DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
hmzainjamil Skill Ugc AgencyUGC Agency — Arcads AI Actor Pipeline
-
hmzainjamil Skill Vibe ProspectingVibe Prospecting MCP wrapper — fetch-entities, enrich-prospects, export-to-csv. Actor 2 in lead-gen-ai pipeline AND SOURCE 2 in hmz-daily-leads sweep. Find any business type in any city worldwide.
-
pitimon Bundle Cybersecurity ProUse when asked to generate professional cybersecurity documents — IR playbooks, DFIR forensic reports, SOC L1–L3 triage runbooks, DevSecOps pipeline configs, threat models, compliance gap analyses, or executive cyber-risk reports. Covers 22 domains across AppSec / Cloud / OT / AI-ML / API / Identity / Web3, bilingual Thai+English output mapped to NIST 800-53, MITRE ATT&CK, OWASP, ISO 27001. Also: post-pentest defensive (Shannon handoff manifest). Triggers: "incident response", "SOC triage", "DFIR", "threat hunt", "compliance audit", "การตอบสนองต่อเหตุการณ์", "post-pentest defensive".
-
hmzainjamil Bundle Apify ActorizationActorization converts existing software into reusable serverless applications compatible with the Apify platform. Actors are programs packaged as Dock
-
hmzainjamil Skill Website Lead AgencyMaster revenue engine: website-builder + lead-gen-ai + HMZ daily sweeps. Find clients via 4 automated daily sweeps → build demo sites → close. 10-actor pipeline + 4 scheduled sweeps running autonomously.
-
0x67108864 Bundle Persistent KbMaintain a local SQLite-backed knowledge base for cross-session agent memory. Save discovered facts, lessons, and references with tags and full-text search, then retrieve them in future sessions to avoid re-discovering the same information. Use when the user wants the agent to remember facts beyond the current chat (decisions, project context, prior research, lessons learned), reduce redundant work across sessions, or build a personal knowledge base. Unlike cloud memory services, this skill stores everything locally in a single SQLite file.
-
vijayjoshi24 Skill Tech Debt ScanScan an Azure DevOps repository or pasted codebase description to quantify technical debt by domain and severity. Activate whenever someone mentions tech debt, code quality, architecture health, modernisation readiness, or asks what needs fixing in a codebase — including: "analyze my repo for tech debt", "score our architecture debt", "what's the state of our code", "find gaps in our codebase", "modernisation assessment", "what should we fix first", or when /discover codebase is invoked. Also activates when a user pastes a file tree, dependency list, or code snippet and asks for an assessment.
-
santosomar Bundle Attack Ics T0851 RootkitAnalyze MITRE ATT&CK T0851 Rootkit in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0851, Rootkit, or ics ATT&CK. Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
-
rycen7822 Skill Teams Meeting PipelineProcess Microsoft Teams meeting transcripts, recordings, speaker turns, summaries, action items, and follow-up notes through a local pipeline.
-
pettha Skill Ship To ProdEnd-to-end deploy of a feature branch to production on Hetzner.
-
santosomar Bundle Attack Ics T0843 001 Download AllAnalyze MITRE ATT&CK T0843.001 Download All in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0843.001, Download All, or ics ATT&CK. Adversaries may execute a full program download to a PLC to overwrite the entire PLC program and configuration to deploy a new project or make major changes.
-
santosomar Bundle Attack Ent T1059 009 Cloud APIAnalyze MITRE ATT&CK T1059.009 Cloud API in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.009, Cloud API, or enterprise ATT&CK. Adversaries may abuse cloud APIs to execute malicious commands.
-
santosomar Bundle Attack Ent T1583 007 ServerlessAnalyze MITRE ATT&CK T1583.007 Serverless in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.007, Serverless, or enterprise ATT&CK. Adversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting.
-
santosomar Bundle Attack Ent T1584 007 ServerlessAnalyze MITRE ATT&CK T1584.007 Serverless in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584.007, Serverless, or enterprise ATT&CK. Adversaries may compromise serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting.
-
santosomar Bundle Attack Ent T1610 Deploy ContainerAnalyze MITRE ATT&CK T1610 Deploy Container in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1610, Deploy Container, or enterprise ATT&CK. Adversaries may deploy a container into an environment to facilitate execution or evade defenses.
-
santosomar Bundle Attack Ent T1069 003 Cloud GroupsAnalyze MITRE ATT&CK T1069.003 Cloud Groups in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1069.003, Cloud Groups, or enterprise ATT&CK. Adversaries may attempt to find cloud groups and permission settings.
-
santosomar Bundle Attack Ent T1136 003 Cloud AccountAnalyze MITRE ATT&CK T1136.003 Cloud Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1136.003, Cloud Account, or enterprise ATT&CK. Adversaries may create a cloud account to maintain access to victim systems.
-
santosomar Bundle Attack Ent T1078 004 Cloud AccountsAnalyze MITRE ATT&CK T1078.004 Cloud Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1078.004, Cloud Accounts, or enterprise ATT&CK. Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
santosomar Bundle Attack Ent T1087 004 Cloud AccountAnalyze MITRE ATT&CK T1087.004 Cloud Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087.004, Cloud Account, or enterprise ATT&CK. Adversaries may attempt to get a listing of cloud accounts.
-
santosomar Bundle Attack Ent T1585 003 Cloud AccountsAnalyze MITRE ATT&CK T1585.003 Cloud Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1585.003, Cloud Accounts, or enterprise ATT&CK. Adversaries may create accounts with cloud providers that can be used during targeting.
-
santosomar Bundle Attack Ent T1586 003 Cloud AccountsAnalyze MITRE ATT&CK T1586.003 Cloud Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1586.003, Cloud Accounts, or enterprise ATT&CK. Adversaries may compromise cloud accounts that can be used during targeting.
-
santosomar Bundle Attack Ent T1556 007 Hybrid IdentityAnalyze MITRE ATT&CK T1556.007 Hybrid Identity in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1556.007, Hybrid Identity, or enterprise ATT&CK. Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credentials, and enable persi…
-
santosomar Bundle Attack Ent T1686 001 Cloud FirewallAnalyze MITRE ATT&CK T1686.001 Cloud Firewall in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1686.001, Cloud Firewall, or enterprise ATT&CK. Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
-
santosomar Bundle Attack Ent T1021 007 Cloud ServicesAnalyze MITRE ATT&CK T1021.007 Cloud Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021.007, Cloud Services, or enterprise ATT&CK. Adversaries may log into accessible cloud services within a compromised environment using [Valid Accounts](https://attack.mitre.org/techniques/T1078) that are synchronized with or federated to on-premises user identitie…
-
santosomar Bundle Attack Ent T1578 001 Create SnapshotAnalyze MITRE ATT&CK T1578.001 Create Snapshot in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1578.001, Create Snapshot, or enterprise ATT&CK. An adversary may create a snapshot or data backup within a cloud account to evade defenses.
-
santosomar Bundle Attack Ent T1648 Serverless ExecutionAnalyze MITRE ATT&CK T1648 Serverless Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1648, Serverless Execution, or enterprise ATT&CK. Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
-
santosomar Bundle Attack Ent T1525 Implant Internal ImageAnalyze MITRE ATT&CK T1525 Implant Internal Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1525, Implant Internal Image, or enterprise ATT&CK. Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment.
-
santosomar Bundle Attack Ent T1530 Data From Cloud StorageAnalyze MITRE ATT&CK T1530 Data from Cloud Storage in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1530, Data from Cloud Storage, or enterprise ATT&CK. Adversaries may access data from cloud storage.
-
santosomar Bundle Attack Ent T1538 Cloud Service DashboardAnalyze MITRE ATT&CK T1538 Cloud Service Dashboard in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1538, Cloud Service Dashboard, or enterprise ATT&CK. An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features.
-
santosomar Bundle Attack Ent T1677 Poisoned Pipeline ExecutionAnalyze MITRE ATT&CK T1677 Poisoned Pipeline Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1677, Poisoned Pipeline Execution, or enterprise ATT&CK. Adversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process.
-
santosomar Bundle Attack Ent T1578 003 Delete Cloud InstanceAnalyze MITRE ATT&CK T1578.003 Delete Cloud Instance in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1578.003, Delete Cloud Instance, or enterprise ATT&CK. An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence.
-
santosomar Bundle Attack Ent T1671 Cloud Application IntegrationAnalyze MITRE ATT&CK T1671 Cloud Application Integration in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1671, Cloud Application Integration, or enterprise ATT&CK. Adversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service environment.
-
santosomar Bundle Attack Ent T1537 Transfer Data To Cloud AccountAnalyze MITRE ATT&CK T1537 Transfer Data to Cloud Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1537, Transfer Data to Cloud Account, or enterprise ATT&CK. Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
-
santosomar Bundle Attack Ent T1651 Cloud Administration CommandAnalyze MITRE ATT&CK T1651 Cloud Administration Command in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1651, Cloud Administration Command, or enterprise ATT&CK. Adversaries may abuse cloud management services to execute commands within virtual machines.
-
santosomar Bundle Attack Ent T1098 003 Additional Cloud RolesAnalyze MITRE ATT&CK T1098.003 Additional Cloud Roles in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098.003, Additional Cloud Roles, or enterprise ATT&CK. An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant.
-
santosomar Bundle Attack Ent T1666 Modify Cloud Resource HierarchyAnalyze MITRE ATT&CK T1666 Modify Cloud Resource Hierarchy in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1666, Modify Cloud Resource Hierarchy, or enterprise ATT&CK. Adversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses.
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include ugc-agency, vibe-prospecting, cybersecurity-pro. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.