DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
dnyoussef Bundle Agentdb Learning PluginsCreate AI learning plugins using AgentDBs 9 reinforcement learning algorithms. Train Decision Transformer, Q-Learning, SARSA, and Actor-Critic models. Deploy these plugins to build self-learning agents, implement RL workflows, and optimize agent behavior through experience. Apply offline RL for safe learning from logged data.
Audited -
dnyoussef Bundle Agentdb Performance OptimizationApply quantization to reduce memory by 4-32x. Enable HNSW indexing for 150x faster search. Configure caching strategies and implement batch operations. Use when optimizing memory usage, improving search speed, or scaling to millions of vectors. Deploy these optimizations to achieve 12,500x performance gains.
Audited -
fluxonlab Skill Bats Testing PatternsMaster Bash Automated Testing System (Bats) for comprehensive shell script testing. Use when writing tests for shell scripts, CI/CD pipelines, or requiring test-driven development of shell utilities.
-
fluxonlab Skill CI CD Pipeline ReviewUse when you need to review CI jobs, workflow triggers, caches, matrixes, artifacts, and safe release gates.
-
fluxonlab Skill Cloud Spend ReviewUse when you need to review cloud spend for waste — rightsizing over-provisioned compute, finding idle and orphaned resources, storage tiering, data egress charges, reserved/spot/committed-use discounts, cost-allocation tagging, and cost-anomaly alerting.
-
fluxonlab Skill Data Pipeline ReviewUse when you need to review or design an ETL/ELT data pipeline for idempotency, incremental loads, orchestration (Airflow/Dagster/cron), backfill safety, partitioning, and failure recovery.
-
fluxonlab Skill Terraform Iac ReviewUse when you need to review Terraform or OpenTofu infrastructure-as-code for remote state and locking correctness, module structure, drift, plan safety, hardcoded secrets, provider pinning, and least-privilege IAM before any apply.
-
fluxonlab Skill Supabase Rls Edge FunctionsUse when implementing or auditing Supabase Row Level Security policies, Edge Functions (Deno), Realtime subscriptions, or Storage RLS — including auth.uid() policy patterns, service_role risk management, and the Supabase CLI deploy workflow.
-
fluxonlab Skill Docker Image HardeningUse when you need to review or author a Dockerfile for multi-stage builds, minimal or distroless base images, non-root runtime, layer caching, .dockerignore hygiene, pinned digests, image vulnerability scanning, and SBOM generation.
-
fluxonlab Bundle Python Pypi Package BuilderEnd-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI. Covers all four build backends (setuptools+setuptools_scm, hatchling, flit, poetry), PEP 440 versioning, semantic versioning, dynamic git-tag versioning, OOP/SOLID design, type hints (PEP 484/526/544/561), Trusted Publishing (OIDC), and the full PyPA packaging flow. Use for: creating Python packages, pip-installable SDKs, CLI tools, framework plugins, pyproject.toml setup, py.typed, setuptools_scm, semver, mypy, pre-commit, GitHub Actions CI/CD, or PyPI publishing.
-
fluxonlab Skill Godot Unity Unreal TriageUse when you need to triage Godot, Unity, Unreal, shader, engine, and asset pipeline issues.
-
fluxonlab Skill Ml Training Pipeline ReviewUse when you need to review an ML training pipeline for reproducibility, data/train/val/test splitting, data leakage, checkpointing, and experiment tracking (MLflow/W&B).
-
fluxonlab Skill Kubernetes Manifest ReviewUse when you need to review or author Kubernetes manifests or Helm charts for resource requests and limits, liveness/readiness/startup probes, pod security context, RBAC scope, network policy, HPA, secret handling, and common workload anti-patterns.
-
fluxonlab Skill Cloud Service ArchitectureUse when you need to choose or review cloud architecture decisions — managed vs self-hosted services, multi-AZ high availability, scaling strategy, VPC/subnet/network design, least-privilege service roles, and cost-aware tradeoffs.
-
fluxonlab Skill Gamedev Team UIOrchestrate the UI team through the full UX pipeline: from UX spec authoring through visual design, implementation, review, and polish. Integrates with /ux-design, /ux-review, and studio UX templates.
-
fluxonlab Skill Deploy Topology And RollbackUse when you need to review or design a deployment topology and rollback strategy — blue-green, canary, and rolling deploys, health gates, automated rollback, zero-downtime cutover, and safe infrastructure change sequencing.
-
fluxonlab Skill Secrets And Config ManagementUse when you need to review or design secret and configuration handling — secret managers (Vault, AWS Secrets Manager, SSM, GCP/Azure), rotation, runtime injection, keeping secrets out of IaC and images, sealed/external secrets, and config-vs-secret separation.
-
fluxonlab Skill Gamedev Team AudioOrchestrate audio team: audio-director + sound-designer + technical-artist + gameplay-programmer for full audio pipeline from direction to implementation.
-
26zl Bundle Sarif ParsingParses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan results", "aggregate findings", "deduplicate alerts", or "process sarif output". Handles filtering, deduplication, format conversion, and CI/CD integration of SARIF data. Does NOT run scans — use the Semgrep or CodeQL skills for that.
Audited -
26zl Skill Offensive SqliSQL injection testing skill for offensive security assessments and bug bounty hunting. Covers error-based, UNION-based, boolean/time-based blind, out-of-band, second-order, NoSQL, GraphQL, WebSocket, and JSON-operator SQLi. Includes WAF bypass techniques, database-specific exploitation (MySQL, MSSQL, PostgreSQL, Oracle), cloud-native attack paths, ORM CVE tracking, and SQLmap automation. Use when performing web application SQL injection testing, database enumeration, privilege escalation via SQLi, or assessing injection vectors in APIs and modern stacks. Use only for authorized security research, training, or assessment.
-
davidcastagnetoa Bundle Opentelemetry JaegerTrazabilidad distribuida del pipeline KYC para identificar cuellos de botella y depurar incidencias
-
davidcastagnetoa Bundle Trace Id PropagationPropagación de trace IDs a través de microservicios del pipeline KYC para correlación de logs y métricas.
-
davidcastagnetoa Bundle Trivy Image ScanningEscanear imágenes Docker en busca de vulnerabilidades CVE antes de desplegar
-
davidcastagnetoa Bundle Webrtc Media DevicesAcceso a cámara en vivo desde web bloqueando galería — base del pipeline de captura
-
davidcastagnetoa Bundle Docker Docker ComposeContenerización de todos los servicios y entorno de desarrollo local reproducible con Docker Compose
-
davidcastagnetoa Bundle Fp16 Int8 QuantizationCuantización de modelos ML a FP16/INT8 para reducir memoria y acelerar inferencia en el pipeline KYC
-
davidcastagnetoa Bundle Log Retention PoliciesPolíticas de retención de logs diferenciadas por tipo y sensibilidad para el pipeline KYC.
-
davidcastagnetoa Bundle Alertmanager StandaloneAlertmanager independiente para routing de alertas del pipeline KYC con integraciones externas
-
davidcastagnetoa Bundle Breaking Change DetectorDetectar automáticamente breaking changes entre versiones de schema en CI/CD
-
davidcastagnetoa Bundle HTTP Health Check ProbesEndpoints HTTP de health check para microservicios del pipeline KYC con reporte de dependencias
-
davidcastagnetoa Skill Chaos EngineeringDisciplina de ingeniería del caos para validar resiliencia del pipeline KYC mediante experimentos controlados
-
davidcastagnetoa Bundle Prometheus Metrics ExporterExportar métricas del API Gateway KYC al formato Prometheus para monitorización del pipeline de verificación.
-
davidcastagnetoa Bundle Kubernetes Liveness Readiness ProbesConfiguracion de probes de Kubernetes para pods del pipeline KYC con timeouts adaptados a servicios ML
-
wgpsec Bundle Ctf MiscCTF 杂项挑战技术。当遇到编码谜题、Python/Bash 沙箱逃逸、RF/SDR 信号、游戏/VM 逆向、K8s RBAC、浮点数技巧、Z3 约束求解、博弈论等不属于 pwn/crypto/web/reverse/forensics/osint 的 CTF 挑战时使用。先排除其他分类后再使用本技能
-
wgpsec Skill K8spider使用 k8spider 进行 Kubernetes 集群 DNS 服务发现与侦察。当需要低权限枚举 K8s 集群中的 Service、探测 DNS 服务、扫描网段 PTR/SRV 记录、尝试 AXFR 区域传输时使用。k8spider 仅需 DNS 访问权限即可发现集群内所有服务,无需 API Server 权限。涉及 K8s 服务发现、DNS 侦察、集群信息收集、PTR 扫描、SRV 枚举的场景使用此技能。当用户提到 k8spider、K8s DNS 枚举、集群服务扫描、DNS 区域传输时也应触发
-
wgpsec Skill Cdk Escape使用 CDK 进行容器环境渗透和逃逸。当已进入容器环境(Docker/K8s Pod)需要评估逃逸可能性、利用容器漏洞、或进行容器内信息收集时使用。CDK 集成了容器环境评估、多种逃逸技术(privileged/mount/cgroup/lxcfs/runc/内核漏洞)、容器内横向移动。拿到容器 shell 后第一步就应该运行 CDK 评估。涉及容器逃逸、Docker 渗透、K8s 安全、容器提权的场景使用此技能
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include terraform-iac-review, alertmanager_standalone, bats-testing-patterns. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.