DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
purpleailab Skill Container CveHigh-impact container-runtime CVE catalog — runC Leaky Vessels (CVE-2024-21626/-23651/-23652/-23653), CVE-2022-0185 (FUSE/legacy-fs), CVE-2019-5736 (runC binary replace), CRI-O Dirty COW analogs, Kubernetes API server CVE-2019-11247 (custom-resource RBAC bypass). Fingerprint → match → exploit.
-
purpleailab Skill M365 Mailbox CompromiseMicrosoft 365 mailbox compromise chain — OAuth consent phishing, delegate access abuse, mail rule persistence, and token theft via device code phishing. Full kill chain from initial access to persistent email collection.
-
purpleailab Skill Web Waf DetectionWeb Application Firewall fingerprinting — Cloudflare, AWS WAF, Akamai, Imperva, etc.
-
purpleailab Skill K8S Pod EscapeKubernetes pod escape to node — privileged container abuse, hostPath mount escape, hostPID/hostIPC, capability misuse (SYS_ADMIN, SYS_PTRACE), runC CVE chains. Pivots from RCE-in-pod to full node compromise.
-
purpleailab Skill K8S Rbac AbuseKubernetes RBAC privilege escalation paths — ClusterRole/Role enumeration via `kubectl auth can-i --list`, abuse of pods/exec, pods/portforward, secrets get, escalate verb, bind verb, impersonate verb, system:masters group abuse, ServiceAccount token theft and reuse.
Audited -
purpleailab Skill Cicd Secrets ExfilExtracting CI secrets / OIDC tokens once you have code execution in a build job — echo/printenv exfil, log-masking bypass (base64, char-split, reversal), OIDC token abuse to assume cloud roles, GITHUB_TOKEN / CI_JOB_TOKEN scope abuse, cache / artifact secret leakage, provenance pivot.
-
purpleailab Skill C2 Domain FrontingDomain fronting and CDN abuse for C2 concealment — CloudFront, Azure CDN, Fastly setup, TLS SNI vs Host header technique, CDN-based redirectors, and integration with Cobalt Strike and Sliver.
Audited -
purpleailab Skill Entra Device Code PhishingEntra ID OAuth device-code phishing for token theft, illicit consent grant via malicious app registration with delegated Graph scopes, refresh-token replay, and primary-refresh-token (PRT) abuse concepts.
-
purpleailab Skill Dep ConfusionDependency confusion — publish a higher-version internal package name on public registry (npm/PyPI/Maven/Crates) to coerce CI/CD into pulling attacker code.
-
purpleailab Skill Web Subdomain TakeoverSubdomain takeover via dangling DNS/CNAME — GitHub Pages, Heroku, Azure, Fastly, Shopify, Netlify, Surge, Tumblr, Beanstalk, Zendesk, etc.
-
purpleailab Skill Docker Socket MountDocker / containerd socket mounted into a container → host RCE. Common in CI runners, GitOps controllers (ArgoCD, Flux), and 'Docker-in-Docker' setups. Single-command escape via `docker run --rm --privileged -v /:/host alpine chroot /host`.
-
purpleailab Skill GCP Svc Account ImpersonationGCP service account impersonation chain — IAM `roles/iam.serviceAccountTokenCreator`, `roles/iam.serviceAccountUser`, `actAs` on Cloud Functions / Cloud Run / Compute Engine. Pivot from low-priv SA to org-admin via chained impersonation.
-
purpleailab Skill C2 Alternative ChannelsNon-traditional C2 channels — Discord/Telegram bots, DNS-over-HTTPS, blockchain-based C2, email-based C2, and cloud function dead drops for covert command and control.
Audited -
purpleailab Skill Entra Conditional Access BypassEntra Conditional Access bypass — discover policy gaps, exploit legacy-auth protocols (IMAP/POP/SMTP-AUTH/EWS), spoof device/platform/UA/location conditions, abuse service-principals + app-based auth excluded from CA, and break-glass account misuse.
-
purpleailab Skill Self Hosted Runner AbuseSelf-hosted runner abuse — non-ephemeral runner persistence, fork-PR job execution on self-hosted, runner-label targeting, secret/token theft from runner env, lateral movement from runner into internal network and cloud metadata services.
-
purpleailab Skill Poisoned Pipeline ExecutionPoisoned Pipeline Execution (PPE) — direct + indirect: inject commands via attacker-controllable build files (Makefile, package.json scripts, build.gradle, Dangerfile, .pre-commit-config.yaml), abuse pull_request_target / fork-PR triggers, and ride dependency / test-script execution on CI.
-
purpleailab Skill Apt29APT29 (Cozy Bear / Midnight Blizzard, SVR) adversary-emulation playbook — malware-light cloud-identity espionage: no-MFA password spray, OAuth consent/token abuse, Golden SAML, mailbox collection over residential proxies. Use when emulating APT29 against an M365/Entra/AWS-identity estate. Triggers on: 'emulate APT29', 'Cozy Bear', 'Midnight Blizzard', 'NOBELIUM', 'OAuth abuse', 'cloud identity espionage', 'Golden SAML'.
Audited -
purpleailab Skill Emulation Scattered SpiderScattered Spider (UNC3944 / Octo Tempest) adversary-emulation playbook — help-desk vishing → MFA takeover → cloud/SaaS/identity privilege expansion → RMM persistence → data-theft extortion. Use when emulating identity-first social-engineering eCrime against a help-desk/IdP estate. Triggers on: 'emulate Scattered Spider', 'UNC3944', 'Octo Tempest', '0ktapus', 'help desk social engineering', 'MFA fatigue', 'SIM swap', 'identity attack'.
Audited -
netvar1337 Bundle Cloud K8SUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
-
netvar1337 Bundle C2 TradecraftC2 / command-and-control tradecraft for authorized red-team and adversary-simulation work: implant-beacon architectures, C2 protocol design, listener/redirector setup, OPSEC-aware egress, and evasion vs EDR/network detection. Use when the operator asks to stand up or extend C2 infrastructure, deploy or debug beacons/implants, design C2 channels (DNS/HTTPS/websocket/ICMP), or tune detection evasion for C2 traffic.
-
netvar1337 Bundle Ags Graphics APIGuide for graphics API interception, overlay rendering, and render-pipeline analysis across DirectX, OpenGL, and Vulkan. Use this skill when working with Present or SwapBuffers hooks, DXGI swap chains, shader or draw-call interception, screenshot-sensitive overlays, or graphics debugging in game security research.
-
netvar1337 Bundle Microsoft FoundryBuild, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end with azd. USE FOR: azd ai agent, azd provision/deploy, hosted agent scaffold/develop/run/deploy, prompt agent create, create agent, update agent, add tool to agent, invoke agent, agent.yaml, evaluate agent, batch eval, continuous eval, continuous monitoring, agent CI/CD, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions, Agent Optimizer scaffold, dataset curation from traces, deploy model, model fine-tuning (SFT/DPO/RFT), Foundry project, RBAC, role assignment, permissions, quota, capacity, region, troubleshoot agent, deployment failure, AI Services, create Foundry resource, knowledge index, customize deployment, onboard, availability, training-data, grader, distillation, fine-tuned model, large file upload. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).
Audited -
netvar1337 Bundle Supply Chain SecurityUse for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
-
netvar1337 Bundle Cheat Longevity EngineeringEngineering cheats for longevity under AC: minimize ban surfaces, feature risk tiers, OPSEC build/deploy, silent flags, update cadence.
-
netvar1337 Skill Hack Skills Subdomain TakeoverSubdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointing to deprovisioned cloud resources, expired third-party services, or unclaimed SaaS tenants that an attacker can register to serve content under the victim's domain.
-
netvar1337 Bundle Router Reverse Skill Router Cloud K8SUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
-
netvar1337 Bundle Offensive CloudUse when assessing AWS, Azure, or GCP security: identity enumeration, IAM privilege paths, cloud resource exposure, persistence review, lateral movement, serverless risks, and evidence-driven reporting.
-
netvar1337 Skill Advanced Redteam OpsUse when designing C2 infrastructure or OPSEC for a long-haul red-team op — redirectors, malleable profiles, tiered/segregated infra, living-off-the-land, data exfiltration
-
netvar1337 Bundle Router Reverse Skill Router Edr Bypass ReUse when reverse engineering and measuring EDR, Defender, AV, or XDR behavior pinned to a Windows build, vendor, sensor, and policy: user-mode hooks, kernel callbacks, minifilters, WFP, ETW/ETW-TI, AMSI, memory scanners, and cloud ingestion. Treat unhooking, direct or indirect syscalls, ETW/AMSI patches, call-stack spoofing, sleep masks, and process injection as falsifiable bypass hypotheses with sensor-health, clean-baseline, positive-control, event-loss, delayed-verdict, and rollback evidence. Maps to MITRE ATT&CK T1562 Defense Evasion. Trigger keywords: EDR bypass, AV bypass, AV evasion, unhook, direct syscall, indirect syscall, Hell's Gate, Halo's Gate, Tartarus Gate, ETW patch, AMSI patch, call stack spoofing, hardware breakpoint Blindside, MITRE T1562, ntdll unhook, kernel callback, CrowdStrike bypass, Defender bypass, Sentinel One bypass, Elastic Defend, Sysmon evasion, PPID spoof, Sleep mask, Process Hollowing, Reflective DLL, sensor health, minifilter, WFP, XDR.
-
ur-grue Bundle Cover Image PipelineGenerates a complete, coordinated set of image prompts for a cover image concept across multiple formats and crop ratios — so a single visual idea produces consistent, properly composed assets for podcast artwork, YouTube thumbnails, newsletter headers, and social media simultaneously.
-
wufufu770 Skill Performing Docker Bench Security AssessmentPerform performing docker bench security assessment assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Integrating Dast With Owasp Zap In PipelineIntegrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration aga…
Audited -
wufufu770 Skill Auditing Kubernetes Rbac Privilege EscalationPerform auditing kubernetes rbac privilege escalation assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Performing Serverless Function Security ReviewPerform performing serverless function security review assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Performing Kubernetes Etcd Security AssessmentPerform performing kubernetes etcd security assessment assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Performing Container Security Scanning With TrivyScan container images, filesystems, Git repositories, and Kubernetes manifests for OS and language-dependency vulnerabilities, IaC misconfig…
Audited
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include c2-alternative-channels, container-cve, m365-mailbox-compromise. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.