DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
aradotso Skill Logos Distributed Reasoning RouterDeploy and use Logos Router for zero-drift distributed AI reasoning with adaptive Claude Opus-style thinking and multilingual semantic routing
-
aradotso Skill Logos Router Distributed ReasoningDeploy and configure Logos Router for distributed semantic reasoning with zero-drift consensus and adaptive thinking depth
-
malekokour Bundle Review Bioanalytical ReportReviews the content of a bioanalytical method validation report and its study sample analysis report against the shared ICH M10 conformance rubric, producing an element-by-element conformance register plus the subset of observations that bear on PK interpretation. Use this skill when someone asks whether a bioanalytical report covers what the standard requires, or whether its stated stability, dilution, carryover and reanalysis content supports the PK data drawn from it — for example "check this validation report against ICH M10" or "does the bioanalytical package support the concentrations behind these PK parameters". Do not use for verifying NCA derivations or parameter values, for reconciling a study report against its own sources, for re-validating or re-fitting the assay, or for any request to certify GLP or GCP compliance or to declare a method acceptable.
Audited -
tomevault-io Bundle Jira REST APIUse when interacting with Jira programmatically via REST API — API v2 and v3 endpoints, authentication (API tokens, OAuth, PAT), issue CRUD (search via JQL — /rest/api/3/search/jql on Cloud, /rest/api/2/search on Data Center), status category mapping, sprint/board queries (Agile API), comments, attachments, labels, pagination (nextPageToken cursor on Cloud, startAt + maxResults on Data Center), rate limiting, error handling, and webhooks. Works with both Jira Cloud and Data Center.
Audited -
aiunlocked1412 Bundle Ml EngineerML Engineer — model deployment, MLOps pipeline, feature store, model monitoring, A/B testing, production ML system design
-
aiunlocked1412 Bundle Devops Helperสร้าง Dockerfile CI/CD yaml และ monitoring config ที่ production-ready ไม่พัง
-
aiunlocked1412 Bundle Blockchain DevBlockchain/Web3 Developer — smart contract (Solidity/Rust), ERC-20/721/1155, DeFi protocol, security audit เบื้องต้น, deploy testnet/mainnet
-
aiunlocked1412 Bundle Cloud ArchitectCloud Architect — AWS/GCP/Azure solution design, cost optimization, HA/DR, multi-region, IaC (Terraform/CDK), Well-Architected Review
-
nvidia-omniverse Skill Usd Remote Stage MirrorOpen a USD stage from an http(s):// URL by mirroring it and its full dependency closure (sublayers, references, payloads, textures) into a local cache, then opening the local copy — because pxr has no HTTP asset resolver. The remote source is never written; the stage's user-facing identity stays the URL. Use when a viewer must accept a pasted URL to a cloud-hosted USD (e.g. the NVIDIA ConceptCar S3 sample).
-
haomingz Bundle K8S Cluster Ops通过 kubectl 命令行工具管理 Kubernetes 集群,执行查询资源状态、部署应用、查看日志、调试容器、切换上下文和监控集群健康等操作。适用于日常运维、发布和故障排查。当用户询问集群状态、Pod/Deployment信息、查看日志、执行容器命令、切换集群或上下文,或使用 kubectl get/describe/logs/exec/apply 等相关命令短语时触发。
Audited -
haomingz Bundle Gitlab CLI Guide提供 GitLab 命令行工具(glab)的完整参考与自动化脚本,涵盖超过30个子命令,包括合并请求创建与审查、CI/CD流水线调试、Issue管理、仓库操作和认证配置等核心工作流。适用于通过终端管理MR/Issue、调试CI失败任务、批量打标签、同步Fork和发布Release等场景。当用户提到glab、GitLab命令行、GitLab CLI、MR管理、流水线调试、glab auth、glab ci或glab mr等关键词时触发。
Audited -
haomingz Bundle Terraform Deploy TrapsTerraform 部署实战踩坑指南,提供对常见运维陷阱(如 provisioner 时序竞争、SSH 连接冲突、DNS 记录重复、卷权限问题、数据库初始化遗漏、Caddyfile 硬编码域名等)的根因分析及可直接复制的修复方案。当用户编写 null_resource provisioner、搭建多环境配置、排查 terraform apply 后容器持续重启或不健康、使用 cloud-init 初始化实例,或遇到 terraform plan/apply 报错、provisioner 执行失败、基础设施漂移、TLS 证书错误以及 Caddy/网关配置问题时,此技能将被激活。
Audited -
haomingz Bundle Glab CI管理 GitLab CI/CD 流水线、作业和产物。适用于检查流水线状态、查看作业日志、调试 CI 失败、触发手动作业、下载产物、验证 .gitlab-ci.yml 或管理流水线运行等场景。触发关键词:流水线、CI/CD、作业、构建、部署、产物、流水线状态、构建失败、CI 日志。
-
haomingz Bundle Glab Job管理单个 CI/CD 作业,包括查看、重试、取消、追踪日志和下载产物。适用于调试作业失败、查看作业日志、重试作业或管理作业执行。触发词:job、CI 作业、作业日志、重试作业、作业产物。
-
haomingz Bundle Glab Auth管理 GitLab CLI 认证,包括登录/登出、检查认证状态、切换账户以及配置 Docker 镜像仓库访问。适用于首次设置 glab、排查认证问题、切换 GitLab 实例/账户或配置 Docker 从 GitLab 镜像仓库拉取镜像。触发关键词:auth、login、logout、认证、凭证、token、Docker 镜像仓库。
-
haomingz Skill Glab Runner管理 GitLab CI/CD Runner(运行器)——列出、分配、取消分配、暂停和删除项目、群组或实例级别的 Runner。适用于查看 Runner 状态、将 Runner 分配给项目、临时暂停 Runner 或移除已退役的 Runner。触发词:runner、glab runner、列出 runner、分配 runner、取消分配 runner、暂停 runner、删除 runner、CI runner。
-
haomingz Bundle Glab Cluster管理 GitLab Kubernetes 集群和 Agent 集成。适用于连接集群、管理集群 Agent 或使用 Kubernetes 集成。触发词:cluster、Kubernetes、k8s、集群 Agent、连接集群。
-
haomingz Bundle Glab Opentofu在 GitLab 中管理 OpenTofu 状态。适用于管理 Terraform/OpenTofu 状态、配置状态后端或进行基础设施即代码(IaC)工作。触发词:OpenTofu、Terraform、状态管理、基础设施即代码、IaC。
-
haomingz Bundle Glab Schedule管理 CI/CD 流水线定时计划,包括创建、列出、更新、删除和运行定时流水线。适用于自动化流水线、设置定时任务或管理定时构建。触发词:schedule、定时流水线、cron、流水线计划、自动化构建。
-
haomingz Bundle Glab Variable管理项目和群组级别的 CI/CD 变量,包括创建、更新、列出和删除操作。适用于设置流水线环境变量、管理密钥或配置 CI/CD 变量。触发词:variable、CI 变量、环境变量、密钥、CI/CD 配置。
-
haomingz Bundle Glab Deploy Key管理 GitLab 项目的 SSH 部署密钥(deploy key),包括添加、列出和删除操作。适用于为 CI/CD 设置部署密钥、管理只读访问权限或配置部署认证。触发关键词:deploy key、SSH 密钥、部署密钥、只读访问。
-
haomingz Bundle Glab Securefile管理 CI/CD 安全文件,包括上传、下载、列出和删除操作。适用于存储流水线敏感文件、管理证书或处理安全配置文件。触发词:secure file、CI 密钥、证书、安全配置。
-
build-with-dhiraj Skill Capital Allocation JudgeUse when assessing how well a CEO/management team allocates capital — to score the CONVICTION dimension "management quality" with a structured, cross-CEO scorecard drawn from William Thorndike's Outsiders framework. Applies during Stage 1 dossier writing, Stage 3 conviction re-grade, and any ad-hoc "is this management great at capital allocation?" question. The Munger/Buffett binding CIO already carries Buffett's own allocation wisdom — this skill ADDS the cross-CEO Outsiders methodology: per-share-value as the CEO scoreboard, opportunistic (not programmatic) buybacks, FCF/owner-earnings over GAAP, centralized capital + decentralized ops, leverage matched to cash-flow predictability, and contrarian analytical discipline. Triggers: "capital allocation", "how does management deploy FCF", "are buybacks value-accretive", "Outsiders framework", "management scorecard", "owner-operator quality", grading mgmt in any v2 conviction step.
-
build-with-dhiraj Skill Stock Onboarding PipelineOnboard new Indian stocks into the "Paise se Paisa" Action Dashboard end-to-end, using the v2 vault-aligned machinery (understanding gate → quality-gated conviction with ROIC+runway → conservative IV range → conviction-scaled margin-of-safety vs opportunity cost → reformed verdict). Use when the user says "add stocks", "add the next batch", "onboard <tickers>", "grow the dashboard", "re-rank", or wants to extend the TO-BUY/study list. Workspace: /Users/Dhiraj/dev/invest, sheet fileId 1N87younF990u-YGMOAiT8q6X-EtZ3jVovlWCF44orEY. Charlie Munger & Warren Buffett (the Obsidian vault) are the binding CIO; the vault gates conviction/verdict/MoS, it is not narrative decoration.
-
build-with-dhiraj Skill Forensic Accounting RedflagsUse at the DOSSIER / UNDERSTANDING stage (Stage 1) on EVERY stock to run the governance-integrity screen before any conviction or IV work. India-specific promoter and accounting red-flag checklist grounded in the SEBI-Satyam, SEBI-IL&FS-CRA, and Damodaran-forensic canon. Covers: CF-vs-PAT divergence, fabricated cash / bank-confirmation tests, related-party loan and pledge chains, promoter share-pledging, auditor independence and resignation signals, provisioning games, asset-liability maturity mismatch (NBFC / infra), group-entity opacity / interdependency complexity, and insider-trading sale patterns. Outputs a GOVERNANCE-RISK verdict (CLEAN / CAUTION / RED) that can cap conviction or push a name to AVOID / TOO_HARD — it is a defensive gate, not a valuation. A RED verdict hard-fails the thesis; CAUTION caps conviction at 2. Triggers: "run the forensic screen", "check governance", "red flags", "is the accounting clean", "related-party risk", "pledge risk", "auditor concerns", dossier stage on any new name.
-
build-with-dhiraj Skill Investigation ModeOrchestrated debugging coordinator. Triggers on frustration signals (stuck, hung, broken, waiting) and systematically triages: runtime logs → workflow status → browser verify → deploy/env. Reports findings at every step.
-
uphiago Skill Hunt K8SHunt Kubernetes & Docker — API anonymous access, kubelet 10250 exec (SPDY/WebSocket, NOT plain POST) and the simpler /run primitive, etcd 2379 unauth, dashboard skip-login, RBAC misconfig, secret/SA-token abuse, docker.sock host escape, runc/container-escape (Leaky Vessels CVE-2024-21626), API-server-mediated nodes/proxy RCE, EphemeralContainers node-shell, bound/projected SA-token audience+expiry abuse, admission-controller bypass, Helm/Tiller remnants. Use when target runs containerized infra, exposes K8s ports (6443/10250/10255/2379/8443), or cloud metadata reveals K8s service accounts.
Audited -
uphiago Skill Hunt CicdHunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into-shell), self-hosted runner poisoning, OIDC trust-policy abuse, Jenkins script-console RCE and CVE-2024-23897 file read, GitLab CI runner-token registration, Terraform state file leakage, artifact/log secret leakage, pipeline env-var disclosure. Use when target has a public GitHub/GitLab org, exposed CI dashboards (Jenkins/TeamCity/Drone/Argo), or build artifacts/images are reachable.
-
uphiago Skill Hunt SsrfHunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOne $25k Analytics PDF, Shopify Exchange $25k, Capital One 106M-record breach, Dropbox/HelloSign $4,913), GCP metadata SSRF (Snapchat $4k), Azure IMDS SSRF (Azure DevOps $15k chain, ChatGPT Custom Actions MSRC), DNS rebinding SSRF (Concrete CMS, GitLab UrlBlocker), gopher-protocol-to-Redis-RCE (Yahoo Mail $15k), link-preview SSRF (Reddit Matrix $6k), and headless-browser PDF-generator SSRF chains. Use when hunting SSRF on any target — OOB Collaborator confirmation mandatory for blind cases.
Audited -
uphiago Skill Bug BountyMaster bug bounty orchestrator — full pipeline: recon, pre-hunt learning, vulnerability hunting (30+ classes), A-to-B chaining, AI/LLM testing (ASI01-ASI10), language-specific grep, bypass tables, and reporting (7-question gate, CVSS 3.1, human-tone templates). Use for ANY bug bounty task — starting a new target, recon, hunting specific vulns, source code audit, AI feature testing, or report writing. 中文触发词:漏洞赏金、安全测试、渗透测试、漏洞挖掘
Audited -
uphiago Skill Docker PrivescEscape Docker containers to host root via 5 techniques.
-
uphiago Skill Pentest Playbook7-phase pentest pipeline from passive recon to exploitation.
Audited -
uphiago Skill Cloud Iam DeepGCP/AWS/Azure cloud exploitation -- Cloud Functions, Firestore, Cloud Run, S3, MinIO, Blob Storage, SA keys
-
uphiago Skill Hunt SubdomainHunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO via wildcard `reply_to`, Binary Security), Zendesk help-desk takeover → email interception → password reset chain (0xprial writeup), Vercel `cname.vercel-dns.com` deleted-project takeover, plus general Fastly CDN service re-attach and S3 dangling-bucket cookie-scope techniques. Use when hunting subdomain takeover — emphasis on ATO-chain primitives (OAuth `redirect_uri`, cookie-domain, email DNS).
Audited -
uphiago Skill Hunt SpringbootHunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, loggers, mappings, shutdown), Spring Expression Language (SpEL) injection → RCE, H2 console RCE, Jolokia JMX exposure, Spring4Shell (CVE-2022-22965), Spring Cloud Function SPEL (CVE-2022-22963), heap dump credential extraction. Use when target runs Spring Boot — detected via X-Application-Context header, /actuator, Whitelabel Error Page, or Java stack traces.
-
uphiago Skill Hunt Host HeaderHunt Host Header Injection — password reset poisoning → ATO, web cache poisoning via unkeyed Host/X-Forwarded-Host, routing-based SSRF (Host picks upstream → cloud metadata/internal services), path-override SSRF/ACL-bypass (X-Original-URL/X-Rewrite-URL), OAuth redirect_uri/issuer poisoning, and absolute-URL link poisoning in emails. High to Critical when it reaches ATO or mass cache poisoning. Built on public Host-header research (PortSwigger 'Practical web cache poisoning' + James Kettle, and the classic password-reset-poisoning class). Use on any forgot-password flow, CDN/reverse-proxy-fronted app, OAuth/OIDC endpoint, or absolute-URL-in-email feature.
Audited
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include glab-auth, glab-deploy-key, hunt-ssrf. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.