DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
brucesongs Bundle Embedded Rtos SecurityRTOS penetration testing — VxWorks WDB debug agent (Urgent/11), QNX microkernel, FreeRTOS+TCP CVEs, ThreadX/Azure RTOS, Zephyr, Mbed OS, TI-RTOS, MicroC/OS, NuttX, RIOT, Contiki
-
brucesongs Bundle Data Exfiltration AttackAttacks for exfiltrating data from compromised networks and bypassing DLP/egress controls. Covers DNS tunneling, ICMP/HTTPS tunneling, protocol smuggling, steganographic exfil, cloud-native exfil (S3/OpenSearch/BigQuery), and DLP bypass. Use when testing egress monitoring, validating DLP controls, or simulating APT exfiltration campaigns.
-
brucesongs Bundle Identity Provider AttackIdentity Provider (IdP) attack patterns covering OAuth 2.0/OIDC, SAML, JWT, token theft/replay, MFA fatigue, service principal abuse (Azure AD/Entra ID), Okta, Auth0, Keycloak, and modern identity-based attacks.
-
brucesongs Bundle AI Agent Framework AttackAI agent framework attack surface — orchestration-layer compromise of LangChain (Python/JS), LangGraph, CrewAI, Microsoft AutoGen, OpenAI Assistants API v2, Anthropic Claude Agent SDK, LlamaIndex, Microsoft Semantic Kernel, Google ADK, SmolAgents, and MCP-integrated agent runtimes. Covers tool poisoning (Simon Willison 2025 research), indirect prompt injection via untrusted tool outputs, tool rug-pull attacks (npm/PyPI dependency confusion in agent toolkits), LangChain SSRF via RequestsTool / SqlQueryTool / PythonREPLTool (CVE-2024-21514 area, CVE-2024-43480 area), CrewAI tool RCE via decorators (CVE-2024-10231 area), AutoGen code executor escape (Docker/code execution services), OpenAI Assistants API code_interpreter abuse, Claude Agent SDK MCP injection, LangGraph state injection via checkpoint poisoning, LlamaIndex query engine injection, MCP server poisoning (Anthropic/rug-pull.com research Nov 2024), tool description injection, agent memory poisoning, Retrieval-Augmented Generation (RAG) corpus poisoning
-
brucesongs Bundle CI CD Supply Chain AttackCI/CD pipeline and software supply chain compromise covering Jenkins (script console, Jenkinsfile injection, shared library abuse, CVE-2024-23897 args4j), GitLab CI/CD (runner abuse, .gitlab-ci.yml injection, self-hosted runner takeover, CVE-2022-1162, OmniAuth CVE-2024-9653), GitHub Actions (self-hosted runner abuse, pull_request_target trap, workflow injection via issue/PR title, secrets exfiltration via cache/artifact, GITHUB_TOKEN scope), CircleCI (context theft, OIDC abuse), Argo CD (CVE-2022-24348, default app creds), Flux CD (GitRepository CRD abuse), Tekton, Buildkite, Drone CI, software supply chain attacks (dependency confusion, typosquatting, brandjacking, malicious npm/PyPI packages, SBOM/SLSA, Sigstore/cosign, in-toto, S2C2F), notable incidents (SolarWinds SUNBURST, 3CX, Codecov, xz-utils CVE-2024-3094, event-stream, ua-parser-js), and detection/defense tooling (StepSecurity Harden-Runner, OpenSSF Scorecard, Socket, Sonatype Nexus, Snyk, Anchore Syft/Grype, KICS, Checkov, semgrep).
-
brucesongs Bundle Cloud Native Vuln ResearchCVE research methodology, PoC reproduction, patch gap analysis, and exploit chain composition across container/k8s/cloud-native surfaces; SBOM-driven vuln management and nuclei template authoring.
Audited -
brucesongs Bundle Data Loss Prevention BypassDLP bypass techniques covering steganography (LSB, audio, video), DNS tunneling, ICMP tunneling, cloud sync abuse (Dropbox, OneDrive), WebSocket/HTTP3 exfil, AI-augmented exfil (semantic chunking), and modern DLP evasion patterns.
-
brucesongs Bundle Confidential Computing AttackAttacks against Trusted Execution Environments (TEEs) and confidential computing platforms — Intel SGX (Foreshadow/SGAxe/LVI/ÆPIC Leak), Intel TDX, AMD SEV/SEV-ES/SEV-SNP (CrossLine/BadRAM), Azure CCF, Marblerun, and Gramine/Occlum libos enclaves. Covers side-channel leakage, attestation forgery, ABI misuse, host-to-enclave breakout, enclave-to-host escape, and recovery of sealed secrets. Distinct from hardware-security (broad hardware attacks) and firmware-reverse (UEFI/BIOS).
-
chainlesschain Skill Cc CLIInvoke ChainlessChain `cc` CLI commands from natural language. Triggers when the user wants to run any `cc …` action (skill / note / chat / ask / search / did / session / memory / mcp / cowork / agent / workflow / automation / pack / orchestrate / pipeline / kg / marketplace / did-v2 / activitypub / matrix / terraform / crosschain / etc.) without remembering the exact subcommand. Always discovers the current command set via `cc --help` at runtime, so newly added commands work without updating this skill.
-
zhouyinlong-lab Skill Repo EvaluatorGitHub 仓库评估器——多 Agent 并行评估任意开源项目的 6 类 30 项指标: 社区健康度(贡献者/增长率/Bus Factor)、维护性(提交频率/Issue解决时间)、 安全性(安全策略/漏洞披露)、文档质量(README/API文档/Changelog)、 采纳度(Stars/Forks/依赖数)、代码质量(测试覆盖率/CI/CD/审查实践)。 每项指标附源 URL 和时间戳,输出结构化评分报告。 Trigger keywords: 评估仓库, 评估项目, 仓库评估, repo evaluation, 开源项目评估, GitHub评估, 项目质量, 代码质量评估, 社区健康, 选开源项目, 评估依赖, oss evaluation, project audit, repo audit, 帮我看看这个仓库, 这个项目靠谱吗, evaluate repository。
-
nimadorostkar Skill CI CDUse when building or fixing a delivery pipeline. Covers pipeline structure, caching, test parallelization, deployment strategies, secrets, and making the pipeline fast enough that people do not route around it.
-
nimadorostkar Skill Ml PipelineUse when building or operating a machine learning pipeline. Covers feature engineering, training reproducibility, train/serve skew, deployment, monitoring for drift, and retraining.
-
nimadorostkar Skill AWS CdkUse when defining AWS infrastructure with the CDK. Covers construct design, stack organization, environment configuration, testing infrastructure code, and safe deployment.
-
nimadorostkar Skill TerraformUse when managing infrastructure as code with Terraform or OpenTofu. Covers module design, state management, drift, plan review, secrets, and applying changes without destroying production.
-
nimadorostkar Skill Data QualityUse when validating a dataset or building quality checks into a pipeline. Covers profiling, schema and constraint validation, freshness and completeness checks, anomaly detection, and failing a pipeline correctly.
-
nimadorostkar Skill KubernetesUse when deploying to or debugging Kubernetes. Covers workload configuration, resource requests and limits, probes, rollout strategy, networking, and the failure modes that produce CrashLoopBackOff and OOMKilled.
-
nimadorostkar Skill AWS ServerlessUse when building serverless systems on AWS. Covers Lambda design, cold starts, event-driven patterns with EventBridge and SQS, idempotency, step functions, and the limits that shape the architecture.
-
nimadorostkar Skill Supply ChainUse when assessing dependency and build-pipeline risk. Covers dependency vetting, lockfiles, SBOMs, provenance and signing, pinning CI actions, and responding to a compromised package.
Audited -
attac-t Bundle Craft CICrafting a CI pipeline. Five workflows, zero manual gates.
-
attac-t Bundle Craft ReleaseCrafting a release pipeline. One action, full pipeline.
-
handsomeboy990 Bundle CI CD PipelinesCI/CD Pipelines
-
handsomeboy990 Bundle Production VerificationProves that a deployed system actually works, by exercising it. Checks availability, version, authentication, critical journeys, data connectivity, assets, configuration, headers, logs and errors against the running deployment. A successful deploy command is not a verified deployment.
-
aradotso Skill MCP Security HubUse FuzzingLabs MCP Security Hub to integrate offensive security tools (Nmap, Nuclei, SQLMap, Ghidra, etc.) with AI assistants via Docker-based MCP servers
-
aradotso Skill Github MCP ServerOfficial GitHub MCP Server for AI-powered repository management, issue/PR automation, CI/CD monitoring, and code analysis through natural language
-
aradotso Skill Excalidraw MCP ServerBuild and deploy MCP servers that stream interactive Excalidraw diagrams with smooth viewport control
-
aradotso Skill Logos Router ReasoningDeploy and configure Logos Router for distributed semantic reasoning with zero-drift consensus across local AI nodes
-
minimax-ai Skill Comfyui DramaGenerate a complete short drama video from a storyboard. Use this Skill for scenarios 5–6 from `comfyui-studio`'s trigger index: 5=首帧 (drama first frame, two-character LoRA + prompt → 16:9 still) and 6=出片 (image-to-video, first frame + motion prompt → MP4 clip). The Skill also describes the full 7-stage pipeline around them (storyboard → TTS → script refinement → first frame → image-to-video → subtitle burn → audio/video assembly). Ships two preset workflow templates: `workflows/drama-first-frame.json` and `workflows/drama-image-to-video.json`.
12.9k -
minimax-ai Bundle Comfyui WorkflowSubmit a ComfyUI workflow JSON to a local 8188 server, monitor the queue, and download generated images. Use this Skill when the user wants to run a saved workflow, check whether ComfyUI is busy, fetch a generated image, list available checkpoints, or automate a reproducible generation pipeline.
Audited 12.9k -
minimax-ai Skill Long Term MemoryDesign a cross-session long-term memory system that extracts, consolidates, and cites durable knowledge from conversation rollouts. USE WHEN: building any system that needs to persist insights across sessions, designing "what should the next agent remember" pipelines, building memory workspaces with git baseline diffing, planning Phase 1/Phase 2 memory architectures, writing JSON-schema-constrained extraction prompts, deciding what NOT to write (no-op gate), or any task involving "memories that survive session boundaries". TRIGGER PHRASES: "long-term memory", "cross-session memory", "memory pipeline", "memory consolidation", "memory citation", "raw_memories.md", "MEMORY.md", "phase 1 extraction", "phase 2 consolidation", "watermark", "no-op gate", "git baseline diff". SKIP WHEN: single-session task state (use `world-state-tracking` instead), ephemeral/short task, no need to survive session boundaries, in-memory only.
Audited 12.9k -
poorvith-mp Bundle Pen TestRun authorised penetration tests and red team exercises against apps, networks and cloud. Use when planning or executing penetration tests and vulnerability validation.
-
poorvith-mp Bundle Cloud CostCut cloud spend with unit economics, rightsizing, showback and commitment planning. Use when optimizing AWS/GCP bills, right-sizing, or FinOps practices.
-
poorvith-mp Bundle DeploymentShip it: platform config for Vercel, Netlify, Fly, Railway, AWS, env secrets, checklists, and rollback. Use when deploying applications to cloud environments.
-
poorvith-mp Bundle SalesforceArchitect Salesforce: multi-cloud design, integration patterns, governor limits and deployment. Use when developing Apex, Lightning Web Components, or Salesforce flows.
-
poorvith-mp Bundle CI PipelinesBuild CI/CD with build, test, security scan and deploy stages across common providers. Use when setting up GitHub Actions, GitLab CI, or build pipelines.
-
poorvith-mp Bundle Cloud SecurityDesign identity boundaries, network segmentation, key management and workload isolation. Use when configuring cloud security, IAM least-privilege, or VPC perimeters.
-
poorvith-mp Bundle InfrastructureWrite Terraform, Pulumi or CloudFormation and automate provisioning, state and drift detection. Use when writing Terraform, OpenTofu, Pulumi, or cloud IaC manifests.
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include comfyui-drama, long-term-memory, repo-evaluator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.