DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
conectlens Bundle Feature Slice DesignerDecide where new behavior belongs across apps, features, domain, data, api, ui, infra, and utils. Use before implementing a feature, refactor, or cross-layer change in the LenserFight monorepo.
-
benbrastmckie Skill Skill TagCreate and push semantic version tags for CI/CD deployment. User-only command - agents cannot invoke.
-
zhaoxuya520 Bundle Infrastructure As Code基础设施即代码实践,覆盖 Terraform / Pulumi / CloudFormation。关注状态管理、模块化设计、drift 检测、环境一致性、变更审计。
12.8k -
zhaoxuya520 Bundle Container Orchestration容器编排与部署时使用。覆盖 Docker/Docker Compose/K8s/Helm 实操。
12.8k -
zhaoxuya520 Bundle Kubernetes OrchestrationKubernetes 工作负载编排,覆盖 Deployment / Service / Ingress / HPA / PDB。Helm Chart 管理、ArgoCD GitOps 部署、资源调优、高可用设计。
12.8k -
noorqureshi Skill Cloud GCPAttack Google Cloud Platform — metadata/SA token theft, IAM privilege escalation, and storage/ function misconfig. Load when the target runs on GCP, you hold a GCP SA key/token, or see gcp/gcloud/GCE/GKE/appspot. Signals: metadata.google.internal, service-account.json, storage.googleapis.com, cloudfunctions, gcloud.
-
noorqureshi Skill Cloud AzureAttack Azure / Entra ID — managed-identity token theft, Entra (Azure AD) role abuse, and app/ storage misconfig. Load when the target is on Azure, you hold Azure creds/a token, or see Entra/AAD/azurewebsites/blob.core.windows.net. Signals: 169.254.169.254 IMDS, Managed Identity, az cli, Entra roles, service principals.
-
noorqureshi Skill Recon OsintPassive OSINT to expand attack surface without touching the target: dorks, code/secret leaks, Shodan/Censys, cloud assets, employees. Load at recon start, on "OSINT", "google/github dorks", "shodan", or gathering intel on an org. Signals: org name, root domain, "find leaks/exposed".
-
noorqureshi Skill Cloud Imds SsrfEscalate SSRF to cloud credential theft via the instance metadata service (IMDS). Load when SSRF is confirmed AND the target runs on AWS/GCP/Azure. Signals: 169.254.169.254 reachable, cloud-hosted app, SSRF that can set arbitrary Host/headers, "metadata".
-
noorqureshi Skill AI RAG PoisoningPoison a RAG/knowledge-base pipeline so retrieved content hijacks the model (indirect prompt injection at scale) or exfiltrates data. Load when the app does retrieval over documents/URLs/ tickets/emails the attacker can influence, "RAG", vector DB, "knowledge base", agent that reads content. Signals: upload-to-KB, "chat with your docs", crawled sources.
-
noorqureshi Skill Cloud KubernetesAttack exposed Kubernetes: API server, kubelet, etcd, dashboards, and RBAC. Load on k8s signals — ports 6443/10250/2379/8443, /api/v1, kube-dns, a pod foothold, or "kubernetes/k8s". Signals: kubectl, service-account tokens, exposed dashboard, container in a cluster.
-
noorqureshi Skill Cloud Iam PrivescEscalate privileges in cloud IAM (AWS/GCP/Azure) from a low-priv set of credentials. Load when you hold cloud creds/keys/a role and want higher privilege or new resources. Signals: leaked AWS keys, an assumed role, a service-account token, "escalate in AWS/GCP/Azure", enumerated permissions.
-
noorqureshi Skill Cloud S3 ExposureFind and prove misconfigured cloud object storage (S3/GCS/Azure Blob). Load when assets load from *.s3.amazonaws.com, storage.googleapis.com, *.blob.core.windows.net, bucket-looking hostnames, or "bucket". Signals: public-read/list, unauthenticated writes, predictable bucket names.
-
noorqureshi Skill Recon Cloud AssetsDiscover an organization's cloud footprint — buckets, blobs, apps, IP ranges, and services across AWS/GCP/Azure. Load during recon on a company target, on "cloud recon", finding storage/assets, or before cloud testing. Signals: an org name/domain in scope, assets on cloud CDNs, wildcard program.
-
noorqureshi Skill Web Subdomain TakeoverClaim a dangling DNS record pointing to a deprovisioned service (subdomain takeover). Load after subdomain enum, on CNAMEs to cloud services, "NoSuchBucket"/"404 there isn't a GitHub Pages site here", or dangling A/CNAME. Signals: CNAME → S3/GitHub/Heroku/Azure/Fastly with a fingerprint error page.
-
noorqureshi Skill Cloud Docker RegistryFind and loot exposed container registries — image pull/push, secrets baked in layers, and registry misconfig. Load on exposed Docker registry (port 5000, /v2/), a registry URL, harbor/ECR/ GCR/ACR references, or "container registry". Signals: /v2/_catalog, registry:2, unauth pull/push.
-
noorqureshi Skill Code Review IacSecurity review of infrastructure-as-code — Terraform, CloudFormation, Ansible, Kubernetes/Helm manifests. Load when reviewing IaC in a repo/PR, on .tf/.yaml/.yml infra files, or "review our Terraform". Signals: *.tf, cloudformation/*.yaml, playbooks, k8s manifests, Helm charts, module registries.
-
noorqureshi Skill Cloud Container EscapeBreak out of a container to the host. Load when you have a shell in a container/pod and want the node: privileged container, mounted docker.sock, dangerous capabilities, hostPath, or "escape the container". Signals: /.dockerenv, cgroup shows docker/k8s, CAP_SYS_ADMIN, mounted socket.
-
noorqureshi Skill Cloud Docker API AbuseTurn an exposed container daemon or an over-privileged container into host compromise — a Docker API on 2375/2376, a mounted docker.sock, or a privileged/`-v /:/host` container. Load when you find an open Docker/containerd socket, port 2375/2376, a container you can run images in, or you landed inside a container and want the host. Signals: 2375/tcp open, /var/run/docker.sock reachable, `docker` group membership, privileged container, host paths mounted in.
-
noorqureshi Skill Code Review CicdReview CI/CD pipelines for security flaws — poisoned workflows, secret leakage, and injection. Load on GitHub Actions / GitLab CI / Jenkins config, ".github/workflows", pull_request_target, self-hosted runners, or "pipeline security". Signals: workflow YAML, secrets in CI, third-party actions.
-
noorqureshi Skill Defense Log AnalysisHunt for attacker activity in logs — auth, web, cloud, endpoint — with concrete queries and what to look for. Load for blue-team log/SIEM hunting, "analyze these logs", "find the attack", triage of auth/web/cloud logs, or building hunts. Signals: log files/SIEM, "what happened", IOC hunting.
-
noorqureshi Bundle Payloads Waf BypassBypass WAFs/filters blocking your payloads. Load when a payload that should work is blocked, you see 403/406/429 or "request blocked", Cloudflare/Akamai/Imperva/AWS-WAF/ModSecurity, or a filter strips keywords. Signals: works locally but blocked on target, generic block pages.
-
noorqureshi Skill API Mongo Agg Facet BypassBypass a MongoDB aggregation-pipeline stage allowlist by nesting disallowed read stages inside $facet, then $unionWith/$lookup sibling collections to exfiltrate secrets (invite tokens, creds, hashes). Load when: an endpoint accepts a user-supplied `pipeline` (or errors like "operator-form queries not accepted, use the pipeline parameter"), a Node/Express + MongoDB backend, 24-hex `_id`s, or an "advanced query" API. Authorized targets only.
-
noorqureshi Skill Defense Cloud DetectionDetect and respond to attacks in cloud control planes — credential abuse, IMDS theft, persistence, and privilege escalation — from audit logs. Load for "detect cloud attacks", "CloudTrail/GuardDuty", "someone used our keys", AWS/Azure/GCP monitoring, or cloud IR. The defensive counterpart to the cloud-* offensive skills.
-
noorqureshi Skill Defense Detection EngineeringBuild detections as a repeatable pipeline, not one-off alerts. Load for "improve our detections", "detection as code", "reduce false positives", "measure ATT&CK coverage", or turning a red-team finding into durable blue-team coverage. Complements defense-detection-sigma (the rule format).
-
noorqureshi Skill Code Review Secrets DetectionFind leaked secrets in code, git history, and CI. Load on "secrets", "leaked key", a repo/ git history in scope, exposed .git, CI config review, or public-repo OSINT. Signals: API keys, tokens, .env files, private keys, cloud creds, hardcoded passwords.
-
noorqureshi Skill Tradecraft Attack Path MappingModel the target as an attack graph — nodes (assets, identities, trust) and edges (a technique that gets you from one to the next) — and find the shortest path to the objective. Load when many findings need to be assembled into a route, on "how do these bugs connect", AD/cloud lateral- movement planning, or to explain how a foothold reaches crown jewels.
-
zhaoxuya520 Bundle Quality Gate上线放行决策 / 阻断不达标交付时使用。适用于版本发布前门禁、CI/CD 自动门禁、阶段性质量评估。融合 SonarQube Quality Gate、DORA Change Failure Rate、Google Beyoncé Rule。
12.8k -
zhaoxuya520 Bundle RAG Pipeline---
12.8k -
zhaoxuya520 Bundle Orchestration选择多工作流编排模式时使用。适用于跨工作流协同任务、决定任务串行/并行/动态规划。优先使用 Microsoft Azure 的四种 Agent 编排模式(顺序/并发/交接/动态)。
12.8k -
zhaoxuya520 Bundle CI CD PipelineCI/CD 流水线设计与实现,覆盖 GitHub Actions / GitLab CI / Jenkins。标准阶段:lint → test → build → scan → deploy。关注流水线性能、安全门禁、环境隔离。
12.8k -
zhaoxuya520 Bundle Secrets Config密钥与配置管理,覆盖 HashiCorp Vault / AWS Secrets Manager / K8s Secrets。12-Factor App 环境变量、配置中心、密钥轮换、零信任访问。
12.8k -
zhaoxuya520 Bundle ContainerizationDocker 多阶段构建、镜像优化、Distroless 基础镜像、安全扫描(Trivy)、Docker Compose 编排。适用于应用容器化、镜像瘦身、供应链安全加固场景。
12.8k -
zhaoxuya520 Bundle CI Test Integration把自动化测试集成到 CI/CD 流水线时使用。适用于 GitHub Actions / GitLab CI 测试阶段配置、并行化、缓存、失败阻塞。
12.8k -
zhaoxuya520 Bundle Deploy Preview快速部署 + 预览环境时使用。适用于 Vercel / Railway / Fly.io / Cloudflare / Docker Compose 快速上线。融合 Preview 环境 + 环境变量 + 数据库连接 + 域名。
Audited 12.8k -
coco-research Skill Voice AIVoice AI architecture and implementation guide. Covers two architectures: speech-to-speech (OpenAI Realtime API, lowest latency) and pipeline (STT->LLM->TTS, more control). Includes provider-specific patterns for OpenAI Realtime, Vapi, Deepgram, ElevenLabs, and LiveKit. Use when building voice agents, voice-enabled apps, or real-time conversational AI.
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include cloud-iam-privesc, cloud-docker-registry, orchestration. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.