DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
killvxk Bundle Performing Container Security Scanning With Trivy使用 Aqua Security Trivy 扫描容器镜像、文件系统和 Kubernetes 清单,检测漏洞(Vulnerability)、错误配置、暴露的密钥和许可证合规问题,并生成 SBOM(Software Bill of Materials,软件物料清单)及集成到 CI/CD 流水线。
-
killvxk Bundle Implementing Fuzz Testing In Cicd With Aflplusplus将 AFL++ 覆盖率引导的模糊测试集成到 CI/CD 管道中,以发现 C/C++ 和编译型应用中的内存损坏、输入处理和逻辑漏洞。
-
killvxk Bundle Implementing Kubernetes Network Policy With Calico使用 Calico NetworkPolicy 和 GlobalNetworkPolicy 实施 Kubernetes 网络分段,实现 Pod 间零信任通信。
-
killvxk Bundle Implementing Opa Gatekeeper For Policy Enforcement使用 OPA Gatekeeper 通过 ConstraintTemplate、Rego 规则和 Gatekeeper 策略库强制执行 Kubernetes 准入策略。
-
killvxk Bundle Implementing Policy As Code With Open Policy Agent本技能涵盖在 Kubernetes 和 CI/CD 管道中实施 Open Policy Agent(OPA)和 Gatekeeper 进行策略即代码执行。 内容包括编写 Rego 策略、将 OPA Gatekeeper 部署为 Kubernetes 准入控制器、在开发中测试策略, 以及将策略评估集成到部署管道中。
-
killvxk Bundle Implementing Zero Standing Privilege With Cyberark部署 CyberArk Secure Cloud Access,通过基于时间、权限和审批控制的即时访问,在混合云和多云环境中消除常设权限。
-
killvxk Bundle Implementing Cloud Vulnerability Posture Management使用 AWS Security Hub、Azure Defender for Cloud 以及 Prowler、ScoutSuite 等开源工具实施云安全态势管理(CSPM),实现多云漏洞检测。
Audited -
killvxk Bundle Implementing Container Network Policies With Calico使用 Calico CNI 网络策略和全局网络策略实施 Kubernetes 网络分段,控制 Pod 间流量、限制出口流量并实现零信任微分段。
-
killvxk Bundle Performing AWS Account Enumeration With Scout Suite使用 ScoutSuite 对 AWS 账户进行全面的安全态势评估,枚举资源、识别配置错误并生成可操作的安全报告。
-
killvxk Bundle Performing Kubernetes Cis Benchmark With Kube Bench使用 kube-bench 对照 CIS Benchmark 审计 Kubernetes 集群安全态势,对控制平面、工作节点和 RBAC 执行自动化检查。
-
killvxk Bundle Implementing Azure Ad Privileged Identity Management配置 Microsoft Entra 特权身份管理(PIM)以强制执行即时角色激活(Just-in-Time)、审批工作流和 Azure AD 特权角色的访问审查。
-
killvxk Bundle Implementing Infrastructure As Code Security Scanning本技能涵盖使用 Checkov、tfsec 和 KICS 等工具为基础设施即代码(IaC)模板实施自动化安全扫描。 内容包括在部署前检测 Terraform、CloudFormation、Kubernetes 清单和 Helm charts 中的配置错误, 建立基于策略的治理,以及将 IaC 扫描集成到 CI/CD 管道中以防止不安全的云资源配置。
-
killvxk Bundle Implementing Image Provenance Verification With Cosign使用 Sigstore Cosign 进行容器镜像来源签名与验证,支持基于 OIDC 的无密钥签名、证明附件及 Kubernetes 准入强制执行。
-
killvxk Bundle Implementing Privileged Identity Management With Azure使用 Microsoft Graph API 配置 Azure AD 特权身份管理(PIM),管理符合条件的角色分配、即时激活、访问审查,以及用于零信任特权访问的角色管理策略。
-
killvxk Bundle Performing GCP Penetration Testing With Gcpbucketbrute使用 GCPBucketBrute 执行 GCP 安全测试,进行存储桶(Storage Bucket)枚举、gcloud IAM 权限提升路径分析和服务账号权限审计。
-
killvxk Bundle Implementing Deception Based Detection With Canarytoken通过 Thinkst Canary API 部署和监控金丝雀令牌,使用 Web Bug 令牌、DNS 令牌、文档令牌和 AWS 密钥令牌实现基于欺骗的入侵检测。
-
sheshiyer Bundle CloudflareDeploy and manage Cloudflare Workers, MCP servers, and Pages, with auth-token gotchas baked in. USE WHEN deploying a Worker or MCP server, publishing a Pages site, or debugging a Cloudflare deploy/auth failure.
-
jiayaoqijia Bundle Silverback Defi InfraSilverback
-
jiayaoqijia Bundle Wazuh Agent DockerChainstack - wazuh-agent-docker
-
sheshiyer Skill File UploadsHandle file uploads and cloud storage safely: S3, Cloudflare R2, presigned URLs, multipart uploads, content-type validation, and image optimization without blocking. USE WHEN an app or agent must accept user file uploads or stream large files to object storage.
-
sheshiyer Skill Conducty ShipPre-merge / pre-deploy gate. Runs the full ship-readiness battery — lint, typecheck, test suite, secrets scan, dependency-vulnerability check, [[conducty-code-review]] verdict — and writes a `Ship Reports/Ship Report YYYY-MM-DD HHmm.md` note with a single-word verdict. Use when the user says "ship it", "is this ready", "ship gate", "pre-merge check", "ready to merge", or after [[conducty-code-review]] passes.
-
sheshiyer Skill GCP Cloud RunProduction-ready serverless on GCP — Cloud Run services (containerized), Cloud Run Functions (event-driven), cold-start optimization, and Pub/Sub event architecture. USE WHEN deploying or tuning Cloud Run containers/functions or wiring Pub/Sub-driven workloads on GCP.
-
sheshiyer Skill Neon PostgresExpert patterns for Neon serverless Postgres — branching, connection pooling, and Prisma/Drizzle integration. USE WHEN running Postgres on Neon, setting up per-PR/preview DB branches, or wiring the serverless driver/pooler from a serverless or edge app.
-
sheshiyer Skill Selemene CoreShared reference for the Selemene cluster: the two report surfaces (deterministic Rust reports vs. narrative witness-pipeline readings), the @selemene/bridge CLI contract, the output manifest format, and non-prescriptive witnessing tone. USE WHEN deciding which Selemene surface to invoke or when routing between birth/compatibility/transit reports and solo/dyadic readings.
-
sheshiyer Skill AWS ServerlessProduction-ready serverless on AWS — Lambda, API Gateway, DynamoDB, SQS/SNS event-driven patterns, SAM/CDK deployment, and cold-start optimization. USE WHEN building, deploying, or tuning AWS serverless apps (Lambda handlers, event pipelines, DynamoDB access, cold starts).
-
sheshiyer Skill Media Gen CoreShared reference for the media-gen cluster: the backend-routing decision (access/billing model × modality), the generate→transform→assemble pipeline, output-format conventions, and the cross-tool guardrails. USE WHEN choosing an image/video/3D/GIF backend, planning a multi-stage media pipeline, or reasoning about cost, format, or provider policy.
-
sheshiyer Bundle Secret ScannerScan codebases for leaked secrets, API keys, and credential exposure patterns. USE WHEN before pushing to a public repo, during a security audit, or wiring secret detection into CI/CD.
-
sheshiyer Skill Upstash QstashUpstash QStash expert for serverless message queues, scheduled jobs, and reliable HTTP-based task delivery without managing infrastructure. USE WHEN you need serverless cron, webhook delivery with retries/signature verification, delayed jobs, or HTTP-based message queuing via QStash.
-
sheshiyer Skill Azure FunctionsAzure Functions patterns — isolated worker model, Durable Functions orchestration, cold-start optimization, production hardening across .NET, Python, and Node.js. USE WHEN building, orchestrating, or optimizing Azure Functions apps (durable workflows, triggers/bindings, cold starts).
-
sheshiyer Skill Cloudflare CoreShared reference for the Cloudflare cluster: the edge-compute + binding model every Worker turns on, wrangler.jsonc conventions, compatibility_date, the storage-primitive decision matrix (KV vs R2 vs D1 vs Durable Objects), secrets, and the auth-token gotcha. USE WHEN adding a binding, choosing a storage primitive, writing wrangler config, or debugging a Cloudflare deploy — the interlocking rules every Cloudflare spoke shares.
-
sheshiyer Skill Git Pr Ops CoreShared reference for the git-pr-ops cluster: the gated review→prepare→merge pipeline, the `.local/` artifact handoff (review.json findings), head-SHA pinning, the push/merge safety rules (force-with-lease, no auto-merge, never push main), and the finding-severity contract. USE WHEN preparing or merging a GitHub PR, resolving review findings, or wiring the issue→PR flow — the interlocking rules every spoke shares.
-
sheshiyer Skill Healthcare CoreShared reference for the healthcare cluster: the three-layer data-protection contract (classify → access-control → audit), the patient-safety bias (alerts block, never silently pass), the alert-severity matrix, and the CRITICAL-vs-HIGH deploy-gate thresholds. USE WHEN handling PHI, designing clinical access control, wiring a CDSS alert, or configuring a safety gate — the interlocking rules every healthcare spoke shares.
-
sheshiyer Bundle Selemene ReportGenerate Selemene Engine reports from a slash-command. Routes deterministic birth/compatibility/transit reports through the existing @selemene/bridge CLI and narrative witness readings through the packages/witness-pipeline. USE WHEN the user says /selemene-report, selemene report, generate selemene report, birth chart report, compatibility report, transit report, or witness reading. NOT for building new engines, not for replacing the bridge CLI, not for human web UI intake.
-
sheshiyer Skill Terraform SkillTerraform & OpenTofu infrastructure-as-code best practices — module hierarchy, testing (validate/plan/frameworks), multi-environment structure, state management, and CI/CD. USE WHEN authoring, structuring, testing, or reviewing Terraform/OpenTofu configs and modules.
-
sheshiyer Bundle Deploy To VercelDeploy applications and websites to Vercel, preferring git-push preview deploys and proper project linking. USE WHEN the user says deploy my app, push this live, give me a link, or make a preview deployment.
-
sheshiyer Skill PHP Laravel CoreShared reference for the Laravel cluster: the layered request flow (controller → service → action → model), typed Eloquent + Form Request validation, the standard JSON response envelope, the test/CI matrix, and the version/tooling baseline. USE WHEN structuring controllers, writing validation, wiring the test/verify pipeline, or choosing tooling — the conventions every Laravel spoke shares.
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include implementing-fuzz-testing-in-cicd-with-aflplusplus, implementing-privileged-identity-management-with-azure, azure-functions. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.