Cloud Infrastructure for AI agents
100 security-reviewed cloud infrastructure listings, skills, MCP servers, and toolkits you can install into Claude Code, Cursor, and other agents with one command.
Wechat Mp Exporter
Use MP Ark to search, retrieve, and archive WeChat Official Account articles through an on-demand Lite workflow (terminal or temporary static HTML status) or an explicitly selected Docker full UI. Use when Codex needs user-approved QR login, account disambiguation, latest/today/article queries, safe HTML/Markdown/text retrieval, resumable deduplicated archives, backend diagnosis, or migration bet…
Nextflow Dsl2 Generator
Generates production Nextflow DSL2 process modules, handles tuple channel mapping, pins Docker containers, and configures AWS Batch / SLURM profiles.
Authentication Dotnet Cognito
Tích hợp Jarvis AWS Cognito qua Jarvis.Authentications.Cognito — CognitoClient và IAuthenticationService. Dùng khi auth qua user pool Cognito.
Authentication Dotnet
Thiết lập Jarvis Authentication — JWT Bearer, API Key, HTTP Basic, AWS Cognito qua AddJarvisAuthentication + Composite scheme. Dùng khi API ASP.NET Core cần xác thực Bearer, header API key, Basic hoặc Cognito qua Jarvis.Authentications.*.
Terraform Engineer
Terraform infrastructure as code across AWS, Azure, or GCP. Use for module development, state management, provider configuration, multi-environment workflows, infrastructure testing.
Azure Landing Zone Workload Integration
Integrate a workload into an existing enterprise Azure Landing Zone (application landing zone): discover the platform contract and inherited guardrails, split workload-team vs platform-team responsibilities, resolve inherited Azure Policy blocks and platform dependencies like central networking and private DNS, and produce compliant workload actions plus precise platform requests. Not for new-app…
Terraform Review
Method for reviewing Terraform/OpenTofu infrastructure-as-code changes for blast radius, state safety, and drift before apply. Use when reviewing a Terraform plan or diff, writing or changing .tf files, restructuring modules, or before running terraform apply. Reviews the implementation of a design — designing the infrastructure itself belongs to infra-design; for IAM/secret depth also use securi…
Infra Design
Simplest-first workflow for designing and proposing infrastructure — pin the requirements, draft the minimal design, then add complexity only where performance, reliability, security, or cost demands justify it. Use when designing new infrastructure, proposing a deployment or hosting architecture, choosing between managed services, planning capacity and scaling, or comparing infrastructure option…
Aws Diagram
|
Code Review Infra
Reviews infrastructure changes: GitHub Actions workflows, Terraform, Dockerfiles, docker-compose, IaC. Focuses on supply-chain pinning, secret handling, least-privilege permissions, action versions, and CI failure modes. Always verifies action hash pins when present.
Investigating Aws Incidents
Investigate a suspected AWS compromise from the control plane — CloudTrail management and data events (queried with Athena or CloudTrail Lake), GuardDuty findings, VPC Flow Logs, and CloudWatch — to reconstruct IAM/STS abuse, persistence, data access, and log tampering into a timeline. Use when the evidence is AWS API calls and cloud logs rather than a host. Preserve the logs before the attacker'…
Recognizing Deception
Spot defensive deception during an authorized engagement before you trigger it — canarytokens (HTTP/DNS/AWS-key/document/Slack/kubeconfig), Active Directory honey accounts and Kerberoast bait, decoy files, and honeypots — using provenance discipline and telltale patterns so a planted tripwire does not burn the operation. Use before acting on found credentials, roasting an SPN, or opening a too-co…
Investigating Azure Incidents
Investigate a suspected Azure and Entra ID compromise from the control plane — Azure Activity Log, Entra sign-in and audit logs, and the Microsoft 365 unified audit log, queried with KQL in Log Analytics/Sentinel — to reconstruct identity abuse, MFA and conditional-access bypass, service-principal and app-consent abuse, role changes, and Key Vault access. Use when the evidence is Azure/Entra logs…
Iac Security
Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s security policies, checking cloud infrastructure compliance, or authoring custom p…
Hardening Cloud Posture
Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage, over-broad roles, missing audit logging, unencrypted data), reading CSPM output critically, and enforcing guardrails at the org level. Use when reviewing a cloud environment's security posture, triaging a…
Exploiting Cloud Platforms
Exploit AWS, Azure, and GCP cloud misconfigurations including S3 buckets, IAM roles, metadata services, serverless functions, and cloud-specific privilege escalation. Use when pentesting cloud environments or assessing cloud security.
Container Security
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning Docker/OCI images, auditing K8s clusters, reviewing Dockerfiles, diffing SBOMs across releases, analyzing RBAC, or assessing container runtime postur…
Investigating Gcp Incidents
Investigate a suspected Google Cloud compromise from the control plane — Cloud Audit Logs (Admin Activity, Data Access, System Event, Policy Denied), Cloud Logging, and VPC Flow Logs — to reconstruct IAM and service-account abuse, key creation, data access, and log tampering into a timeline. Use when the evidence is GCP audit logs rather than a host. Service-account keys and IAM bindings are the…
Pimcore 12 Upgrade
Upgrade Pimcore 11 projects and bundles to Pimcore 12 - composer, config, PHP 8.3, Symfony 7, Docker, CI/CD, cors/dev, cors/saml
Cors Dev Setup
Set up or migrate a Pimcore project/bundle to use the cors/dev Docker Compose development environment
Cargo Cdk
Define an entire Cargo workspace in code — connectors, models, plays, tools, agents, MCP servers, context, capacities, territories, segments, folders, files, workers, apps — and deploy it declaratively with `cargo-ai cdk` (init → types → plan → deploy), the way you'd manage cloud infra with Pulumi or the AWS CDK. Use when the user wants to manage Cargo resources as code: reproducibly, version-con…
Cargo Hosting
Build, deploy, and manage Cargo Hosting apps and workers with the Cargo CLI — Vite SPAs served on *.cargo.app and serverless edge HTTP handlers, plus the deployments that ship and promote them. Use when the user wants to scaffold, deploy, promote, or manage a hosted app or worker on Cargo.
Gitlab Pages Ci
GitLab CI — test job and GitLab Pages job (artifact `public/`); `.gitlab-ci.yml` templates
Ops Reverse Proxy
Public deploy via Traefik/Nginx/frp on a VPS — inspect first; reverse proxy is **HTTP-only** by default (no TLS on the edge)
App Control
Open, close, and control applications on the computer
File Operations
Create, read, write, edit, move, copy, and delete files and directories
Gitlab Api
GitLab REST API — проекты, MR, issues, pipelines, файлы репозитория
Aws Ops
AWS EC2 — инстансы, VPC, subnets через aws_api tool
System Info
Get system information, check processes, disk usage, network status
Desktop Automation
Take screenshots, interact with desktop UI, capture screen content
Ops Tmux Remote Deploy
Run remote deploy via SSH using tmux sessions (frps + app), with idempotent restart and health checks
Code Execution
Run Python code, scripts, calculations, and data processing
Tektoncd Mcp Server
A Model Context Protocol server for the tektoncd projects
Operate Ai Stack
Develop, test, and troubleshoot this generated AI or ML workload across its framework, model and embedding providers, retrieval stores, interfaces, training, serving, and observability layers. Use when changing prompts, tools, agents, RAG, MCP, inference, fine-tuning, evaluations, or provider integration.
Project Workflow
Develop, test, and maintain this generated Python project using its recorded Copier choices and uv toolchain. Use for any code, dependency, configuration, documentation, or test change in this project, including simple libraries, CLIs, APIs, and layered AI or ML applications.
Deploy Python Project
Validate and deploy this generated Python project using its selected target, portable Docker base, and optional Pulumi or Terraform configuration. Use for deployment preparation, local container checks, cloud previews, release rollout, health verification, or deployment troubleshooting.
Validate Python Stack
Validate the Python Template repository or a project generated from it. Use before committing, publishing, deploying, or reviewing a stack to check catalog compilation, rendering, dependencies, formatting, tests, security workflows, skills, and representative runtime behavior.
Compose Python Stack
Design and generate a compatible project from the Python Template component layers or presets. Use when choosing a workload, framework, AI providers, data engines, interfaces, training and serving tools, deployment target, or IaC option; also use when a user wants a simple library, CLI, or API without AI.
Loomfeed
The open-source Reddit alternative built for AI agents and humans — provenance tracking, reputation, epistemic status labels, and agent debates. Self-host with docker compose.
Redteam Subdomain Takeover Detail Pack
Domain routing and boundary guidance for authorized subdomain takeover testing, including dangling CNAME records, NS takeover, and cloud service takeover paths such as S3, Azure, and Heroku. Use when a task belongs to the subdomain takeover domain and needs scope, evidence, pivot, or exit criteria.
Redteam Cloud Detail Pack
Domain routing and boundary guidance for authorized cloud security testing, including IAM misconfiguration, exposed storage, metadata services, and serverless injection. Use when a task belongs to the cloud testing domain and needs scope, evidence, pivot, or exit criteria.
Redteam Container Detail Pack
Domain routing and boundary guidance for authorized container and orchestration security testing, including Docker escape, Kubernetes privilege escalation, image vulnerabilities, and service mesh bypasses. Use when a task belongs to the container testing domain and needs scope, evidence, pivot, or exit criteria.
Creek
Open-source edge deployment platform. Deploy full-stack apps to Cloudflare Workers in seconds.
Meho
Governance backplane for AI agents acting on infrastructure — policy-gated, audit-grade, MCP-native. Apache 2.0.
Cockroach Crawler
Give AI agents bounded eyes on the public web: crawl, search, and normalize evidence without an unrestricted browser.
MCP Bridge Enhanced
MCP 内网穿透 Android 客户端 - 支持 Bore 隧道和 Cloudflare Tunnel,悬浮窗控制,服务保活
Omnimancer
A unified CLI for multiple AI language models with AWS Bedrock integration, MCP support, and autonomous agent capabilities. Access 13+ AI providers (Claude, OpenAI, Gemini, Bedrock, and more) through one interface with secure file operations, approval workflows, and agent-driven automation.
Sdr Mcp
RTL-SDR + MCP server: spectrum, waterfall, FM audio, station DB, GNU Radio demod — web dashboard and AI control via FastMCP 3.4
Secret Scanner
Static secret/token scanning for codebases and git repos: detects leaked credentials (AWS, GitHub, OpenAI, Anthropic, Stripe, Google, Slack, private keys, JWTs) using gitleaks v8.30.1 pattern table + Shannon entropy gating + allowlist noise filters. Stdlib-only Python script with JSON/Markdown/text reports, redaction, CI exit-code gate.
Sample Fraud Investigation Assistance Using Aws Bedrock Strandsagents Mcp
The Fraud Investigator Assistant shows how AWS Bedrock, MCP servers, and Strands expert agents can transform fraud investigations. By combining private MCP servers for secure data with open-source MCPs for public intelligence, it speeds up case analysis and ensures compliance, reducing investigation timelines significantly.
Agentic AI Engineer
My complete journey to becoming an Agentic AI Engineer through structured learning, projects, experiments, and production-ready implementations of modern AI systems.
Ai901 Cert Buddy Claude
AI-901 (Azure AI Fundamentals) study buddy built natively for Claude Code: exam-realistic questions, Microsoft Foundry labs, and study plans, grounded in Microsoft Learn via MCP, with subagents, skills, slash commands, and deterministic hook guardrails.
HuaweiCloud Devkit
华为云全能力插件 一集成 KooCLI、SDK、Terraform、APIG、Skills、MCP 六大开放能力,开箱即用;用自然语言操作云资源,开启智能云管理新体验。
Weather
Look up a location's weather forecast using a live web search. Invoke whenever the user asks about the weather, whether to expect rain, temperature, or what to wear or plan for outdoor activities.
Greeter
Greets a user by name in a friendly, concise sentence.
Github Issues
Read, summarize, and triage GitHub issues and pull requests for a repository using the authenticated GitHub MCP server. Invoke whenever the user asks about open issues, wants a repo's issues summarized or triaged, asks to find issues by label or author, or asks to draft an issue.
Red
Placeholder skill so the bundle passes plugin-format validation.
Green
Placeholder skill so the bundle passes plugin-format validation.
Broken
Placeholder skill so the bundle passes plugin-format validation.
Text Stats
Compute word count, character count, or reading time for a piece of text using the in-bundle text-stats engine. Invoke whenever the user asks how long a passage is, how many words or characters it has, or how long it takes to read.
Skills Keys
Manage API keys for the runner's --execute layer. CRUD on ~/.skills.env (chmod 600): list / add / update / remove / verify / export. Covers OpenAI, Gemini, BFL, FAL, Replicate, Runway, Kling, Suno, Eleven, Ideogram, Anthropic, S3. Use when: 'add my OpenAI key', 'rotate the Suno key', 'which keys are set', 'verify my key works'.
Macos Disk Cleanup
診斷並清理 macOS 磁碟空間,特別是「系統資料 / System Data」這類看不出內容的用量。涵蓋開發者工具殘骸(Xcode iOS DeviceSupport、Simulator runtime、DerivedData)、套件管理器快取(Homebrew、pnpm、pip、npm、cargo、go、uv)、容器與 VM 磁碟(Docker、podman、lima)、瀏覽器 profile、以及已移除 app 的孤兒 container。使用時機:(1) 使用者說磁碟快滿了、System Data 佔太多、想清空間 (2) 詢問某個資料夾或快取能不能刪 (3) 移除 app 後想清乾淨殘留檔案、完整解除安裝 (4) 想知道 Docker.raw、Group Containers、Library/Caches 這些是什麼、佔了多少。Also triggers in English…
Projektor
Self hosted Wiki + Jira-style AI native issue tracker on Cloudflare Workers
Deadline Cloud
Submit and manage rendering jobs on AWS Deadline Cloud, the AWS managed render farm service, from Python, the command line, or third party software.
Libre Webui
A local-first workspace for chat, private knowledge, artifacts, and isolated model-driven work. Self-hosted. Provider-flexible. Apache 2.0.
Classical Poem Silk Video
Turn Chinese classical poems and ci into coherent vertical Chinese-art videos with poem-driven scene grouping, GPT ImageGen stills, Docker-only Gemini I2V, retained model-generated ambience, Gemini sparkle-watermark cleanup, brush-calligraphy captions revealed character by character, optional local BGM mixing, stitching, and final-frame QA. Supports verse-driven variation across ink landscape, go…
Openchoreo
OpenChoreo is an internal developer platform for Kubernetes
Openmake Llm
Open-source, self-hosted AI workspace for local and open-weight LLMs with vLLM, LiteLLM, autonomous agents, MCP tools, deep research, artifacts, and BYOK.
Md Page
Instantly turn Markdown into a shareable web page. Self-hostable open-source engine of md.page.
Crewhelm
MCP control plane for AI agents on Cloudflare
Shopify App
Production patterns for embedded Shopify apps with React Router v7,
CampaignRepo
A self-hosted, Git-backed campaign manager for tabletop RPGs with wiki pages, player-safe portals, maps, sessions, quests, imports, AI tools, and MCP support.
SerpScrap
SerpScrap retrieves structured search results for SEO, research, and automation. It is available as a Python package, a CLI, a Docker application, and an MCP-compatible server. Results are JSON-compatible and preserve the source engine, rank, URL, title, snippets, result type, and typed failures.
Ultimate Scraper
Scrapes web pages with intelligent tier escalation and AI extraction. Use when user provides a URL and needs to extract content, bypass anti-bot protection, or parse protected pages. Handles static data extraction (__NEXT_DATA__, JSON-LD), TLS fingerprint spoofing, stealth browsers (CloakBrowser + Patchright), Cloudflare bypass, CAPTCHA solving, proxy rotation, rate limiting, session persistence,…
Camofox Browser
Anti-detection browser automation using Camoufox (Firefox fork with C++ fingerprint spoofing). Use when standard browser tools get blocked by Cloudflare, Akamai, or bot detection. Triggers include "stealth browse", "anti-detection", "bypass bot", "camofox", "blocked by Cloudflare", scraping protected sites (X/Twitter, Amazon, Product Hunt), or when agent-browser/playwright fails with bot detectio…
Ephemeral Sandbox
Open-source agent sandbox infrastructure for parallel coding agents: isolated workspaces, MCP/CLI control, observability, and atomic publication.
Vmware Aiops
>
VMware AIops
VMware vCenter/ESXi AI-powered monitoring and operations. Two skills: vmware-monitor (read-only, safe) and vmware-aiops (full operations) | Claude Code Skill
Browser Search
A skill for AI agents: search the web with SearXNG, browse with Camofox, bypass protections with CloakBrowser. Anti-hallucination by design. Self-hosted, free, unlimited.
Five9 Mcp
Zero-dependency MCP server that puts your Five9 domain in your AI's hands. 73 tools for campaigns, users, skills, lists, dispositions, and IVRs. Works with Claude and ChatGPT, one-click deploy to Cloudflare Workers.
Boxkite
Self-hostable sandbox for agent code execution — SandboxManager, control-plane, 4 SDKs, MCP server, running inside real Kubernetes pod isolation
Agentic RAG Knowledge Base
Local-first Agentic RAG knowledge base with hybrid retrieval, ReAct agent, Vue UI, Ollama/DeepSeek/OpenAI, MCP and Docker.
Kina Microvm
Run microVM-isolated Kubernetes workloads on Apple Silicon using kina, the Kubernetes-in-Apple-Containers analogue of kind. Use when developing kubernetes-sigs/agent-sandbox workloads on macOS where Kata Containers cannot run, when each k8s node must be an Apple Container microVM, or when applying SandboxTemplates without a per-pod runtimeClassName because the cluster itself is the microVM isolat…
K8s Agent Sandbox
Install and operate the kubernetes-sigs/agent-sandbox controller and CRDs for per-session, isolated AI agent pods on Kubernetes. Use when authoring SandboxTemplate / SandboxClaim manifests, configuring SandboxWarmPool for sub-second provisioning, applying default-deny NetworkPolicy, choosing between Kata Containers and gVisor as the RuntimeClass, or comparing managed GKE Agent Sandbox to the upst…
Sandbox
Index for agent-sandboxing approaches — routes to the right sub-skill based on host OS, isolation tier, and deployment scale. Use when picking a sandboxing strategy for an AI coding agent, comparing kernel-level isolation (gVisor) vs microVM isolation (Kata, Apple Container, Docker), choosing between Kubernetes-orchestrated and single-host CLI approaches, or unsure which agent-sandboxing skill to…
Kata On Kind
Install Kata Containers on a local kind cluster via the kata-deploy DaemonSet, registering the kata-qemu RuntimeClass so agent-sandbox SandboxTemplates can request microVM isolation. Use when standing up a Linux dev loop for microVM-isolated pods, verifying nested-KVM prerequisites, or pairing kind with kubernetes-sigs/agent-sandbox for local hacking.
Kata On Gke
Install Kata Containers on a self-managed GKE node pool to run microVM-isolated agent workloads via kubernetes-sigs/agent-sandbox. Use when managed GKE Agent Sandbox (gVisor-only) is not enough, when running Claude Code or similar agents on GKE with hardware-level isolation, or when configuring N2 Intel Ubuntu nodes with nested virtualization for the upstream kata-gke-sandbox recipe.
Agent Substrate Overview
Reference for the alpha agent-substrate/substrate project as an alternative ultra-scale control plane that shares snapshot and runtime primitives with kubernetes-sigs/agent-sandbox. Use when comparing agent-sandbox vs Substrate, evaluating the WorkerPool + ActorTemplate multiplexing model, reviewing the kubectl-ate CLI, or deciding which control plane fits a workload that needs millions of sub-se…
Twelve Factor
Guide for 12-Factor cloud-native applications. Use when designing microservices, configuring containers, deploying to Kubernetes, or following cloud-native patterns.
Diverge
Structured divergence engine. Generates a wide, deliberately non-anchored set of approaches to a consequential, open-ended problem by spawning isolated parallel sub-agents under different cognitive frames, then a separate critic pass scores, declusters, and deepens the best. The divergent complement to /deep-analysis. Use for high-stakes architecture, strategy, design-space, and "what are our opt…
Context Escalation
Explicit-level policy for context management in long-horizon Claude Code sessions. Five escalating responses to context pressure — apply the cheapest intervention that still preserves the work. Auto-activates on context limit, near context limit, conversation getting long, /compact, handoff, /save-session.
Remote Triggers
Cross-session automation using RemoteTrigger API. Create, manage, and run scheduled remote agents that execute on cron schedules and survive session exit. Auto-activates on remote trigger, scheduled agent, cross-session, persistent schedule, automated agent, trigger API.
Api Contract Testing
Tools and patterns for API contract testing using OpenAPI, JSON Schema, and contract-first development
Api Guidelines
Comprehensive guidelines for building secure, consistent, and modern API endpoints in Next.js with TypeScript
Deployment Runbook
Deployment procedures, health checks, and rollback strategies. Use this skill when deploying applications, performing health checks, managing releases, or handling deployment failures. Provides systematic deployment workflows, verification scripts, and troubleshooting guides. Complements the devops-automation agent.
Handoff
Create HANDOFF.md files for session continuity between conversations. Use when ending a session, switching context, or before /compact.
Deep Read
Comprehensive codebase reading engine. Systematically reads actual source code line by line through a 6-phase protocol — scoping, structural mapping, execution tracing, deep reading, pattern synthesis, and structured reporting. Source code is the source of truth. Use when needing to truly understand how code works, not just what documentation claims.
Ui Guidelines
Comprehensive UI/UX guidelines for building React/Next.js components with Ant Design, shadcn/ui charts, and consistent styling. Use when creating forms, tables, modals, cards, or any UI component. Enforces color palette, typography, spacing (8px/12px/16px/24px), animations, and component patterns specific to the application.
Infrastructure As Code
Infrastructure as Code decision framework, testing pyramid, CI/CD for infrastructure, state management, module composition, policy-as-code, and drift detection. Covers Terraform, CloudFormation, CDK, Pulumi patterns. Auto-activates on Terraform, CloudFormation, CDK, Pulumi, infrastructure as code, IaC, module, state, tfstate, HCL, stack, drift.
Browser Testing
E2E browser testing with Playwright MCP. Visual regression, responsive design, cross-browser testing, codegen sessions. Auto-activates on e2e test, visual regression, screenshot test, browser test, Playwright, responsive test, cross-browser, visual verification.