (USD 5,000 for 2024, USD 600 for 2026 per OBBBA confirmation). Does NOT cover: cloud (see global-cloud-infrastructure), productivity SaaS (see global-productivity-tools), ad platforms (see global-ad-platforms), payment processors (see global-payment-processors).
Audited -
openclaw-commons Skill GCP GoGcp Go
-
openclaw-commons Skill Helm GoHelm Go
-
openclaw-commons Skill Azure GoAzure Go
-
openclaw-commons Skill AWS Boto3Aws Boto3
-
openclaw-commons Skill Docker GoDocker Go
-
openclaw-commons Skill GCP SetupGcp Setup
-
caishengold Skill Data Pipeline Doc Writer当需要撰写数据管道相关专业文案、行业指南、科普文章时使用。触发场景:数据管道文档。当用户提到"数据管道"、"数据管道文档"、"data"、"pipeline"、"doc"时应触发此技能。
Audited -
mouadja02 Bundle FastmcpBuild, test, inspect, install, and deploy MCP servers with FastMCP in Python. Use when creating a new MCP server, wrapping an API or database as MCP tools, exposing resources or prompts, or preparing a FastMCP server for Claude Code, Cursor, or HTTP deployment.
-
mouadja02 Skill WranglerCloudflare Wrangler CLI: Workers, KV, R2, D1, tail, deploy, account routing.
-
vincentchuwaichow Bundle Netsuite Suitecloud Developer SkillStatic-review flashlight for NetSuite SuiteCloud Development Framework projects and SuiteScript 2.x code. Adapts the Oracle netsuite-suitescript-upgrade upstream skill (UPL-1.0, Copyright (c) 2019, 2023 Oracle and/or its affiliates) with Vanguard-specific CI gate thresholds and CHANGELOG conventions. Reviews SDF object XML, deployment manifests, SuiteScript entry points, custom record definitions, and SuiteApp packaging. TRIGGER when: user asks to review SDF project structure, audit SuiteScript 2.x code, assess SuiteScript 1.0 or 2.0 upgrade readiness, review a Suitelet or RESTlet design, inspect custom record definitions, review SuiteApp manifest configuration, or score SuiteScript migration complexity. Trigger phrases: SDF review, SuiteScript upgrade, SuiteScript 2.1, custom record design, Suitelet review, SuiteApp packaging, SDF manifest. DO NOT TRIGGER when: the question is about SDF DevOps release pipeline or CI/CD (use netsuite-sdf-devops-release-agent), OWASP SuiteScript security review (use netsuite-s
-
vincentchuwaichow Bundle Nvidia Tensorrt LLM Deployment ReviewUse this skill when reviewing TensorRT or TensorRT-LLM deployment artifacts statically — ONNX/PyTorch export pipelines, precision selection (FP16/BF16/INT8/FP8/INT4), calibration cache integrity, dynamic shape profiles, custom plugin loading, engine cache and serialized engine provenance, runtime memory pool sizing. Trigger when the user asks whether a TensorRT build script, calibration pipeline, or trtexec invocation follows NVIDIA's published guidance.
-
vincentchuwaichow Bundle Scaleway Live Kapsule Rollout GuardGate and execute Scaleway Kapsule live mutations — Kubernetes version upgrades, node pool creation/deletion/scaling, and cluster configuration changes — with mandatory PDB audit, cluster health verification, explicit approval, and a documented rollback plan. Use when a live Kapsule cluster or node pool mutation is requested. Hard-stops when target cluster ID, region/zone, approval, or rollback plan is absent or ambiguous.
-
vincentchuwaichow Bundle Sigstore Cosign Supply Chain ReviewUse this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno imageVerify policy is correctly scoped, whether SLSA provenance attestations exist, whether SBOM attestations are present, whether keyless signing is in use, or whether Rekor transparency log posture is appropriate for private images.
-
vincentchuwaichow Bundle Azure Cosmosdb Performance InvestigatorAzure Cosmos DB Performance Investigator
-
vincentchuwaichow Bundle Azure Private Endpoint Adoption PlannerAzure Private Endpoint Adoption Planner
-
vincentchuwaichow Bundle Cert Manager Issuer Trust ReviewUse this skill when reviewing cert-manager PKI configuration for Kubernetes clusters. Trigger when the user asks about Issuer or ClusterIssuer scope, CertificateRequestPolicy coverage, certificate SAN or duration risks, trust-manager bundle distribution, SPIFFE mesh CA integration, cert-manager webhook health, or cloud CA authentication method.
-
vincentchuwaichow Bundle Contabo Live Instance Lifecycle GuardLive-guard skill for Contabo VPS and VDS lifecycle operations including instance creation with product selection and region, reinstallation with image and Cloud-Init userData, and cancellation. Requires mandatory contract period acknowledgment (1, 3, 6, or 12 months), billing impact confirmation, and a rollback plan before any mutation. Hard-stops any lifecycle action that lacks explicit period acknowledgment or rollback documentation.
-
vincentchuwaichow Bundle GCP Daily Operations Briefing CoordinatorCoordinate the daily GCP operations standup — cost delta from previous day, quota warning review, failed deployment detection, Security Command Center finding triage, SLO burn rate alert review, and action item assignment.
-
vincentchuwaichow Bundle Huawei Cce Container Platform OperatorOperate Huawei CCE (Cloud Container Engine) Kubernetes clusters, SWR container image registry lifecycle, ASM service mesh traffic policies, and IEF edge node management for cloud-native and hybrid workloads.
-
vincentchuwaichow Bundle Huawei Serverless Production ReadinessReview FunctionGraph production readiness on Huawei Cloud — VPC access configuration, concurrency limits and reserved instances, cold-start optimization, observability via LTS and AOM, timeout configuration, dependency package size, custom vs managed runtimes, and ServiceStage application lifecycle.
-
vincentchuwaichow Bundle Netsuite Live Operation Safety SkillEvaluates live NetSuite mutation requests against a structured authorization checklist covering blast-radius, rollback, human decision ownership, and integration posture. T0 static evaluation — no org connection required. TRIGGER when: a request involves activating a workflow, deploying an SDF project, editing live records, publishing a saved search to new roles, changing permissions, rotating OAuth certificates, issuing or revoking TBA tokens, or any other operation that writes to or configures a live NetSuite account. Trigger phrases: deploy to production, activate workflow, change permissions in NetSuite, rotate cert, publish saved search, edit live record, SDF deploy, grant role. DO NOT TRIGGER when: the request is purely a static design review with no live-op intent (use the appropriate domain specialist); request is about reading or querying live data without mutation (use netsuite-saved-searches-workbook-agent or netsuite-bi-reporting-agent); request is about architecture design only (use netsuite-ente
-
vincentchuwaichow Bundle Alibaba Cost Anomaly Watch CoordinatorDetect and coordinate response to Alibaba Cloud cost anomalies — MaxCompute CU vs on-demand billing mismatch, ECS spot instance interruption cascades, CDN traffic spike billing, OSS API request cost explosions, budget alert → DingTalk notification → remediation playbook.
-
vincentchuwaichow Bundle Alibaba Load Balancer Traffic EngineerTraffic engineering for Alibaba Cloud load balancers — CLB (Classic, legacy), ALB (Application Load Balancer, Layer 7 advanced routing), NLB (Network Load Balancer, Layer 4 high throughput), and GA (Global Accelerator) — type selection, health check design, WAF integration, and traffic distribution.
-
vincentchuwaichow Bundle Azure Key Vault Secret Lifecycle AuditorAzure Key Vault Secret Lifecycle Auditor
-
vincentchuwaichow Bundle Azure Keyvault Certificate Issuer ReviewUse this skill when reviewing Azure Key Vault certificate issuer configurations for cert-manager on AKS. Trigger on any request to audit Key Vault certificate policies, Managed Identity role assignments, exportability settings, private endpoint connectivity, integrated CA credentials, or rotation policy alignment.
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include sigstore-cosign-supply-chain-review, gcp-go, helm-go. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.