DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
usmanskillsmd Skill Pulumi Typescriptpulumi typescript — production-ready pulumi configuration and management for AWS/GCP/Azure infrastructure.
-
usmanskillsmd Skill Arcane Docker Managerarcane-docker-manager
-
usmanskillsmd Skill Cloud Cost Alertingcloud cost alerting — production-ready FinOps configuration and management for multi-cloud infrastructure.
-
usmanskillsmd Skill GCP Cloud Functionsgcp cloud functions — production-ready gcp configuration and management for cloud infrastructure.
-
usmanskillsmd Skill Afrexai Cloud Cost Auditafrexai-cloud-cost-audit
-
usmanskillsmd Skill Implementing Zero Trust In CloudThis skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access control
-
usmanskillsmd Skill Microsoft Azure AI Translation Document Pyazure-ai-translation-document-py
-
usmanskillsmd Skill Microsoft Azure AI Vision Imageanalysis Pyazure-ai-vision-imageanalysis-py
-
usmanskillsmd Skill Microsoft Azure Keyvault Certificates Rustazure-keyvault-certificates-rust
-
usmanskillsmd Skill Implementing Ot Network Traffic Analysis With NozomiDeploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial co
-
usmanskillsmd Skill Azure Enterprise Infra PlannerArchitect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource
-
usmanskillsmd Skill Microsoft Azure Monitor Opentelemetry Pyazure-monitor-opentelemetry-py
-
usmanskillsmd Skill Azure Monitor Opentelemetry TSInstrument applications with Azure Monitor and OpenTelemetry for JavaScript (@azure/monitor-opentelemetry). Use when adding distributed tracing, metrics, and logs to Node.js applications with Applicat
-
usmanskillsmd Skill Detecting Cryptomining In CloudThis skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage
-
usmanskillsmd Skill Microsoft Azure AI Agents Persistent Javaazure-ai-agents-persistent-java
-
usmanskillsmd Skill Implementing Infrastructure As Code Security ScanningThis skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform,
-
usmanskillsmd Skill Implementing Deception Based Detection With CanarytokenDeploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.
-
usmanskillsmd Skill Implementing Network Intrusion Prevention With SuricataDeploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking.
-
usmanskillsmd Skill Implementing Privileged Access Management With CyberarkDeploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c
-
usmanskillsmd Skill Auditing Kubernetes Cluster RbacAuditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using ku
-
usmanskillsmd Skill Detecting Azure Lateral MovementDetect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, to
-
usmanskillsmd Skill Exploiting Broken Link HijackingDiscover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker.
-
usmanskillsmd Skill Openclaw Youtube Transcript Pipeline Liteyoutube-transcript-pipeline-lite
-
usmanskillsmd Skill Microsoft Azure Webjobs Extensions Authentication Events DotMicrosoft Entra Authentication Events SDK for .NET. Azure Functions triggers for custom authentication extensions.
-
usmanskillsmd Skill Implementing Next Generation Firewall With Palo AltoConfigure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security.
-
usmanskillsmd Skill Implementing Vulnerability Management With GreenboneDeploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.
-
usmanskillsmd Skill Performing GCP Penetration Testing With GcpbucketbrutePerform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditing
-
usmanskillsmd Skill Microsoft Azure Webjobs Extensions Authentication Events 2Microsoft Entra Authentication Events SDK for .NET. Azure Functions triggers for custom authentication extensions. Use for token enrichment, custom claims, attribute collection, and OTP customization
-
vbrevik Bundle API FuzzDynamic API security testing using OWASP OFFAT. Fuzzes API endpoints for auth bypass, input injection, schema violations, and information disclosure. Falls back to curl-based probe testing when OFFAT is unavailable. Produces STIG V-ID-tagged findings for /stig-compliance pipeline. Use when (1) testing API endpoints for auth boundary gaps, (2) validating input validation/sanitization, (3) checking error handling for information disclosure, (4) before deploying API changes. Requires running target server. Works air-gapped.
-
vbrevik Bundle Secret ScanScan git repositories for leaked secrets (API keys, passwords, tokens, certificates) using gitleaks. Detects secrets in git history and current code. Produces STIG V-ID-tagged findings that feed into /stig-compliance as pipeline evidence. Use when (1) reviewing code changes for accidental secret commits, (2) auditing git history for previously committed secrets, (3) /stig-compliance review needs secret detection evidence. Works air-gapped.
-
txampa Bundle Odoo IntegrationUse this skill when the user needs to connect to Odoo via XML-RPC, sync Odoo data to external systems (Google Sheets, databases, APIs), read or write Odoo models (stock.picking, sale.order, purchase.order, product.product, etc.), set up cron-based sync jobs, or deploy Odoo integrations on Railway/Render/Fly.io. Also use when the user mentions albaranes, pedidos, stock, ERP sync, or Odoo automation. Do NOT trigger for generic REST API tasks or non-Odoo ERP systems.
-
lap-platform Bundle Storagemanagementclient 8StorageManagementClient API skill. Use when working with StorageManagementClient for providers, subscriptions. Covers 19 endpoints.
6 -
vbrevik Bundle Static AnalysisRun deterministic static code analysis using semgrep with STIG-mapped rules. Produces findings tagged with DISA STIG V-IDs that feed into /stig-compliance as pipeline evidence. Use when (1) building a prompt contract that involves security-sensitive code (guard mode injects tool constraints), (2) reviewing code changes for security issues (review mode runs semgrep), (3) /stig-compliance review needs deterministic evidence before semantic review. Supports any language semgrep supports (TypeScript, Python, Go, Java, C/C++, etc.). Works air-gapped with bundled rules.
-
vbrevik Bundle Container SecurityScan container images, Dockerfiles, docker-compose files, and Kubernetes manifests for security misconfigurations and vulnerabilities. Uses Trivy for image/IaC scanning and Kubescape for K8s policy compliance. Falls back to regex-based Dockerfile and K8s YAML analysis when tools are unavailable. Produces STIG V-ID-tagged findings for /stig-compliance pipeline. Use when (1) reviewing Docker or K8s configuration changes, (2) scanning container images for OS-level CVEs, (3) validating K8s RBAC and NetworkPolicy configuration, (4) before deployment. Works air-gapped with pre-downloaded vulnerability database.
-
juanmarchetto Bundle E2e PipelineGenerate and run E2E tests for mobile and web apps. Discovers screens, states, and flows via static analysis, generates Maestro test flows with assertions, executes them, and reports pass/fail results. Use when: run e2e, test flows, e2e tests, generate tests, automated testing.
-
lap-platform Bundle Fabricadminclient 14FabricAdminClient API skill. Use when working with FabricAdminClient for subscriptions. Covers 2 endpoints.
6
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include pulumi-typescript, arcane-docker-manager, cloud-cost-alerting. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.