DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
xspoonai Bundle Deploy On VercelDeploy applications and websites to Vercel instantly without authentication. Use when the user wants to "deploy my app", "push this live", or "create a preview link". Returns a live preview URL and a claimable link.
Audited -
xspoonai Bundle Spoonos Platform IntegrationDeploy SpoonOS agents to messaging platforms and APIs. Use when integrating agents with Telegram, Discord, Slack, REST APIs, webhooks, or scheduled tasks.
Audited -
qa-aman Skill Deal QualificationQualify a sales opportunity using the MEDDIC framework. Use when the user says "qualify this deal", "is this deal real", "MEDDIC qualification", "MEDDICC framework", "should I pursue this opportunity", "deal review", "how qualified is this prospect", "pipeline review prep", "forecast this deal", "sanity check on this opportunity", or wants to assess whether a sales opportunity is worth pursuing and at what pipeline stage.
-
qa-aman Skill Etl RunbookWrite an ETL operational runbook. Use when the user says "ETL runbook", "pipeline runbook", "data job runbook", "how to operate this ETL", "on-call guide for data pipelines", "what to do when the data job fails", "pipeline troubleshooting guide", "data ops runbook", or needs to document how to operate, monitor, and recover a data pipeline or ETL job - even if they don't explicitly say "runbook".
-
qa-aman Skill Deployment ChecklistRun a pre and post-deployment checklist. Use when the user says "deploy to production", "deployment checklist", "release checklist", "pre-deploy checks", "is this ready to deploy", "deployment readiness", "reduce deployment risk", "change management", or is about to ship code to production and wants to reduce failure risk - even if they don't explicitly say "deployment checklist".
-
qa-aman Skill Sourcing StrategyBuild a candidate sourcing strategy and outreach pipeline. Use when the user says "where do I find candidates for this role", "build a sourcing plan", "write a cold outreach message", "we're not getting enough applicants", "our pipeline is dry", "help me find passive candidates", "write a LinkedIn message", or wants to increase the volume or quality of candidates in the funnel - even if they don't explicitly say "sourcing strategy". Also use when a recruiter needs to go beyond job postings to find talent.
-
qa-aman Skill Pipeline Design DocWrite a data pipeline design document. Use when the user says "pipeline design doc", "document this pipeline", "pipeline architecture doc", "data flow document", "how does this pipeline work", "design doc for ETL", "pipeline spec", or needs to capture the architecture, data flow, and operational details of a data pipeline - even if they don't explicitly say "design doc".
-
garphengate Skill Crm HygienistList every open deal with no activity in 14 or more days, ranked by value with days-silent attached; use as the Monday-morning two-minute pipeline truth serum.
-
garphengate Skill Devops SentinelThe ten checks that catch most bad deploys before they leave the driveway. Use as a fast gate before any production deploy when there's no custom checklist yet.
-
uphiago Skill Supply Chain Attack ReconExternal recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry exposure, SBOM mining, internal-package-name leakage, and CI/CD configuration exposure. Reconnaissance and identification ONLY — actual package publishing / typosquat attacks are EXTERNAL-OFFENSIVE and require explicit written sign-off because they can affect the entire npm/PyPI ecosystem. Use when the target has a public GitHub org, when their build artifacts/SBOMs are reachable, when their docker images are on Docker Hub/GHCR, or when you find internal package names in their JS bundles.
-
the-nam-shub Skill Abm Field EventsGuidance for planning and executing ABM field events—including dinners, lunches, activations, and suite sponsorships—to build pipeline and deepen relationships with target accounts
-
the-nam-shub Skill Visual Content StrategyGuides Claude in advising marketers on how to select, prioritize, and deploy visuals on product and landing pages to support messaging and drive conversion
-
the-nam-shub Skill Outbound Abm And Account TargetingGuides marketers through outbound strategy, ABM execution, account targeting, signal-based prioritization, and multi-channel orchestration for B2B pipeline generation
-
the-nam-shub Skill Funnel Pipeline And Revenue MetricsGuides marketers on how to define, measure, and report funnel, pipeline, and revenue metrics in B2B contexts — including which metrics to own, how to calculate them, how to report to executives, and how to align with sales and finance.
-
the-nam-shub Skill Lead Scoring And Predictive ScoringGuides Claude in helping marketers design and implement modern lead and account scoring systems, replacing traditional lead scoring with account-level, buying group, and predictive pipeline approaches.
-
openlabor Skill Content Repurpose PipelineAtomize one piece of content into platform-native posts for X, LinkedIn, Instagram, Reddit, and YouTube — with viral scoring and dedup
-
zhouyinlong-lab Skill Academic Research SkillsAcademic Research Skills (ARS) — 学术研究全流程 AI 助手,38.7k⭐ 开源项目。 4 个技能覆盖从文献调研到论文发表:Deep Research (13 agents 文献调研/系统综述)、 Academic Paper (12 agents 写作流水线/LaTeX PDF 输出)、 Academic Paper Reviewer (7 agents 多视角审稿/反谄媚协议)、 Academic Pipeline (10 阶段编排器/引文验证/完整性闸门)。 核心理念:AI 是副驾驶,不是飞行员——帮你查文献、管引用、校格式,研究判断由你做主。 Trigger keywords: 学术研究, 写论文, 论文写作, 文献综述, 系统综述, 投稿, 审稿, 毕业论文, academic research, paper writing, literature review, systematic review, PRISMA, peer review, 发表论文, 学术写作, 论文润色, 期刊投稿, 会议投稿, 引文检查, 参考文献, LaTeX论文, 博士研究, 硕士论文, 科研全流程, ARS, academic pipeline, deep research paper, 论文审稿, rebuttal, 审稿回复, 学术引用, citation check, 论文格式, APA, IEEE, Chicago, 科研流水线.
-
brucesongs Bundle Web SsrfServer-Side Request Forgery (SSRF) attacks including basic, blind, and advanced bypass techniques, internal port scanning, cloud metadata extraction (AWS/GCP/Azure), protocol smuggling (gopher://, dict://, file://), and chained RCE exploitation.
Audited -
brucesongs Bundle Hsm AttackHardware Security Module attacks — physical (side-channel, fault injection, decapping) and logical (PKCS#11 API abuse, key extraction, M-of-N quorum bypass, RDP, firmware exploitation). Covers Thales Luna (SafeNet), Utimaco SecurityServer, nCipher nShield, YubiHSM, AWS CloudHSM, Azure Dedicated HSM, Google Cloud HSM. Includes 2024-2025 CVEs (CVE-2024-47787 Thales Luna, CVE-2024-45294 Utimaco), HSM-as-a-Service tenant isolation attacks, and quorum-spoofing scenarios. Distinct from crypto-attacks (algorithm-level) and pam-privilege-attack (credential management).
-
brucesongs Bundle Iot PentestIoT application-layer penetration testing covering MQTT broker abuse, CoAP server attacks, AMQP exploitation, OT/cloud IoT gateways (AWS IoT, Azure IoT Hub), device management platforms, mobile companion apps, embedded web services, and proprietary IoT protocol reverse engineering using mosquitto, MQTT-Pwn, IoT-Goat, EMQX, CoAP testing tools, and IoT-Goat lab environments.
Audited -
brucesongs Bundle LLM Red TeamLLM and generative AI red team testing covering prompt injection, jailbreaking (DAN, many-shot, Crescendo, PAIR/TAP, GCG suffix, persona modulation, prefix injection, payload smuggling), model extraction, RAG poisoning, agentic tool abuse, and safety policy bypass using promptfoo, garak, PyRIT, PurpleLlama, AI-Infra-Guard and llm-guard — plus Constitutional AI, Llama Guard, NeMo Guardrails, and Azure AI Content Filter evasion.
-
brucesongs Bundle Cloud SecurityCloud security covers security assessment for major cloud platforms including AWS, Azure, and GCP, with core focus on IAM misconfiguration detection, storage bucket exposure scanning, metadata service attacks, container escape, and Kubernetes RBAC auditing.
Audited -
brucesongs Bundle Agentic PentestLLM-driven autonomous penetration testing framework operations covering PentestGPT, HexStrike AI, Viper, PentestAgent, AI-Infra-Guard, AutoPWN, and custom agent harness patterns — including reasoning chain orchestration, tool delegation, context window management, output validation, multi-agent pentest team coordination, and human-in-the-loop checkpoints.
Audited -
brucesongs Bundle Docker PatternsSetting up a practice lab for penetration testing techniques - Creating isolated environments for exploit development and testing - Building vulnerable application targets for training - Testing tools against known-vulnerable configurations - User says "lab", "docker lab.
Audited -
brucesongs Bundle Sase Sse AttackSecure Access Service Edge (SASE) and Security Service Edge (SSE) platform compromise covering Zscaler (ZIA/ZPA/ZDX/Client Connector), Netskope (Security Cloud, SWG, CASB, Private Access), Palo Alto Prisma Access, Cisco Umbrella, CATO Networks SASE, Cloudflare One (WARP, Gateway, Access), and Microsoft Entra Global Secure Access — including client connector reverse engineering, TLS inspection bypass via certificate pinning and ESNI/ECH, split-tunnel race conditions, BYOD vs managed device bypass, stolen SSO token replay through SSE proxy, anonymizer proxy evasion (Shadowsocks/V2Ray/Obfs4/Trojan), and detection avoidance using Wireshark, Frida, mitmproxy, JA3/JA4 fingerprint spoofing.
-
brucesongs Bundle Firmware ReverseFirmware reverse engineering covers the full pipeline from raw firmware image acquisition through filesystem extraction, static and dynamic analysis, full-system emulation, and vulnerability/backdoor detection.
-
brucesongs Bundle AI Agent SecurityOffensive security testing of AI agent systems covering MCP server attacks, tool poisoning, indirect prompt injection against agents, RAG knowledge base poisoning, agent sandbox escape, multi-agent compromise chains, and autonomous agent hijacking — using MCP security testers, HexStrike AI, AI-Infra-Guard, custom agent harness probes, and prompt injection toolkits.
-
brucesongs Bundle Kubernetes AttackKubernetes cluster attack and red team covering RBAC abuse, pod escape (privileged pods, hostPath, capabilities, hostPID/hostIPC, container runtime sockets, kernel CVEs), kubelet API abuse (10250/10255), etcd direct access, service account token theft (legacy and projected), RBAC privilege escalation chains, cloud-managed K8s (EKS/GKE/AKS) pivoting, and kubectl plugin ecosystem (peirates, CDK, kube-hunter, BOtB, kubeletctl, kubescape, stratus-red-team, kubernetes-goat).
-
brucesongs Bundle Container SecurityContainer security covers the complete lifecycle from image building, registry management, runtime protection, to orchestration platform (Kubernetes) security.
Audited -
brucesongs Bundle Deception HoneypotDefensive deception and honeypot deployment covering SSH/Telnet (Cowrie), web (OpenCanary), enterprise (HFish), ICS/SCADA (Conpot), all-in-one (T-Pot), AI-driven deception (Beelzebub), Thinkst Canarytokens (DNS, HTTP, file, AWS API key, SQL), Dionaea multi-protocol honeypot, notification pipelines (Slack/Teams webhooks), false positive tuning, and attacker engagement — including lure design, deployment OPSEC, IOC extraction, and attacker attribution.
Audited -
brucesongs Bundle Storage San AttackStorage/SAN/NAS/Object storage penetration testing — iSCSI, Fibre Channel, NFSv3/v4, SMB3, S3-compatible APIs, NetApp ONTAP, Dell EMC, Pure Storage, QNAP, Synology, TrueNAS, NDMP backup tape pilfering, and ransomware patterns targeting storage appliances. Distinct from database-attack (which targets RDBMS/NoSQL query protocols) and cloud-native-vuln-research (which focuses on CVE research rather than storage fabric and appliance pentest).
-
brucesongs Bundle Data Platform AttackAttacks against cloud data platforms and analytics pipelines — Snowflake, Databricks, BigQuery, Redshift, dbt, Apache Airflow, and lakehouse architectures. Covers identity-based breaches (no perimeter), warehouse SQL injection at scale, IAM privilege escalation, secrets in DAGs, notebook code injection, and cross-tenant data exfiltration. Distinct from database-attack (protocol-level RDBMS) and cloud-security (broader CSP control plane).
-
brucesongs Bundle Cloud Identity AttackCloud identity provider attacks covering Azure AD/Entra ID, Okta, Auth0, Ping, AWS IAM Identity Center, and Google Workspace — including OAuth 2.0 token theft, OIDC redirect abuse, SAML response forgery, conditional access bypass, MFA fatigue, federation compromise (AD FS, Ping), app registration abuse, and JIT access exploitation using ROADtools, AADInternals, MicroBurst, MFASweep, TokenTactics, and Okta API probing tools.
-
brucesongs Bundle Detection EngineeringDetection-as-code engineering covering Sigma rule authoring, YARA signature development, Splunk SPL / Kusto KQL / Elastic EQL queries, MITRE ATT&CK mapping, detection CI/CD pipelines, false-positive tuning, and rule testing against EVTX-ATTACK-SAMPLES — using SigmaHQ, Yara-Rules, Loki, yarGen, hayabusa, SigmaCLI, and zircollo.
Audited -
brucesongs Bundle Edge Computing AttackAttacks against edge computing platforms — Cloudflare Workers (V8 isolate), Fastly Compute@Edge (WASM/Wasmtime), AWS Lambda@Edge and CloudFront Functions, Akamai EdgeWorkers, Vercel Edge Functions, and Deno Deploy. Covers V8 isolate escape, WASM sandbox bypass, request smuggling at the edge, edge KV store abuse, secret leakage via edge logs, and bypass of origin WAF via edge script injection. Distinct from cloud-security (broader CSP control plane), container-security (Linux namespaces), and web-ssrf (origin-side issues).
-
brucesongs Bundle Patch To Poc PipelineThe end-to-end patch-diff vulnerability reproduction workflow — patch analysis (read diff, identify protective pattern, hypothesize bug class), source or binary-only code path walking (Ghidra + BinDiff), PoC generation (manual craft OR AFL++/libFuzzer harness with ASan/UBSan), CyberGym-style differential verification (vuln crashes, patched clean) as the deterministic stop condition, and YARA + Sigma detection rule authoring tested against both versions. Covers 2024-2026 CVEs (libwebp, xz-utils, runc, glibc Looney Tuner, regreSSHion, MOVEit, Jenkins, Confluence, TeamCity, OFBiz). Solidifies validation/scenarios/SCEN-008.md into a reusable knowledge base and wires in Schema 3 reproduction memory for memory-driven convergence.
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include firmware-reverse, container-security, sase-sse-attack. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.