DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
daemon-blockint-tech Bundle CybersecurityGuides enterprise cybersecurity across security architecture, control design, vulnerability and threat management, incident response, identity security, and GRC alignment (SOC 2, ISO 27001, NIST CSF). Use when defining security strategy, assessing risk, designing defense-in-depth, running security incidents, scoping penetration tests, writing security policies, or high-level GRC strategy—not for hands-on audit evidence automation (compliance-engineer), GRC program/audit prep (compliance-specialist), embedding scans in CI/CD (devsecops), provisioning cloud networks (infrastructure-engineer), or LLM or enterprise red team (ai-redteam, red-team-specialist), binary RE (reverse-engineer), web/API pentest (web-pentester), or on-call/SEV program (incident-management-engineer).
-
daemon-blockint-tech Bundle Web PentesterGuides authorized web application and API security testing—scoping and rules of engagement, OWASP-oriented testing (injection, auth/session, access control, SSRF, XSS, CSRF, business logic), REST and GraphQL API security, Burp/ZAP-style manual methodology without requiring commercial tools, evidence and remediation reporting, and retest validation. Emphasizes written authorization and safe boundaries. Use for web pentest, OWASP web assessment, web app security test, API pentest, Burp-style testing, XSS or SQL injection testing when authorized—not network/AD/infra pentest (network-pentester), general multi-domain pentest orchestration (penetration-tester), LLM or agent adversarial testing (ai-redteam), enterprise adversary simulation or purple-team campaigns (red-team-specialist), SOC alert triage (soc-analyst), incident command (incident-responder), or CI/CD security gates and SBOM programs (devsecops).
-
daemon-blockint-tech Bundle Aml ComplianceThis skill should be used when the user asks about AML compliance, anti-money laundering, KYC, CDD, EDD, PEP screening, sanctions screening, transaction monitoring, SAR, STR, suspicious activity, FATF, BSA, financial crime compliance, travel rule, AML risk assessment, or MLRO. Guides risk-based AML/CFT programs, alert triage, SAR narrative structure (not legal filing), governance, crypto AML, and exam readiness—not ISO/SOC only (compliance-engineer), cloud attestations (cloud-compliance-specialist), contracts (commercial-counsel), IT audit workpapers (auditor), FinOps (finops-analyst), SIEM build (information-security-engineer), or blockchain LE investigations (blockint skills).
-
daemon-blockint-tech Bundle CI CD EngineerGuides CI/CD engineering—pipeline design, build/test/deploy stages, branch and environment strategy, artifact promotion, workflow-level deploy patterns (rolling, blue-green, canary), CI secrets, security gates, flaky tests, monorepo/polyrepo layout, DORA metrics, and rollback/release coordination with platform/SRE. Use when designing or fixing delivery pipelines, GitHub Actions, GitLab CI, Jenkins, release automation, deployment gates, or delivery metrics—not app implementation (senior-software-engineer), K8s cluster internals only (cloud-engineer), SRE on-call/SLO programs (site-reliability-engineer), security policy only (information-security-engineer), or IDP/golden paths (platform-engineer). Triggers: CI/CD, continuous integration, continuous delivery, pipeline design, GitHub Actions, deployment pipeline, build and deploy, release pipeline, DORA metrics, canary deployment, pipeline gates.
-
daemon-blockint-tech Bundle Cloud EngineerGuides cloud engineering on AWS, GCP, and Azure—landing zones and account structure, VPC/VNet networking, compute and autoscaling, object/block storage, managed databases and caches, serverless and messaging, DNS/CDN, cloud IAM and workload identity, multi-AZ/region reliability, backups and DR, tagging, cost controls, and service-level troubleshooting. Use when designing or operating cloud resources, wiring private connectivity, rightsizing spend, or debugging control-plane and managed-service failures—not for CI/CD and GitOps (devops), Kubernetes cluster bootstrap and Helm (cluster-deployment-engineer), internal developer platforms (platform-engineer), release cutover strategy (deployment-strategist), security program and IdP/KMS ownership (information-security-engineer), enterprise integration ADRs (senior-system-architecture), or physical data center facilities (data-center-design-execution-lead). Reusable Terraform module libraries: infrastructure-engineer.
-
daemon-blockint-tech Bundle Finops AnalystGuides FinOps analysis on AWS, GCP, and Azure—cost visibility and allocation, tagging and showback/chargeback models, rightsizing and waste removal, RI/Savings Plan/CUD recommendations, budgets and forecasts, anomaly detection, unit economics (cost per service/customer), and FinOps cadence with engineering accountability. Use when optimizing cloud spend, analyzing CUR/billing exports, building cost dashboards, explaining bill spikes, or improving allocation—not for GL mapping, capex, depreciation, or month-end ledger close (compute-accounting-manager), enterprise EA negotiation (enterprise-cloud-architect), hands-on resource provisioning (cloud-engineer), or hardware supply efficiency (data-center-compute-supply-efficiency).
-
daemon-blockint-tech Bundle Iam SpecialistGuides identity and access management—workforce and machine identity lifecycle, RBAC/ABAC/PBAC entitlement design, access reviews and recertification, SSO/SAML/OIDC federation, privileged access (PAM/JIT), cloud IAM least privilege (AWS/GCP/Azure concepts), service accounts and secrets hygiene, and separation of duties. Use for IAM, identity governance, access review, RBAC, least privilege, SSO federation, PAM, privileged access, cloud IAM policy, service account, or SoD—not full cloud landing zone architecture (enterprise-cloud-architect), broad cloud security controls (cloud-security-engineer), day-2 break-glass ticket execution only (cloud-system-administrator), pentest (penetration-tester), or legal/HR policy drafting only.
-
daemon-blockint-tech Bundle Talent SourcerThis skill should be used when the user asks to talent sourcer, source candidates, define a sourcing strategy, run boolean search or X-ray search, conduct LinkedIn sourcing, find passive candidates, build a talent map or talent pool, build a recruiting pipeline, draft recruiting outreach, produce a candidate list, or follow a sourcer playbook for proactive recruiting. Guides role intake and search strategy, platform sourcing (LinkedIn, GitHub, communities), talent mapping and market scans, personalized outreach at scale, pipeline hygiene and CRM notes, diversity sourcing, competitor talent pool analysis, and handoff to recruiters—not interview loop design (interview-prep, interview-system-designer), offer letters (draft-offer), comp bands (comp-analysis), HR policy or employee relations (hr-business-partner), generic B2B prospecting (lead-researcher, account-research, enrich-lead unless explicitly recruiting), employer branding campaigns (cmo-advisor), or end-to-end recruiting ops (talent-acquisition).
-
daemon-blockint-tech Bundle Sd Wan EngineerDesign, deploy, and operate SD-WAN—overlay WAN (hub-spoke, mesh, regional hubs), underlay overlay (MPLS, broadband, LTE/5G), path selection, application-aware routing, SASE, zero trust WAN, branch connectivity, orchestration templates, NGFW/SWG/ZTNA insertion, HA, and brownfield SD-WAN migration; vendor-agnostic (Viptela, VeloCloud, Prisma SD-WAN). This skill should be used when the user asks about SD-WAN, software-defined WAN, SDWAN engineer, overlay WAN, path selection, application-aware routing, hub-spoke SD-WAN, SASE, zero trust WAN, branch connectivity, underlay overlay, VeloCloud, Viptela, Prisma SD-WAN, WAN optimization, or brownfield SD-WAN migration—not carrier BGP/MPLS backbone-only (network-backbone-architect), cloud VPC design (cloud-architect, cloud-engineer), enterprise APIs (enterprise-integration-api-developer), endpoint security program only (information-security-engineer), or physical DC cabling (infrastructure-engineer).
-
daemon-blockint-tech Bundle Reverse EngineerGuides authorized reverse engineering—static and dynamic binary analysis, disassembly and decompilation workflows, protocol and file-format reversing, defensive malware analysis (behavior, IOCs, YARA ideas), firmware RE, patch diffing, and vulnerability research documentation. Emphasizes written authorization, export-control awareness, and no assistance bypassing protections on unowned or unlicensed software. Use for reverse engineering, disassemble, decompile, Ghidra/IDA-style workflows, binary analysis, malware analysis for defense, firmware RE, patch analysis—not disk imaging forensics (digital-forensics-analyst), live incident command (incident-responder), SOC alert triage (soc-analyst), authorized pentest exploitation (penetration-tester), LLM red team (ai-redteam), or CI pipeline gates (devsecops).
-
daemon-blockint-tech Bundle Extreme LifecycleGuides end-to-end lifecycle governance for mission-critical, high-assurance, or zero-failure- tolerance systems—concept through retirement: phases, gates, evidence, traceability, obsolescence, tech refresh, configuration baselines, NDA-safe regulated/classified patterns, assurance/DevSecOps/ ATO interfaces, decommissioning and data disposition. Use for extreme lifecycle, system lifecycle, mission-critical lifecycle, lifecycle gates, sustainment, tech refresh, obsolescence management, decommissioning, configuration baseline, lifecycle evidence, end-to-end lifecycle, or retire a system—not TPM-only (technical-program-manager), HRO-only (zero-tolerance-for-failure), tiering-only (mission-critical), classified pipeline-only (classified-software-devsecops-engineer), formal proofs (software-assurance-formal-methods-specialist), compliance-only (compliance-engineer), CI-only (build-validator), infra portfolio-only (vp-of-infrastructure).
-
daemon-blockint-tech Bundle Network PentesterGuides authorized network and infrastructure penetration testing—scoping and rules of engagement, external and internal network assessments, host and service enumeration, vulnerability validation on network services, Active Directory attack paths within scope, lateral movement documentation, segmentation testing, wireless assessment methodology (high level), evidence and remediation reporting, and retest. Emphasizes written authorization and safe boundaries. Use for network pentest, internal pentest, external pentest, AD assessment, lateral movement testing, port scan methodology when authorized—not OWASP web/API testing (web-pentester), cross-domain pentest orchestration when network is one workstream (penetration-tester), LLM/agent adversarial testing (ai-redteam), enterprise adversary simulation or purple-team campaigns (red-team-specialist), SOC triage (soc-analyst), incident command (incident-responder), or cloud guardrail implementation (cloud-security-engineer).
-
daemon-blockint-tech Bundle AI Risk GovernanceGuides AI risk management and governance—use-case risk assessment, model/system documentation, policies and guardrails, human oversight, third-party model/vendor review, and mapping to frameworks (NIST AI RMF, ISO 42001, EU AI Act concepts, internal AI policy). Use when classifying AI use cases, drafting AI acceptable-use policies, building risk registers, preparing model cards or DPIAs for AI, reviewing vendor LLMs, or aligning product teams with compliance—not for implementing RAG/agents (ai-engineer), running jailbreak tests (ai-redteam), or SOC 2/ISO evidence automation and technical control mapping (compliance-engineer), or general SOC 2 IT controls without AI scope (cybersecurity). For AI solution architecture in commercial or enterprise deployments, use applied-ai-architect-commercial-enterprise. For agent skills catalog standards and security review before publish, use ai-skill-manager. Safeguard infra/research: ml-infrastructure-engineer-safeguards, ml-research-engineer-safeguards.
-
daemon-blockint-tech Bundle Matrix EnvironmentGuides organizational operating models for cross-functional security and technology teams—matrix vs hierarchical structures, RACI and interaction models, chapter/pod/guild patterns, platform vs product vs security alignment, interfaces between SOC/IR/AppSec/GRC/Engineering, scaling patterns, anti-patterns, and operating rhythm. Use when designing or tuning a matrix org, security/engineering interaction models, chapter or guild structure, decision rights between central and embedded teams, cross-functional interfaces (SOC, IR, AppSec, GRC, SRE, platform), or org scaling—not cloud environment tiers or deployment matrices alone (cloud-engineer), executive security program strategy (chief-information-security-officer), enterprise security reference architecture (enterprise-security-architect), multi-team program RAID and milestones (technical-program-manager), or VP infrastructure portfolio and capex (vp-of-infrastructure).
-
daemon-blockint-tech Bundle Penetration TesterGuides authorized penetration testing—scoping and rules of engagement, reconnaissance, vulnerability identification, exploitation within scope, post-exploitation documentation, evidence and remediation reporting, and retest validation. Emphasizes written authorization, RoE boundaries, and safe/legal testing. Use for pentest, penetration test, ethical hacking, authorized assessment—not enterprise adversary simulation or purple-team campaigns (red-team-specialist), dedicated network/AD/infra pentest (network-pentester), deep web/API-only assessments (web-pentester), SOC alert triage (soc-analyst), incident command (incident-responder), forensic imaging (digital-forensics-analyst), binary/firmware RE (reverse-engineer), LLM/adversarial AI testing (ai-redteam), or implementing cloud guardrails (cloud-security-engineer).
-
daemon-blockint-tech Bundle Data System Ops LeadRun data system operations and reliability engineering. Cover pipeline monitoring, incident response, SLA management, capacity planning, on-call runbooks, data quality alerting, and operational excellence. Triggers on "data pipeline monitoring", "incident response", "SLA management", "capacity planning", "on-call runbook", "data quality alerting", "operational excellence", "system reliability", "pipeline health check", or "data ops".
-
daemon-blockint-tech Bundle Vp Of InfrastructureGuides VP-level infrastructure leadership—org strategy and operating model, multi-year cloud, data center, and platform portfolio, capex and opex governance, org-wide reliability and security posture, hyperscaler/colo/vendor and enterprise agreement strategy, build-vs-buy and multi-year roadmaps, and board/CFO/CTO executive narratives. Use when setting infrastructure direction, designing infra org and decision rights, prioritizing portfolio investments, steering vendor or EA strategy, preparing executive or board updates, or adjudicating cross-functional trade-offs—not for Terraform/K8s implementation (infrastructure-engineer), cloud program leadership—migration portfolio, CCoE, EA at cloud scope (vp-of-cloud), landing zone or CCoE design (enterprise-cloud-architect), SLI/SLO operations (site-reliability-engineer), monthly CUR FinOps (finops-analyst), TCO/NPV modeling (cloud-economist), or GL close/capex accounting policy (director-infrastructure-capex-accounting, compute-accounting-manager).
-
daemon-blockint-tech Bundle Compliance SpecialistGuides cross-functional GRC and compliance programs—framework selection and scope (SOC 2, ISO 27001, HIPAA, PCI, GDPR concepts), control mapping and gap assessments, policy and procedure outlines, audit and assessor coordination prep, vendor security questionnaire support, and continuous compliance program design with ownership and cadence. Use when standing up or maturing a compliance program, scoping attestations, running readiness gap analyses, drafting control matrices, preparing audit walkthroughs, responding to SIG/CAIQ-style questionnaires, or designing continuous compliance—not technical control implementation or evidence automation (compliance-engineer), cloud-only API evidence and residency packages (cloud-compliance-specialist), IAM/terraform guardrails (cloud-security-engineer, information-security-engineer), legal interpretation or contract redlines (commercial-counsel), security risk registers (security-risk-analyst), or pentest execution (penetration-tester).
-
daemon-blockint-tech Bundle Microservices AnalystGuides analysis of existing microservice estates—service and API inventory, dependency and coupling maps (sync chains, shared-database smells), observability and SLO coverage gaps, deployment and version skew, API contract drift and breaking consumers, operational toil indicators, security blast radius, and consolidation or decomposition recommendations with evidence. Produces executive summaries for platform, SRE, and architect audiences. Use when the user says microservices analyst, analyze microservices, service dependency map, coupling analysis, microservice health, API drift, service inventory, blast radius, operational analysis, SLO coverage, technical debt microservices, strangler assessment—not greenfield boundary research only (microservice-researcher), writing new services (senior-software-engineer), Kubernetes-only tuning (cloud-engineer), or pure load testing (performance-engineer).
-
daemon-blockint-tech Bundle Security Risk AnalystGuides information security risk analysis—risk identification and scoring, risk registers, threat/vulnerability/control mapping, treatment recommendations (accept/mitigate/transfer/avoid), third-party and supply-chain risk framing, business impact analysis, KRIs, and risk committee or board narratives. Aligns with ISO 27005 and NIST RMF concepts without full compliance audits. Use for security risk assessment, risk register maintenance, inherent/residual risk scoring, FAIR-style quantitative framing, treatment decisions, third-party risk tiers, or executive risk reporting—not SOC alert triage (soc-analyst), pentest execution (penetration-tester, web-pentester, network-pentester), control implementation (information-security-engineer, cloud-security-engineer), GRC program and audit prep (compliance-specialist), audit evidence automation (compliance-engineer, cloud-compliance-specialist), AI model risk programs (ai-risk-governance), or adversary simulation (red-team-specialist).
-
daemon-blockint-tech Bundle Cloud Security EngineerGuides cloud security engineering on AWS, GCP, and Azure—org guardrails (SCPs, org policies), cloud IAM and federation, network segmentation and private connectivity, encryption and KMS, logging and audit to SIEM, CSPM and native detective controls (Config, Security Hub, GuardDuty, SCC, Defender), workload hardening, and secure cloud architecture review with remediation. Use when implementing or auditing cloud security controls, fixing misconfigurations, designing multi-account guardrails, hardening VPC/VNet and data plane access, or integrating cloud audit logs—not for corporate IdP/SIEM/EDR programs broadly (information-security-engineer), CI pipeline gates and SBOM only (devsecops), SOC alert triage (defensive-security-analyst), pentest execution (penetration-tester, network-pentester, web-pentester for app/API), GRC evidence packaging (compliance-engineer), GRC program and audit prep (compliance-specialist), or routine cloud provisioning without security ownership (cloud-engineer).
-
daemon-blockint-tech Bundle Data Warehouse EngineerDesign and implement data warehouses. Cover star/snowflake schemas, dimensional modeling, SQL optimization, ETL/ELT patterns, partitioning strategies, and warehouse-specific features (Snowflake, BigQuery, Redshift). Triggers on "design star schema", "optimize SQL query", "build ETL pipeline", "warehouse partitioning", "dimensional modeling", "data warehouse design", "query performance tuning", or "warehouse migration". For dbt project structure, staging/mart layers, incremental models, and analytics CI, use analytics-data-engineer—not data-warehouse-engineer alone. OLTP app latency and load testing: performance-engineer.
-
daemon-blockint-tech Bundle Field Services EngineerGuides field services engineering—on-site and colocation smart-hands work: site readiness, rack-and-stack, power and network cabling, hardware install/replace, labeling, acceptance tests, photo documentation, customer sign-off, and remote handoff to NOC or platform teams. Use when planning or executing a field visit, writing work orders, troubleshooting physical layer on site, or coordinating vendor/colocation access—not for K8s cluster deploy (cluster-deployment-engineer), DC capacity program delivery (senior-data-center-capacity-delivery-manager), hall MEP design (data-center-design-execution-lead), cloud IaC (infrastructure-engineer), or software support tickets (support-engineer). Customer escalation program: community-executive-escalations-program-manager.
-
daemon-blockint-tech Bundle Infrastructure EngineerDesign and implement cloud infrastructure. Cover cloud architecture, IaC (Terraform, Pulumi), CI/CD pipelines, container orchestration (Kubernetes), networking, observability, and security hardening. Triggers on "design cloud infrastructure", "set up Terraform", "configure Kubernetes", "build CI/CD pipeline", "infrastructure monitoring", "network architecture", "security hardening", "infrastructure cost optimization", or "platform engineering". For day-2 Kubernetes cluster operations—Helm rollouts, add-ons, RBAC, GitOps sync, workload troubleshooting, use cluster-deployment-engineer. For data center facility design, power/cooling, rack layout, and build commissioning, use data-center-design-execution-lead. For on-prem compute utilization, GPU/CPU supply planning, stranded kW, and hardware refresh efficiency, use data-center-compute-supply-efficiency. For on-site colo smart-hands, rack-and-stack, cabling, and physical acceptance, use field-services-engineer. Compute accounting: compute-accounting-manager.
-
daemon-blockint-tech Bundle Microservice ResearcherGuides research and analysis for microservices architecture decisions—domain decomposition, bounded contexts, service boundary options and trade-offs, sync vs async integration patterns, data ownership and consistency (eventual consistency, sagas at research level), API and contract evolution, Team Topologies alignment, build vs buy vs managed services, monolith strangler migration, NFR impact (latency, reliability, operability), and decision records with options and recommendations. Use for microservice research, service boundaries, bounded context, strangler fig, monolith to microservices, saga vs two-phase commit, domain decomposition, microservices trade-off, team topologies, eventual consistency research, API versioning strategy—not assessing an existing estate (microservices-analyst), production service code (senior-software-engineer, platform-engineer), Kubernetes cluster ops only (cloud-engineer), pure network design (network-backbone-architect), or EDA implementation when building not researching
-
daemon-blockint-tech Bundle Microservices DeveloperGuides microservice design and delivery—bounded contexts, service boundaries, REST/gRPC/event APIs, sync vs async tradeoffs, resilience (timeouts, retries, circuit breakers, bulkheads), per-service data ownership, saga and outbox patterns, twelve-factor containers, observability (logs, metrics, trace propagation), API versioning at gateways/meshes, and contract testing. Use for microservices developer, service boundary, bounded context, gRPC between services, circuit breaker, saga pattern, outbox pattern, twelve-factor, contract testing microservices, service decomposition, or event-driven microservice—not K8s platform ops (platform-engineer, site-reliability-engineer), enterprise iPaaS (enterprise-integration-api-developer), monolith-first apps (senior-software-engineer), or classified pipelines (classified-software-devsecops-engineer).
-
daemon-blockint-tech Bundle Cyber Resilience EngineerDesigns and operates cyber resilience capabilities—RTO/RPO architecture, backup/restore and immutable backup patterns, dependency mapping for critical services, crisis playbooks for ransomware, destructive malware, and cloud control-plane loss, chaos and failure injection for security-relevant failures, resilience testing with evidence, and alignment with NIST CSF Recover and business continuity. Use when engineering recovery objectives and tiers, designing backup immutability and restore validation, running resilience or chaos tests, mapping attack-scenario playbooks, reporting resilience metrics, or sustaining continuity during active attacks—not enterprise BCM program ownership alone (bcm-disaster-recovery-specialist), live incident command (incident-responder), SRE performance and toil only (site-reliability-engineer), backup operator runbooks without architecture (cloud-system-administrator), GRC audit prep only (compliance-specialist), or CISO board strategy (chief-information-security-officer).
-
daemon-blockint-tech Bundle Digital Forensics AnalystGuides digital forensics for security incidents—evidence acquisition and chain of custody, disk/memory/mobile/cloud artifact analysis, log and network forensics, timeline correlation, malware artifact triage, and investigation reports for legal/IR and expert-witness preparation outlines (not legal advice). Use when preserving and analyzing forensic artifacts, building super-timelines, documenting acquisition worksheets, triaging malware samples, or preparing forensic findings for counsel—not live incident command (incident-responder), SOC alert queue triage (soc-analyst), authorized penetration testing (penetration-tester), deep binary RE (reverse-engineer), LLM red team (ai-redteam), enterprise ISMS programs (information-security-engineer), audit control mapping (compliance-engineer), or cloud guardrail implementation (cloud-security-engineer).
-
daemon-blockint-tech Bundle Iot Network Edge EngineerThis skill should be used when the user asks about IoT network design, edge engineer work, MQTT broker and topic design, LoRaWAN, LPWAN, IoT gateway, device provisioning, IoT edge, CoAP, Azure IoT Edge, AWS IoT Core, device shadow, OTA updates, Zigbee, protocol bridge, IoT fleet, and IoT segmentation. Guides connectivity, edge gateways, store-and-forward, broker scale, and cloud IoT handoffs—not enterprise WLAN (wireless-wifi-mobility-specialist), OT/ICS plant security (scada-ics-cyber-security-specialist), embedded without connectivity (embedded-real-time-software-engineer), carrier backbone (network-backbone-architect), cloud landing zones (cloud-architect), or telemetry ML (data-scientist).
-
daemon-blockint-tech Bundle Site Reliability EngineerGuides Site Reliability Engineering—SLI/SLO and error budgets, reliability dashboards and burn-rate alerting, production readiness reviews, capacity planning for availability, toil reduction, dependency and failure-mode analysis, release reliability (canaries, rollback criteria), and service-owner incident mitigation tied to customer impact. Use when defining or operating SLOs, measuring error budget burn, improving service reliability, running PRRs before launch, planning scalable resilient capacity, or leading technical mitigation during outages—not for CI/CD pipeline implementation (devops), incident program and paging policy design (incident-management-engineer), cloud access and patch tickets (cloud-system-administrator), load-test profiling (performance-engineer), rollout cutover strategy (deployment-strategist), or greenfield cloud build-out (cloud-engineer).
-
daemon-blockint-tech Bundle Vendor Cyber Risk AnalystGuides third-party and vendor cyber risk—TPRM intake and tiering, security questionnaire analysis and scoring, evidence and attestation review (SOC 2, ISO 27001, pen test summaries), continuous vendor monitoring, concentration and fourth-party risk, remediation tracking, and executive or procurement risk reporting. Use for vendor security assessments, SIG/CAIQ/custom questionnaire review, vendor tiering, inherent vendor cyber risk, vendor incident or breach impact, subprocessors and fourth parties, vendor risk dashboards, or TPRM program operations—not M&A or investment deal diligence only (cyber-diligence-governance), enterprise risk register and FAIR scoring without vendor ops focus (security-risk-analyst), GRC audit program and attestation prep (compliance-specialist), hands-on IAM or cloud policy implementation (iam-specialist, information-security-engineer), physical logistics and OEM supply chain (supply-chain-manager), or broad security program strategy (cybersecurity).
-
daemon-blockint-tech Bundle Cloud System AdministratorGuides cloud system administration—day-2 operations on AWS, GCP, and Azure: access requests and IAM role assignment, key and certificate rotation, OS patching and maintenance windows, backup and restore execution, monitoring and alert triage, quota and limit increases, runbooks, change records, and on-call troubleshooting of cloud control-plane and managed-service issues. Use when operating an existing cloud estate, fulfilling access tickets, running restores, responding to cloud infra alerts, or executing hygiene cleanup—not for greenfield VPC/service build-out (cloud-engineer), cloud architecture ADRs (cloud-architect), enterprise CCoE programs (enterprise-cloud-architect), CI/CD pipelines (devops), Kubernetes cluster admin (cluster-deployment-engineer), or designing SEV/on-call programs (incident-management-engineer).
-
daemon-blockint-tech Bundle Compute Accounting ManagerGuides accounting for compute infrastructure—cloud COGS and prepaid commitments, capex vs OpEx for servers/GPUs, depreciation and asset disposal, colo and hardware accruals, GL mapping from usage and invoices (CUR, billing exports), chargeback/showback to products, and month-end reconciliation of compute spend to the ledger. Use when classifying compute costs, capitalizing hardware, amortizing RIs/Savings Plans, building allocation models, fixed-asset register for compute, or closing compute-related accounts—not for ASC 606 revenue recognition (senior-revenue-accountant), engineering utilization optimization (data-center-compute-supply-efficiency), cloud architecture (infrastructure-engineer), deal desk order forms (deal-operations-administrator), commercial contract negotiation (commercial-counsel), or capex policy and board-level infrastructure asset governance (director-infrastructure-capex-accounting).
-
daemon-blockint-tech Bundle Control Software DeveloperGuides industrial control application software—real-time loops and application layers above field devices; DCS/PLC/RTU integration; OPC UA, Modbus, DNP3, MQTT/AMQP; historian and alarm/event pipelines; HMI/SCADA server-side logic (not graphics-only); soft-PLC/PC control; deterministic scan cycles; MIL/SIL (high level); versioned OT deploy; coordination with OT security/safety without owning plant ops. Use for control logic, PLC/DCS apps, protocol integration, historian/alarms, SCADA server logic, scan-cycle determinism, MIL/SIL planning, OT software deployment—not OT cyber only (scada-ics-cyber-security-specialist), MCU firmware only (embedded-real-time-software-engineer), HIL security bench (hardware-in-the-loop-security-tester), enterprise web/backend (senior-software-engineer), tiering without control depth (mission-critical), HRO only (zero-tolerance-for-failure).
-
daemon-blockint-tech Bundle Cyber Diligence GovernanceGuides cyber due diligence and governance—M&A/investment diligence, vendor and third-party assessments, questionnaire and evidence review, control maturity and gaps, integration risk, IC/board cyber briefs, and governance cadence. Use for target or vendor security diligence, SIG/CAIQ review, deal or procurement committee packs, post-close integration planning, or IC/board cyber briefs—not pentest (penetration-tester, web-pentester, network-pentester), AI governance only (ai-risk-governance), risk register without diligence (security-risk-analyst), GRC audit prep (compliance-specialist), contract redlines (commercial-counsel), closing logistics (transaction-manager), control deploy (information-security-engineer), CISO strategy (chief-information-security-officer), or TPRM ops (vendor-cyber-risk-analyst). Draft only; counsel and deal leads approve binding positions.
-
daemon-blockint-tech Bundle Defensive Security AnalystGuides defensive security analysis—alert triage, log and SIEM investigation, threat hunting, detection engineering basics, MITRE ATT&CK mapping, incident scoping, containment recommendations, and DFIR evidence handling for SOC and blue-team analysts. Use when investigating security alerts, writing detection rules, tuning false positives, analyzing EDR/network/auth logs, building timelines of suspicious activity, recommending containment steps, or documenting findings for incident command—not for enterprise security strategy (cybersecurity), CI/CD pipeline hardening (devsecops), offensive pentest execution (authorize red team separately), or LLM adversarial testing (ai-redteam), or designing on-call rotations and postmortem programs (incident-management-engineer).
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include security-risk-analyst, cloud-security-engineer, field-services-engineer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.