DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
cyberstrikeus Skill Cis K8S V1110 5 7 1Create administrative boundaries between resources using namespaces (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1110 5 7 2Ensure that the seccomp profile is set to docker/default in your pod definitions (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1110 5 7 3Apply Security Context to Your Pods and Containers (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1110 5 7 4The default namespace should not be used (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 1 1Ensure that the API server pod specification file permissions are set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 1 2Ensure that the API server pod specification file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 1 3Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 1 4Ensure that the controller manager pod specification file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 1 5Ensure that the scheduler pod specification file permissions are set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 1 6Ensure that the scheduler pod specification file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 1 7Ensure that the etcd pod specification file permissions are set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 1 8Ensure that the etcd pod specification file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 1 9Ensure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 2 1Ensure that the --anonymous-auth argument is set to false (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 2 2Ensure that the --token-auth-file parameter is not set (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 2 3Ensure that the DenyServiceExternalIPs is set (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 2 4Ensure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 2 5Ensure that the --kubelet-certificate-authority argument is set as appropriate (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 2 6Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 2 7Ensure that the --authorization-mode argument includes Node (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 2 8Ensure that the --authorization-mode argument includes RBAC (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 2 9Ensure that the admission control plugin EventRateLimit is set (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 3 1Ensure that the --terminated-pod-gc-threshold argument is set as appropriate (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 3 7Ensure that the --bind-address argument is set to 127.0.0.1 (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 1 4 2Ensure that the --bind-address argument is set to 127.0.0.1 (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 3 1 1Client certificate authentication should not be used for users (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 3 1 2Service account token authentication should not be used for users (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 3 1 3Bootstrap token authentication should not be used for users (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 3 2 2Ensure that the audit policy covers key security concerns (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 4 1 3If proxy kubeconfig file exists ensure permissions are set to 600 or more restrictive (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 4 1 5Ensure that the --kubeconfig kubelet.conf file permissions are set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 4 1 7Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 4 1 9If the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 4 2 1Ensure that the --anonymous-auth argument is set to false (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1111 4 2 4Verify that if defined, readOnlyPort is set to 0 (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1111 4 2 5Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Manual)
Audited
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include cis-k8s-v1110-5.7.1, cis-k8s-v1110-5.7.2, cis-k8s-v1110-5.7.3. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.