DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
uphiago Skill Hunt Cache PoisonHunting skill for cache poison vulnerabilities. Built from 10 public bug bounty reports including X-Forwarded-Host poisoning, X-HTTP-Method-Override / GCS cache, reflected→stored XSS via cache, classic Omer-Gil Web Cache Deception, Cloudflare Cache Deception Armor bypass, session-token cache deception, Akamai hop-by-hop smuggling → server-side edge poisoning, and Kettle's 2024 path-normalization WCD against Cloudflare/Fastly/GCP. Use when hunting cache poisoning, Web Cache Deception, CDN-fronted apps.
Audited -
uphiago Skill Hunt Cloud MisconfigHunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles, AWS metadata accessible via SSRF. GCP: public GCS buckets, exposed Cloud Run services, leaked service account JSON. Azure: public blob containers, exposed Function App. (Kubernetes/Docker exposure is owned by hunt-k8s; CI/CD pipeline attacks by hunt-cicd; post-credential IAM escalation by cloud-iam-deep.) Detection: targeted dorking, certificate transparency, JS bundle secret extraction, port scan for known service ports. Validate: actual data read / write / RCE. Use when hunting cloud-native storage and compute misconfig (S3/GCS/Blob, IMDS-via-SSRF, serverless, public managed services).
Audited -
uphiago Skill Recon Sector ExpansionMulti-sector batch domain expansion — identify untested/under-tested sectors, generate candidate company domains (national chains, franchises, regionals), filter against existing test coverage, probe alive domains, and run the full testing pipeline across 20+ new targets in a single session. Complements per-sector recon-* skills by telling you WHICH sectors to expand into next.
Audited -
build-with-dhiraj Skill RAG PatternsBuild RAG pipelines — vector DB + LLM, document Q&A, chunking/embedding strategies. Triggers on 'build RAG', 'document Q&A', 'retrieval pipeline', 'embed and search'.
-
build-with-dhiraj Skill Idea To BuildThe global 4-stage idea→shipped pipeline (Sonnet brainstorms → tracker tickets with dependencies → Fable plans in-repo → Fable orchestrates Opus 4.8 implementers). Invoke when the user says "run the pipeline", "idea to build", "take this brainstorm and build it", "plan the build from Linear/Jira tickets", "execute the tickets", or arrives in a project session pointing at tickets produced by a chat brainstorm. Also invoke at Stage-4 time when the user asks to "execute the plan with 4.8 agents".
Audited -
build-with-dhiraj Skill Moat AnalysisUse when the conviction step needs a rigorous moat judgment — taxonomy, durability test, and pricing-power check — for any Indian stock being onboarded or re-graded. Enriches the existing v2 conviction step (STAGE 3) and the inversion/FOREVER gate (STAGE 4); it is NOT a new pipeline step. Outputs a moat-tier (Wide / Narrow / Contestable / None) and a durability verdict (Widening / Stable / Eroding) that feed directly into the conviction rubric (Wide+Stable → higher conviction, Contestable → COMPOUND-not-FOREVER, None → conviction cap 1). Triggers: "what is the moat here", "is this moat durable", "why COMPOUND not FOREVER", "contestable vs durable", grading INDIAMART-style marketplace or IGI-style trust franchise moat, any stock where the conviction band is uncertain because the moat characterisation is unclear.
-
build-with-dhiraj Skill Github ActionsSet up GitHub Actions CI/CD workflows. Triggers on "add CI", "run tests on PR", "GitHub Actions", "branch protection", "scheduled workflow".
-
build-with-dhiraj Skill Decision JournalUse when sharpening Stage 4 (inversion / strict FOREVER gate) of the v2 onboarding machinery, or when attaching a decision-journal artifact to any conviction call. Provides process-vs-outcome (resulting) discipline, base-rate and skill/luck awareness, calibrated probabilistic framing, pre-mortem/inversion protocol, and a per-stock DECISION-JOURNAL template (what we believed, bet size, kill-criteria, what would change our mind). Enriches — but does NOT replace — the binding Munger/Buffett CIO (vault) and Munger's Psychology of Misjudgment layer already embedded in the pipeline. Triggers: "decision journal", "pre-mortem", "kill criteria", "what would change my mind", "am I falling in love with this stock", "bias check on FOREVER", "was I right for the right reasons", "resulting", "process vs outcome", Stage 4 inversion on any FOREVER candidate.
-
build-with-dhiraj Skill Deployments CicdVercel deployment and CI/CD expert guidance. Use when deploying, promoting, rolling back, inspecting deployments, building with --prebuilt, or configuring CI workflow files for Vercel.
-
build-with-dhiraj Skill Python PipelinesBuild Python automation pipelines, scheduled jobs, async task orchestration, or ETL workflows. Triggers on "build a pipeline", "schedule this script", "task queue".
-
build-with-dhiraj Bundle Stock Pick RankerSUPERSEDED (2026-06-13) — OFFLINE xlsx-research variant ONLY; for adding/ranking stocks into the LIVE Action Dashboard use the stock-onboarding-pipeline skill instead (vault-binding v2). This v1 runs the full matured equity quality+valuation ranking pipeline on new stocks and append them into the Substack_Stock_Picks.xlsx workbook. Use this skill WHENEVER the user gives new companies/tickers to evaluate, new Substack (or other newsletter) investor profile URLs to scrape for stock picks, or asks to "add these stocks", "rank these companies", "score this stock", "run the workflow on X", "append to the stock workbook", "update the ranking", or extend/refresh the investment ranking. It scrapes investor newsletters, enriches live (Indian-listed) financials from Screener/Moneycontrol, scores each stock on a 7-factor principles rubric, runs forward + reverse DCF valuation (method-appropriate by stock type), reliability-weights the valuation into the rank, re-ranks the combined universe, and appends/refreshes the wor
Audited -
build-with-dhiraj Skill Etf Reit OnboardingSystematically FIND, GRADE and BUY great ETFs / REITs / InvITs that ride durable global trends — evaluating funds LIKE stocks (verdict → conviction → margin-of-safety) and holding the good ones for life. The fund mirror of the stock onboarding pipeline. Use when the user says "add an ETF/REIT/InvIT", "grade this fund", "build a global-trend buy-list", "passive sleeve", "evaluate a fund like a stock", "should I buy <ETF>", "is this trend worth owning", or wants to extend / re-rank the global-trend exposure list. Workspace: /Users/Dhiraj/dev/invest. Publish target is the 🌍 Global & Passive Base tab (re-architected per the plan) — the LOCKED Action Dashboard is NEVER touched. Charlie Munger & Warren Buffett (the Obsidian vault) are the binding CIO; the vault gates trend-durability/conviction/verdict/MoS — it is not narrative decoration.
-
build-with-dhiraj Bundle Obsidian Brain EvalTest your Obsidian RAG, measure your second brain's retrieval quality, and score your vault on Recall@10 against a gold-set generated from your own notes. Pluggable retrieval backends (BM25 zero-infra, LanceDB hybrid FTS+vector). Pure Python CLI, read-only. The skill is the only tool that publishes a methodology and a default 0.85 pass/fail threshold for "is your vault chat actually working". Use when the user asks any of: test my obsidian rag, measure my second brain, is my pkm answering well, obsidian retrieval quality, test my obsidian search, recall at 10 my vault, evaluate my obsidian rag, obsidian rag benchmark, score my obsidian retrieval, is my second brain working, obsidian search quality, pkm retrieval eval, obsidian eval framework, gold set obsidian, smart connections eval, obsidian copilot eval, rag over my vault, does my vault chat work, vault retrieval test. Works on any markdown vault using wikilinks (Obsidian, Logseq, Foam, Quartz). Complements obsidian-graph-auditor (measures graph topology);
Audited -
build-with-dhiraj Skill Ner Content PipelineExtract named entities, relationships, and topics from unstructured text into knowledge graphs or taxonomies. Triggers on "NER pipeline", "extract entities", "tag content".
-
gianlucanaarden Skill AI Theory Of Constraints AnalistPast de Theory of Constraints van Eliyahu Goldratt toe op elk bedrijf, project of proces. Vindt de bottleneck in een systeem, maakt zichtbaar waar de doorvoer vastloopt en geeft de vijf stappen waarmee je de constraint kunt opheffen. Gebruik deze skill ALTIJD wanneer iemand zegt 'waar zit de bottleneck', 'mijn proces loopt vast', 'we draaien op volle kracht maar groeien niet', 'theory of constraints', 'TOC', 'Goldratt', 'doorlooptijd verlagen', 'capaciteit vergroten', 'waar moet ik op focussen', 'wat is de zwakste schakel', 'flow optimalisatie', 'throughput verhogen', 'drum buffer rope', 'thinking processes', 'evaporating cloud', 'current reality tree', of 'future reality tree'. Trigger ook wanneer een ondernemer met meerdere afdelingen of stappen worstelt en niet weet welke stap de hele keten remt.
Audited -
xspoonai Bundle CI Pipeline ScaffoldDescription
Audited -
xspoonai Bundle Contract DeployerCompile and deploy Solidity smart contracts to EVM chains.
Audited -
xspoonai Bundle Terraform Plan Risk AuditorAnalyze Terraform plan JSON for risky changes and blast radius.
Audited -
xspoonai Bundle K8S Manifest Security AuditorStatic analysis for common Kubernetes manifest security and reliability risks.
Audited -
spike-faye-lei Skill RebuttalWorkflow 4: Submission rebuttal pipeline. Parses external reviews, enforces coverage and grounding, drafts a safe text-only rebuttal under venue limits, and manages follow-up rounds. Use when user says "rebuttal", "reply to reviewers", "ICML rebuttal", "OpenReview response", or wants to answer external reviews safely.
-
spike-faye-lei Skill Paper WritingWorkflow 3: Full paper writing pipeline that goes from a narrative report to a polished, submission-ready PDF. Use when user says "写论文全流程", "write paper pipeline", "从报告到PDF", "paper writing", or wants the complete paper generation workflow.
-
spike-faye-lei Skill Run ExperimentDeploy and run ML experiments on local, remote, Vast.ai, or Modal serverless GPU. Use when user says "run experiment", "deploy to server", "跑实验", or needs to launch training jobs.
-
spike-faye-lei Skill Autosci Exp RunFull experiment execution pipeline — prepare code → deploy(Confirm with the user before operation and ask the applicant to conduct manual inspection) → monitor → collect results, supporting three run modes
-
spike-faye-lei Skill Claims DraftingDraft patent claims for an invention. Use when user says "撰写权利要求", "draft claims", "写权利要求书", "claim drafting", or wants to create patent claims. The core skill of the patent pipeline.
-
spike-faye-lei Skill Resubmit PipelineWorkflow 5: orchestrate a text-only resubmit of a polished paper to a different venue under hard constraints (no new experiments, no bib edits, no framework changes, never overwrite prior submissions). Use when user says "resubmit pipeline", "重投流程", "port paper to <new venue>", "resubmit to <venue>", "tighten paper for resubmission", or has a rejected/withdrawn paper to move to a different top venue under tight time budget.
-
spike-faye-lei Skill Vast GpuRent, manage, and destroy GPU instances on vast.ai. Use when user says "rent gpu", "vast.ai", "rent a server", "cloud gpu", or needs on-demand GPU without owning hardware.
-
spike-faye-lei Skill Paper TalkEnd-to-end conference talk pipeline: paper → slide outline → Beamer + PPTX → per-page polish → assurance checks (claim / citation / anonymity) → final export and report. Default-good for academic conference talks (NeurIPS / ICML / ICLR / VALSE / 投稿 talks). Trigger phrases: "做 talk", "做 PPT 全流程", "talk pipeline", "end-to-end slides", "做演讲", "conference talk full workflow". Use when the user wants the complete talk artifact, not just a slide deck.
-
spike-faye-lei Skill Patent PipelineFull patent drafting pipeline from invention description to jurisdiction-formatted filing documents. Supports CN (CNIPA), US (USPTO), EP (EPO). Supports invention patents and utility models. Use when user says "写专利", "patent pipeline", "专利申请", "draft patent", "写权利要求书", or wants to draft a complete patent application.
-
spike-faye-lei Skill Serverless ModalRun GPU workloads on Modal — training, fine-tuning, inference, batch processing. Zero-config serverless: no SSH, no Docker, auto scale-to-zero. Use when user says "modal run", "modal training", "modal inference", "deploy to modal", "need a GPU", "run on modal", "serverless GPU", or needs remote GPU compute.
Audited -
h-mmer Skill PipelinePrepare the battlefield — recon, scanning, and surface ranking. Stops before hunting. Run /hunt or /autopilot after. Usage: /pipeline or /pipeline <target>
-
h-mmer Skill Subdomain TakeoverSubdomain Takeover specialist (H1 #145). Use for finding dangling DNS records pointing to unclaimed cloud resources, expired services, or deprovisioned infrastructure.
-
is-bo Bundle ForgeUse automatically for installed software engineering: build, change, fix, review, audit, test, verify, deploy, release, or ship. Apply production discipline proportionately; explicit commands are optional. Not for unrelated conversation.
-
is-bo Skill Forge UploadsAudit the complete upload, processing, storage, delivery, and deletion pipeline against hostile files.
-
is-bo Bundle Google Cloud Storage BasicsStores, retrieves, and manages data as objects in Cloud Storage (Google Cloud Storage, or GCS) buckets. Use when you need to interact with Cloud Storage — create or configure buckets, upload, download, stream, or transfer data, organize objects with folders, generate signed URLs, control access (IAM, ACLs, public access prevention), set storage classes and tiering (Standard, Nearline, Coldline, Archive), manage cost and lifecycle, protect data (versioning, encryption/CMEK, retention and Bucket Lock, object holds, soft delete), host static websites, trigger Pub/Sub notifications on object changes, mount buckets as a file system (gcsfuse), or optimize storage performance at any scale. Covers the gcloud storage / gsutil CLI, JSON and XML APIs, client libraries, Terraform, and Cloud Storage MCP servers. Don't use for block storage (Persistent Disk), data warehousing/analytics (BigQuery), or databases (Cloud SQL, Spanner, Bigtable, Firestore).
-
is-bo Bundle Google Cloud Solution ArchitectureInteractively discovers requirements for a specific cloud workload and generates design recommendations and architectural guidance to build a multi-product solution in Google Cloud. Use this skill for holistic, end-to-end design recommendations and architectural guidance for complex, multi-product workloads on Google Cloud for specific use cases. Don't use this skill when other specialized skills (e.g., product-specific or google-cloud-recipe-*) directly address the user's workload or use case.
-
xspoonai Bundle Spoonos Deployment GuideDeploy SpoonOS agents to production environments. Use when containerizing agents with Docker, deploying to cloud platforms (AWS, GCP, Vercel), or setting up self-hosted infrastructure.
Audited
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include hunt-cloud-misconfig, github-actions, hunt-cache-poison. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.