DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
cyberstrikeus Skill Cis Gke V170 3 2 8Ensure that the --rotate-certificates argument is not present or is set to true (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 3 2 9Ensure that the RotateKubeletServerCertificate argument is set to true (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 1 1Ensure that the cluster-admin role is only used where required (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 1 2Minimize access to secrets (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 1 3Minimize wildcard use in Roles and ClusterRoles (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 1 4Ensure that default service accounts are not actively used (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 1 5Ensure that Service Account Tokens are only mounted where necessary (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 1 6Avoid use of system:masters group (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 1 7Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 4 1 8Avoid bindings to system:anonymous (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 1 9Avoid non-default bindings to system:unauthenticated (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 2 1Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 4 3 1Ensure that the CNI in use supports Network Policies (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 4 3 2Ensure that all Namespaces have Network Policies defined (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 4 1Prefer using secrets as files over secrets as environment variables (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 4 2Consider external secret storage (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 4 5 1Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 4 6 1Create administrative boundaries between resources using namespaces (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 4 6 2Ensure that the seccomp profile is set to RuntimeDefault in the pod definitions (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 4 6 3Apply Security Context to Pods and Containers (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 4 6 4The default namespace should not be used (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 1 1Ensure Image Vulnerability Scanning is enabled (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 1 2Minimize user access to Container Image repositories (Manual)
-
cyberstrikeus Skill Cis Gke V170 5 1 3Minimize cluster access to read-only for Container Image repositories (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 5 1 4Ensure only trusted container images are used (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 5 2 1Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 2 2Prefer using dedicated GCP Service Accounts and Workload Identity (Manual)
Audited -
cyberstrikeus Skill Cis Gke V170 5 3 1Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 4 1Ensure the GKE Metadata Server is Enabled (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 5 1Ensure Container-Optimized OS (cos_containerd) is used for GKE node images (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 5 2Ensure Node Auto-Repair is enabled for GKE nodes (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 5 3Ensure Node Auto-Upgrade is enabled for GKE nodes (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 5 4When creating New Clusters - Automate GKE version management using Release Channels (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 5 5Ensure Shielded GKE Nodes are Enabled (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 5 6Ensure Integrity Monitoring for Shielded GKE Nodes is Enabled (Automated)
Audited -
cyberstrikeus Skill Cis Gke V170 5 5 7Ensure Secure Boot for Shielded GKE Nodes is Enabled (Automated)
Audited
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include cis-gke-v170-3.2.8, cis-gke-v170-3.2.9, cis-gke-v170-4.1.1. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.