DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
cyberstrikeus Skill Cis Docker 1 1 6Ensure auditing is configured for Docker files and directories - /etc/docker
Audited -
cyberstrikeus Skill Cis Docker 1 1 7Ensure auditing is configured for Docker files and directories - docker.service
Audited -
cyberstrikeus Skill Cis Docker 1 1 8Ensure auditing is configured for Docker files and directories - containerd.sock
Audited -
cyberstrikeus Skill Cis Docker 1 1 9Ensure auditing is configured for Docker files and directories - docker.sock
Audited -
cyberstrikeus Skill Cis Docker 1 2 1Ensure the container host has been Hardened
Audited -
cyberstrikeus Skill Cis Docker 1 2 2Ensure that the version of Docker is up to date
Audited -
cyberstrikeus Skill Cis K8S V1120 4 1 7Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 1 8Ensure that the client certificate authorities file ownership is set to root:root (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 1 9If the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 2 1Ensure that the --anonymous-auth argument is set to false (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 2 2Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 2 3Ensure that the --client-ca-file argument is set as appropriate (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 2 4Verify that if defined, readOnlyPort is set to 0 (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 2 5Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 2 6Ensure that the --make-iptables-util-chains argument is set to true (Automated)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 2 7Ensure that the --hostname-override argument is not set (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 2 8Ensure that the eventRecordQPS argument is set to a level which ensures appropriate event capture (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 2 9Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 4 3 1Ensure that the kube-proxy metrics service is bound to localhost (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 1 1Ensure that the cluster-admin role is only used where required (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 1 2Minimize access to secrets (Manual)
-
cyberstrikeus Skill Cis K8S V1120 5 1 3Minimize wildcard use in Roles and ClusterRoles (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 1 4Minimize access to create pods (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 1 5Ensure that default service accounts are not actively used (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 1 6Ensure that Service Account Tokens are only mounted where necessary (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 1 7Avoid use of system:masters group (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 1 8Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 1 9Minimize access to create persistent volumes (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 2 1Ensure that the cluster has at least one active policy control mechanism in place (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 2 2Minimize the admission of privileged containers (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 2 3Minimize the admission of containers wishing to share the host process ID namespace (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 2 4Minimize the admission of containers wishing to share the host IPC namespace (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 2 5Minimize the admission of containers wishing to share the host network namespace (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 2 6Minimize the admission of containers with allowPrivilegeEscalation (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 2 7Minimize the admission of root containers (Manual)
Audited -
cyberstrikeus Skill Cis K8S V1120 5 2 8Minimize the admission of containers with the NET_RAW capability (Manual)
Audited
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include cis-docker-1.1.6, cis-docker-1.1.7, cis-docker-1.1.8. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.