DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
cyberstrikeus Skill Cis K8S V1120 1 1 8Ensure that the etcd pod specification file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 1 9Ensure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 2 1Ensure that the --anonymous-auth argument is set to false (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 2 2Ensure that the --token-auth-file parameter is not set (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 2 3Ensure that the DenyServiceExternalIPs is set (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 2 4Ensure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 2 5Ensure that the --kubelet-certificate-authority argument is set as appropriate (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 2 6Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 2 7Ensure that the --authorization-mode argument includes Node (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 2 8Ensure that the --authorization-mode argument includes RBAC (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 2 9Ensure that the admission control plugin EventRateLimit is set (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 3 1Ensure that the --terminated-pod-gc-threshold argument is set as appropriate (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 3 2Ensure that the --profiling argument is set to false (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 3 3Ensure that the --use-service-account-credentials argument is set to true (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 3 4Ensure that the --service-account-private-key-file argument is set as appropriate (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 3 5Ensure that the --root-ca-file argument is set as appropriate (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 3 6Ensure that the RotateKubeletServerCertificate argument is set to true (Automated)
-
cyberstrikeus Skill Cis K8S V1120 1 3 7Ensure that the --bind-address argument is set to 127.0.0.1 (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 4 1Ensure that the --profiling argument is set to false (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 1 4 2Ensure that the --bind-address argument is set to 127.0.0.1 (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 3 1 1Client certificate authentication should not be used for users (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 3 1 2Service account token authentication should not be used for users (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 3 1 3Bootstrap token authentication should not be used for users (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 3 2 1Ensure that a minimal audit policy is created (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 3 2 2Ensure that the audit policy covers key security concerns (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 1 1Ensure that the kubelet service file permissions are set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 1 2Ensure that the kubelet service file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 1 3If proxy kubeconfig file exists ensure permissions are set to 600 or more restrictive (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 1 4If proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 1 5Ensure that the --kubeconfig kubelet.conf file permissions are set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 1 6Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill T1535 Unusedunsupported Cloud RegionsAdversaries may create cloud instances in unused geographic service regions in order to evade detection.
Audited -
cyberstrikeus Skill T1666 Modify Cloud Resource HierarchyAdversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses.
Audited -
cyberstrikeus Skill T1562 008 Disable Or Modify Cloud LogsAn adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection.
-
cyberstrikeus Skill T1021 008 Direct Cloud Vm ConnectionsAdversaries may leverage Valid Accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods.
Audited -
cyberstrikeus Skill T1548 005 Temporary Elevated Cloud AccessAdversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
Audited
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include cis-k8s-v1120-1.1.8, cis-k8s-v1120-1.1.9, cis-k8s-v1120-1.2.1. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.