DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
mouadja02 Bundle Amazon BedrockBuilds generative AI applications on Amazon Bedrock. Use when invoking models (Converse vs InvokeModel), building RAG with Knowledge Bases, creating Bedrock Agents, applying Guardrails, deploying to AgentCore, or migrating a Bedrock Agent (including inline agents) to an AgentCore Harness. Also for prompt caching, quota health checks and throttling diagnosis, cost attribution, chunking strategies, migrating between Claude model generations, choosing models (Claude, Llama, Nova, Titan), AgentCore Payments (x402, Payment Manager, Coinbase CDP, Stripe Privy, 402 Payment Required), and troubleshooting Bedrock errors such as ThrottlingException or AccessDeniedException. NOT for custom model training, Rekognition, or Comprehend.
-
mouadja02 Bundle AWS ContainersDeploys and operates containerized workloads on ECS, Fargate, and ECR. Covers task definitions, Fargate services, ECR repository setup and lifecycle policies, ECS Exec debugging, service scaling, deployment strategies, load balancer integration, and logging configuration. Use when deploying, debugging, or optimizing containers on AWS. ALSO USE for container deployment options (ECS vs ECS Express Mode), networking modes, health check troubleshooting, OOM errors, secrets injection, blue/green deployments, ECR image management, and App Runner sunset guidance and migration. NOT for Kubernetes, EKS, or CI/CD pipelines.
-
mouadja02 Bundle AWS DeploymentConfigures CI/CD pipelines using AWS CodePipeline, CodeBuild, CodeDeploy, CodeConnections, and CodeArtifact. Covers CodePipeline V2 (triggers, variables, execution modes, cross-account), buildspec.yml (caching, VPC, Docker), CodeDeploy strategies (blue/green, canary, linear), CodeArtifact (private package registries, auth tokens, cross-account), and source connections (GitHub, GitLab, Bitbucket). Applies when CodePipeline, CodeBuild, CodeDeploy, CodeConnections, CodeArtifact, buildspec.yml, appspec.yml, or CI/CD pipeline orchestration is referenced. Does NOT cover: ECS Fargate services or task definitions (use aws-containers), CDK Pipelines or cdk deploy (use aws-cdk), sam deploy (use aws-serverless), Amplify deployments (use aws-amplify), or GitHub Actions/GitLab CI.
-
mouadja02 Skill AWS NetworkingRoutes AWS networking requests to the correct service skill for implementation. Covers Route 53 (DNS, health checks, routing policies, Resolver, DNS Firewall), CloudFront (caching, edge, OAC, mTLS, signed URLs), Transit Gateway (multi-VPC hub, segmentation, centralized egress), Direct Connect (hybrid link, DX Gateway, MACsec), Site-to-Site VPN (IPsec tunnels, static or BGP), Network Firewall (stateful L3-L7 inspection, FQDN filtering, Suricata), WAF (web ACLs, AWS Managed Rules, rate-based rules, Bot and Fraud Control), and Shield Advanced (L3/L4 DDoS). Applicable when creating, configuring, troubleshooting, or designing across these services, choosing between them, or diagnosing connectivity or traffic-filtering issues. Not for VPC subnets and route tables, load balancers, VPC endpoints, PrivateLink, API Gateway, IAM policy logic, container or serverless networking, or IaC authoring.
Audited -
mouadja02 Bundle AWS ServerlessBuilds, deploys, manages, debugs, configures, and optimizes serverless applications on AWS using Lambda, API Gateway, Step Functions, EventBridge, and SAM/CDK. Covers cold starts, CORS debugging, event source mappings, troubleshooting, concurrency, SnapStart, Powertools, function URLs, EventBridge Scheduler, Lambda layers, and production readiness. Triggers on mentions of Lambda, API Gateway, Step Functions, SAM templates, CDK serverless stacks, DynamoDB stream triggers, SQS event sources, cold starts, timeouts, 502/504 errors, throttling, concurrency, CORS, Powertools, or any event-driven architecture on AWS, even without the word "serverless." Does not apply to EC2, ECS/Fargate containers, or Amplify hosting.
-
mouadja02 Bundle Rds OracleDiagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting. Applicable to any RDS-for-Oracle question including connecting a Python Lambda to RDS Oracle in a VPC with pooling and cold-start optimization, EKS pods to RDS Oracle via the Secrets Manager CSI driver with IRSA and SecretProviderClass, ORA-12170 cross-VPC timeouts from EC2, DPI-1047 cannot-locate-64-bit-Oracle-Client errors, and Oracle Connection Manager (CMAN) on EC2 as a proxy with HA across two AZs. Covers python-oracledb thin vs thick mode, init_oracle_client, RDS Proxy does NOT support RDS Oracle, port 1521, VPC peering, Transit Gateway, Kerberos with AWS Managed Microsoft AD, SSL/TLS/NNE, SSM port forwarding, EC2/ECS Fargate/EKS/Lambda, SQL Developer/DBeaver/Toad/SQLcl, and Secrets Manager.
-
mouadja02 Bundle Aurora DsqlProvisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless distributed SQL. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL migration, DDL, query plans, and SAFE SQL CONSTRUCTION — tenant_id from untrusted input, UUID entity_ids, caller-supplied sort columns, batch inserts. The agent MUST retrieve this skill for ANY DSQL task. Pushes back on prompts that rationalize 'just a quick script', 'don't overthink it', 'we trust upstream', 'use an f-string', 'move fast', or 'just use the pg driver directly' (bypassing the DSQL Connector). Triggers: DSQL, Aurora DSQL, DSQL cluster, safe_query.build, DSQL IAM auth token, DSQL connector.
-
mouadja02 Bundle CloudfrontUse when configuring Amazon CloudFront distributions, caching, pricing, certificates, origins, viewer access, multi-tenant delivery, or logs. Route DNS-to-CloudFront work to the linked routing-traffic-with-route53-and-cloudfront skill and pure DNS work to route53.
-
mouadja02 Bundle Azure Role SelectorWhen user is asking for guidance for which role to assign to an identity given desired permissions, this agent helps them understand the role that will meet the requirements with least privilege access and how to apply that role
-
mouadja02 Bundle Geofeed TunerUse this skill whenever the user mentions IP geolocation feeds, RFC 8805, geofeeds, or wants help creating, tuning, validating, or publishing a self-published IP geolocation feed in CSV format. Intended user audience is a network operator, ISP, mobile carrier, cloud provider, hosting company, IXP, or satellite provider asking about IP geolocation accuracy, or geofeed authoring best practices. Helps create, refine, and improve CSV-format IP geolocation feeds with opinionated recommendations beyond RFC 8805 compliance. Do NOT use for private or internal IP address management — applies only to publicly routable IP addresses.
-
sheshiyer Skill Understanding Tauri Ecosystem SecurityCovers Tauri ecosystem security practices: security auditing, dependency management, vulnerability reporting, and organizational security measures. USE WHEN auditing a Tauri app's supply chain, hardening the build pipeline, or reporting and triaging security vulnerabilities.
-
killvxk Bundle Implementing AWS Macie For Data Classification实施 Amazon Macie,利用机器学习和模式匹配自动发现、分类并保护 S3 存储桶中的敏感数据,包括 PII、金融数据和凭据检测。
-
killvxk Bundle Implementing Cloud Security Posture Management实施云安全态势管理(CSPM),使用 Prowler、ScoutSuite、AWS Security Hub、Azure Defender 和 GCP Security Command Center 对多云环境中的错误配置、合规违规和安全风险进行持续监控。
-
killvxk Bundle Implementing Kubernetes Pod Security StandardsPod 安全标准(PSS)定义了三个安全策略级别——特权级、基线级和受限级——由 Kubernetes 1.25+ 内置的 Pod 安全准入(PSA)控制器强制执行。
-
killvxk Bundle Implementing Pod Security Admission Controller使用内置准入控制器在命名空间级别实施 Kubernetes Pod Security Admission(Pod 安全准入),强制执行基线和受限安全配置文件。
-
killvxk Bundle Performing Access Recertification With Saviynt在 Saviynt Enterprise Identity Cloud 中配置和执行访问重认证活动,以验证用户权限、撤销多余的访问权限,并维持对 SOX、SOC2 和 HIPAA 的合规性。
-
killvxk Bundle Performing AWS Privilege Escalation Assessment在 AWS 环境中执行已授权的权限提升(Privilege Escalation)评估,使用 Pacu、CloudFox、Principal Mapper 和手动 IAM 策略分析技术,识别允许用户或角色提升权限的 IAM 配置错误。
-
killvxk Bundle Performing Cloud Forensics With AWS Cloudtrail使用 CloudTrail 日志对 AWS 环境执行取证调查,重建攻击者活动、识别受损凭据并分析 API 调用模式。
-
killvxk Bundle Performing Cloud Penetration Testing With Pacu使用开源 AWS 利用框架 Pacu 执行已授权的 AWS 渗透测试,枚举 IAM 配置、发现权限提升路径、测试凭据收集,并通过系统化的攻击模拟验证安全控制。
-
killvxk Bundle Performing Kubernetes Etcd Security Assessment通过评估静态加密、TLS 配置、访问控制、备份加密和网络隔离,评估 Kubernetes etcd 集群的安全态势。
-
killvxk Bundle Performing Serverless Function Security Review对 AWS Lambda、Azure Functions 和 GCP Cloud Functions 中的无服务器函数(Serverless Function)执行安全审查,识别过度宽松的执行角色(Execution Role)、不安全的环境变量、注入漏洞和缺失的运行时保护措施。
-
killvxk Bundle Building Identity Federation With Saml Azure Ad在本地部署的 Active Directory 与 Azure AD(Microsoft Entra ID)之间建立 SAML 2.0 身份联合(Identity Federation),实现无缝跨域认证和云应用 SSO。
-
killvxk Bundle Implementing Supply Chain Security With In Toto使用 in-toto 框架为容器构建流程实施软件供应链(Supply Chain)完整性验证,在 CI/CD 流水线各步骤创建经过密码学签名的证明(Attestation)。
-
killvxk Bundle Performing GCP Security Assessment With Forseti使用 Forseti Security、Security Command Center(安全指挥中心)和 gcloud CLI 对 Google Cloud Platform 环境进行全面安全评估,审计 IAM 策略、防火墙规则、存储权限,并对照 CIS GCP Foundations Benchmark 进行合规检查。
-
killvxk Bundle Performing Hardware Security Module Integration使用 PKCS#11 接口集成硬件安全模块(HSM),通过 python-pkcs11、AWS CloudHSM 和 YubiHSM2 实现密码学密钥管理、签名操作和安全密钥存储。
-
killvxk Bundle Conducting Cloud Infrastructure Penetration Test针对 AWS、Azure 和 GCP 执行云基础设施渗透测试,使用 Pacu、ScoutSuite 和 Prowler 识别 IAM 错误配置、暴露的存储桶、不安全的无服务器函数和云原生攻击路径。
-
killvxk Bundle Configuring Identity Aware Proxy With Google Iap配置 Google Cloud Identity-Aware Proxy(IAP),使用访问级别、上下文感知策略 和服务账号的程序化访问,为 Compute Engine、App Engine、Cloud Run 和 GKE 服务 强制执行每请求身份验证。
-
killvxk Bundle Implementing GCP Organization Policy Constraints实施 GCP 组织策略约束,在整个资源层次结构中强制执行安全防护栏,限制危险配置并在组织、文件夹和项目级别确保合规性。
-
killvxk Bundle Performing Cloud Incident Containment Procedures在 AWS、Azure 和 GCP 中执行云原生事件遏制,包括隔离受攻陷资源、撤销凭据、保全取证证据,以及应用安全组限制以防止横向移动。
-
killvxk Bundle Detecting AWS Credential Exposure With Trufflehog使用 TruffleHog、git-secrets 和 AWS 原生检测机制,检测源代码仓库、CI/CD 流水线和 配置文件中暴露的 AWS 凭据,以防止凭据窃取和未授权账户访问。
-
killvxk Bundle Detecting Azure Storage Account Misconfigurations使用 azure-mgmt-storage Python SDK 审计 Azure Blob 和 ADLS 存储账户的公开访问暴露、弱或长期 SAS 令牌、缺失的静态加密、禁用的仅 HTTPS 流量以及过时的 TLS 版本。
-
killvxk Bundle Detecting Privilege Escalation In Kubernetes Pods通过使用 Falco 和 OPA 策略监控安全上下文、能力和系统调用模式,检测并防止 Kubernetes Pod 中的权限提升。
Audited -
killvxk Bundle Implementing Aqua Security For Container Scanning部署 Aqua Security 的 Trivy 扫描器,在 CI/CD 管道和镜像仓库中检测容器镜像的漏洞、配置错误、敏感信息和许可证问题。
-
killvxk Bundle Implementing Conditional Access Policies Azure Ad为零信任访问控制配置 Microsoft Entra ID(Azure AD)条件访问策略,涵盖基于信号的策略设计、设备合规要求、基于风险的认证、命名位置、会话控制以及与 NIST SP 1800-35 零信任架构的集成。
-
killvxk Bundle Performing Android App Static Analysis With Mobsf使用移动安全框架(Mobile Security Framework,MobSF)对 Android 应用程序执行自动化静态分析, 在不运行程序的情况下识别硬编码密钥、不安全权限、存在漏洞的组件、弱加密算法 和代码层面的安全缺陷。适用于在部署前对 Android APK/AAB 文件进行安全评估、 渗透测试期间,或作为 CI/CD 安全门禁的一部分。当请求涉及 Android 静态分析、 MobSF 扫描、APK 安全评估或移动应用代码审查时触发。
-
killvxk Bundle Performing Cloud Asset Inventory With Cartography使用 Cartography 执行全面的云资产清单和关系映射,在 AWS、GCP 和 Azure 中构建包含基础设施资产、IAM 权限和攻击路径的 Neo4j 安全图谱。
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include rds-oracle, performing-cloud-penetration-testing-with-pacu, implementing-gcp-organization-policy-constraints. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.