DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
marktantongco Skill AI Automation WorkflowsBuild automated AI workflows combining multiple models and services. Patterns: batch processing, scheduled tasks, event-driven pipelines, agent loops. Tools: inference.sh CLI, bash scripting, Python SDK, webhook integration. Use for: content automation, data processing, monitoring, scheduled generation. Triggers: ai automation, workflow automation, batch processing, ai pipeline, automated content, scheduled ai, ai cron, ai batch job, automated generation, ai workflow, content at scale, automation script, ai orchestration
Audited -
marktantongco Bundle Building Inferencesh AppsBuild and deploy applications on inference.sh. Use when getting started, understanding the platform, creating apps, configuring resources, or needing an overview of inference.sh app development. Supports both Python and Node.js. Triggers: inference.sh app, belt app, inf.yml, inference.py, inference.js, deploy app, app development, build app, create app, GPU app, VRAM, app resources, app secrets, app integrations, multi-function app
-
gigik2a Skill RAG PipelineProgettazione e valutazione pipeline RAG (Retrieval-Augmented Generation) per knowledge base aziendali di PMI italiane. Copre architettura, chunking, embedding, retrieval strategy, valutazione qualità e casi d'uso pratici.
-
gigik2a Skill Data PipelineProgettazione pipeline dati per PMI: ETL da gestionali italiani, qualità dati, scheduling con n8n/Make, warehouse su Supabase/BigQuery, dashboard operativa. Copertura dati commerciali, produzione, finanza.
-
gigik2a Skill Sales StrategySkill verticale per P01 — Agenti AI Email & CRM. Fornisce knowledge operativa sulla strategia commerciale B2B per PMI italiane. Usare quando il K-BOT deve analizzare pipeline di vendita, cicli commerciali, gestione follow-up, scoring opportunità, o proporre automazioni CRM per accelerare le vendite. Entra nel bundle settoriale insieme a lead-qualification e diagnosi-ai-operativa-pmi.
-
gigik2a Skill API IntegrationIntegrazione API REST e webhook per PMI italiane: connessione gestionali (TeamSystem, Zucchetti, Mago4, Fatture in Cloud), automazione flussi con n8n/Make, mappatura endpoint, gestione autenticazione OAuth2/API key.
-
wgpsec Bundle Post Exploit LinuxLinux 后渗透全流程:信息收集→提权→凭据收集→横向准备。当通过 RCE/webshell/SSH 获取到 Linux shell 后使用。提权覆盖 sudo 滥用、SUID/SGID、Capabilities、Cron 劫持、PATH 劫持、Docker/LXD 组、NFS no_root_squash、可写 /etc/passwd、内核漏洞(DirtyPipe/PwnKit/DirtyCow)、组件提权。无论当前权限是 www-data 还是 root,都应先执行此方法论。任何拿到 Linux shell 后的操作——提权、找凭据、找 flag、准备横向移动——都从这个技能开始
-
wgpsec Skill Browser Xterm InteractionPlaywright Browser MCP 与 xterm.js 终端交互方法论。当需要通过浏览器操作网页内嵌终端、CTF 靶场伪终端、Cloud Shell、在线 IDE 中的终端时使用。覆盖终端内容读取(5 种方法)、命令执行、输出捕获、screenshot 降级策略。只要目标页面中有任何形式的 Web 终端(xterm.js/hterm/jQuery Terminal),就应使用此技能
-
wgpsec Bundle Java File AuditJava 源码文件操作类漏洞审计。当在 Java 白盒审计中需要检测文件相关漏洞时触发。 覆盖 5 类文件风险: 任意文件上传(MultipartFile/Servlet Part/类型绕过)、任意文件读取(NIO/IO流/路径穿越)、 任意文件写入(覆盖配置/WebShell落地)、归档提取漏洞(ZipInputStream/Zip Slip)、文件删除/重命名竞争。 需要 java-audit-pipeline 提供的数据流证据。
-
wgpsec Bundle PHP Audit PipelinePHP 白盒源码安全审计总方法论。当需要对 PHP 项目进行完整的源码安全审计、 或需要系统化的白盒漏洞挖掘流程时触发。 覆盖 5 阶段审计流水线: 路由映射→权限建模→数据流追踪→分类漏洞审计→利用链组装。 核心机制: 证据合约系统(EVID_*)防止 AI 幻觉误报,所有漏洞结论必须有数据流证据支撑。
-
wgpsec Bundle PHP Injection AuditPHP 源码注入类漏洞审计。当在 PHP 白盒审计中需要检测注入类漏洞时触发。 覆盖 6 种注入: SQL 注入(PDO/MySQLi/ORM)、NoSQL 注入(MongoDB)、 命令注入(system/exec/passthru)、LDAP 注入、表达式注入(eval/preg_replace /e)、SSRF。 需要 php-audit-pipeline 提供的数据流证据(EVID_*)作为审计输入。
-
wgpsec Bundle Webshell DeployWebshell 部署与利用方法论。当漏洞利用需要上传/写入 webshell 到目标服务器时使用。覆盖 JSP/PHP/ASPX webshell 生成、HTTP PUT 上传(含绕过技巧)、文件上传表单、日志注入+LFI 写入,以及 webshell 验证和利用。当发现文件上传漏洞、PUT 方法可用、LFI 可利用、或需要在目标部署持久化命令执行入口时,都应使用此 skill
-
wgpsec Bundle Argocd TacticsArgoCD 后渗透方法论:Redis缓存投毒集群接管、SSO认证绕过、未授权API枚举、恶意Application部署、Webhook SSRF、默认凭据利用。 当用户提到ArgoCD漏洞、ArgoCD利用、ArgoCD RCE、ArgoCD Redis、ArgoCD未授权、ArgoCD检测、GitOps安全时,必须使用此技能。 也适用于用户提到K8s持续交付、Kubernetes GitOps、ArgoCD集群接管、ArgoCD缓存投毒等场景。
-
wgpsec Bundle Java Audit PipelineJava 白盒源码安全审计总方法论。当需要对 Java 项目进行完整的源码安全审计、 或需要系统化的白盒漏洞挖掘流程时触发。 覆盖 5 阶段审计流水线: 路由映射→权限建模→数据流追踪→分类漏洞审计→利用链组装。 核心机制: 证据合约系统(EVID_*)防止 AI 幻觉误报,所有漏洞结论必须有数据流证据支撑。
-
wgpsec Bundle Supply Chain Audit供应链安全审计与攻击。当指纹识别发现 WordPress/Jenkins/Struts/Django 等已知框架、或发现 /package.json /composer.json /package-lock.json /Gemfile 等依赖声明文件时使用。也适用于发现 CI/CD 构建系统(Jenkins/GitLab CI/OpsFlow)、私有镜像仓库(Harbor/Nexus/Verdaccio)、或题目涉及供应链投毒/dependency confusion 场景。框架和组件版本直接关联 CVE——这是利用链的第一步,也是最容易忽略的攻击面
-
wgpsec Bundle Java Framework AuditJava 框架特定漏洞源码审计。当在 Java 白盒审计中需要检测框架层面的已知漏洞模式时触发。 覆盖 5 大框架/组件: Spring 全家桶(SpEL/Actuator/参数绑定/Spring Cloud Gateway)、 Struts2(OGNL/ActionMapping/Content-Type 解析)、Shiro(RememberMe 反序列化/URI 绕过)、 FastJSON/Jackson/Gson(反序列化 autotype/polymorphic)、MyBatis(${} 注入/动态 SQL)。 这些是 Java 生态中出现频率最高、影响面最广的框架级漏洞。
-
wgpsec Bundle Java Injection AuditJava 源码注入类漏洞审计。当在 Java 白盒审计中需要检测注入类漏洞时触发。 覆盖 6 种注入: SQL 注入(JDBC/MyBatis/Hibernate/JPA)、命令注入(Runtime.exec/ProcessBuilder)、 SSRF(HttpURLConnection/OkHttp/RestTemplate)、LDAP 注入、SpEL/OGNL 表达式注入、NoSQL 注入(MongoDB)。 需要 java-audit-pipeline 提供的数据流证据(EVID_*)作为审计输入。
-
wgpsec Bundle Supply Chain Attack软件供应链攻击方法论。当目标使用 npm/PyPI/Maven 等包管理器、有私有仓库、使用 CI/CD Pipeline 时使用。覆盖 Dependency Confusion、Typosquatting、恶意包发布、CI/CD 投毒、构建服务器攻击
-
wgpsec Bundle Subdomain Takeover子域名接管检测与利用方法论。当目标存在悬挂 CNAME/NS/MX 记录指向已停用的云资源、过期第三方服务或未认领 SaaS 租户时使用。覆盖 CNAME 接管(S3/GitHub Pages/Heroku/Azure/Shopify/Fastly 等 14+ 供应商)、NS 接管(全域控制)、MX 接管(邮件拦截)、通配符 DNS 风险、接管后影响评估(cookie/CORS/CSP/OAuth/TLS)。任何涉及子域名资产清理、DNS 记录审计、域名安全评估的场景都应使用此 skill
-
wgpsec Bundle Concourse TacticsConcourse CI 渗透测试与利用。当发现目标运行 Concourse CI 实例、获取 Fly CLI 凭据或 API Token、需要从 Concourse Pipeline 窃取凭据或注入恶意任务时使用。覆盖未授权访问、Pipeline 变量与私有密钥窃取、Job 篡改、Resource 凭据提取(Git/S3/Docker)、Task 脚本注入、Build 日志窃取、Worker 利用、容器逃逸、Pipeline 后门持久化
Audited -
wgpsec Bundle Portainer TacticsPortainer 后渗透方法论:默认凭据认证突破、用户枚举时间差攻击、Docker API特权容器逃逸RCE、宿主机文件系统挂载。 当用户提到Portainer漏洞、Portainer RCE、Portainer Docker逃逸、Portainer认证绕过、Portainer利用、Portainer检测时,必须使用此技能。 也适用于用户提到Docker管理面板漏洞、容器管理平台利用、Portainer CE/BE渗透等场景。
-
wgpsec Bundle Terraform TacticsTerraform 状态文件与基础设施即代码攻击。当发现目标使用 Terraform 管理基础设施、找到 terraform.tfstate 文件、可访问远程 State 后端(S3/Consul/HTTP)、或可修改 Terraform 代码仓库时使用。覆盖 State 文件凭据提取、远程 State 后端利用、Provider 凭据窃取、Output 敏感值提取、tfvars 变量文件利用、恶意资源注入、State 篡改、Module 供应链攻击、CI/CD Pipeline 利用
-
wgpsec Bundle PHP Serialization AuditPHP 源码序列化与模板类漏洞审计。当在 PHP 白盒审计中需要检测反序列化、XML 解析或模板注入漏洞时触发。 覆盖 3 类风险: PHP 反序列化(unserialize/phar 反序列化/POP 链构造)、 XXE(XML 外部实体注入/libxml 配置)、SSTI(模板注入/Twig/Blade/Smarty 引擎)。 需要 php-audit-pipeline 提供的数据流证据。
-
wgpsec Skill Webshell ManagementWebshell 部署后的 CLI 交互与深度利用。当 webshell 已经上传成功、需要通过 curl/python 执行命令、传输文件、建立加密通信、绕过 disable_functions/open_basedir、或做权限维持时使用。本 skill 与 webshell-deploy 互补——deploy 负责生成和上传 webshell,本 skill 负责上传成功后的所有操作。纯命令行操作,不依赖 GUI 工具
-
wgpsec Bundle Servicemesh TacticsService Mesh 攻击方法论(Istio/Linkerd/Envoy)。当目标 Kubernetes 集群部署了 Service Mesh、发现 istio-system/linkerd 命名空间、Envoy Sidecar 注入、或需要利用服务网格进行横向移动时使用。覆盖 Istio 配置窃取、Gateway 攻击、Sidecar 注入滥用、Envoy Admin 接口利用、Service-to-Service 横向移动、Linkerd 攻击、TLS 证书窃取、AuthorizationPolicy 绕过、Telemetry 日志利用
-
wgpsec Bundle Elasticsearch AttackElasticsearch 未授权访问与利用。当发现目标开放 9200/9300 端口、Elasticsearch 服务无认证、需要从 ES 获取索引数据或实现远程命令执行时使用。覆盖未授权访问、认证绕过、索引数据窃取、MVEL/Groovy 脚本 RCE(旧版本)、快照仓库滥用、集群信息泄露、动态脚本注入、Ingest Pipeline 滥用、路径穿越
-
wgpsec Bundle Expression Language Injection表达式语言(EL)注入方法论。当目标使用 Spring(SpEL)、Struts2(OGNL)、Confluence(OGNL)、JSP/JSF(Java EL) 且存在用户可控的表达式求值时使用。覆盖多语法探测与区分(${7*7}/#{7*7}/%{7*7})、SpEL RCE(Runtime.exec/ProcessBuilder/反射绕沙箱)、Spring Cloud Gateway CVE-2022-22947、OGNL RCE(_memberAccess 操纵/OgnlUtil 黑名单清除)、Struts2 经典 CVE(S2-045/S2-046/S2-016/S2-057)、Confluence CVE-2021-26084、Java EL RCE。任何涉及 Spring/Struts2/Confluence/JSF 框架的表达式注入测试都应使用此 skill
-
pixartseu Bundle Ml PipelineDesigns and implements production-grade ML pipeline infrastructure: configures experiment tracking with MLflow or Weights & Biases, creates Kubeflow or Airflow DAGs for training orchestration, builds feature store schemas with Feast, deploys model registries, and automates retraining and validation workflows. Use when building ML pipelines, orchestrating training workflows, automating model lifecycle, implementing feature stores, managing experiment tracking systems, setting up DVC for data versioning, tuning hyperparameters, or configuring MLOps tooling like Kubeflow, Airflow, MLflow, or Prefect.
-
pixartseu Bundle Cloud ArchitectDesigns cloud architectures, creates migration plans, generates cost optimization recommendations, and produces disaster recovery strategies across AWS, Azure, and GCP. Use when designing cloud architectures, planning migrations, or optimizing multi-cloud deployments. Invoke for Well-Architected Framework, cost optimization, disaster recovery, landing zones, security architecture, serverless design.
-
pixartseu Bundle Terraform EngineerUse when implementing infrastructure as code with Terraform across AWS, Azure, or GCP. Invoke for module development (create reusable modules, manage module versioning), state management (migrate backends, import existing resources, resolve state conflicts), provider configuration, multi-environment workflows, and infrastructure testing.
-
pixartseu Bundle Salesforce DeveloperWrites and debugs Apex code, builds Lightning Web Components, optimizes SOQL queries, implements triggers, batch jobs, platform events, and integrations on the Salesforce platform. Use when developing Salesforce applications, customizing CRM workflows, managing governor limits, bulk processing, or setting up Salesforce DX and CI/CD pipelines.
-
pixartseu Bundle DockerDocker MCP - gestione container Coolify, debug log, ispezione deployment, monitor risorse. Use when inspecting containers, debugging deployments, reading logs, or monitoring resource usage via Docker MCP.
-
pixartseu Bundle CoolifyCoolify deployment knowledge base - Docker multi-stage builds, CI/CD, SSL, health checks. Use when deploying to Coolify, setting up Docker containers, configuring CI/CD pipelines, or managing SSL certificates.
-
pixartseu Bundle Webgpu TslWebGPU + Three.js TSL (Three Shading Language) knowledge base — WebGPURenderer, node-based materials, MeshBasicNodeMaterial / MeshStandardNodeMaterial, compute shaders via Fn(), node operators (mix, fract, sin, attribute/uniform helpers), WGSL bridges, feature detection and WebGL2 fallback. Use when targeting modern GPUs with compute, replacing GLSL ShaderMaterial with TSL nodes, writing first WebGPU shader, or porting effects to Three.js's WebGPU pipeline.
-
pixartseu Bundle Shopify AppsSviluppo di app Shopify embedded nell'admin — Polaris, App Bridge, Admin GraphQL API, session token, webhook, billing, extension. ATTIVARE SEMPRE quando l'utente menziona "app Shopify", "app embedded", "Polaris", "App Bridge", "shopify app init", "shopify app dev", "shopify app deploy", "shopify.app.toml", "access scope", "OAuth Shopify", "session token", "Admin API", "admin GraphQL", "authenticate.admin", "app extension", "admin action", "admin block", "webhook Shopify", "billing API", "Built for Shopify", "App Store Shopify", "custom app", "app proxy", "s-page", "s-section", "polaris web components". Attivare anche senza queste parole quando la richiesta descrive uno strumento per il merchant dentro il pannello Shopify - "una schermata nell'admin per gestire X", "un pannello dove il cliente configura Y", "sincronizzare ordini Shopify col gestionale", "automatizzare qualcosa lato backoffice". NON è la skill per la vetrina - quella è shopify-storefront o shopify-themes.
-
pixartseu Skill File HandlingFile handling patterns — S3/R2/Vercel Blob storage, PDF generation, CSV/Excel import-export, file streaming, presigned URLs, multipart upload. Use when implementing file uploads to cloud storage, generating documents, processing large files, or building download endpoints.
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include browser-xterm-interaction, post-exploit-linux, java-file-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.