Install
$ agentstack add skill-alexei-led-cc-thingz-operating-infra ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Operate Infrastructure
Boundary
- Work from files, plans, logs, and read-only commands before changing anything.
- Do not run apply, delete, destroy, or rollback until identity, exact resources, blast radius, and plan/diff/inventory are shown and the user confirms.
- If the task is deployment, rollout, rollback, or production apply, use
deploying-infra. - If the task is only shell scripts or generic command pipelines, use
writing-shell.
Role behavior
- Write-capable: make minimal file changes and run safe validation. Stop before live mutation unless the user confirmed exact resources.
- Read-only: apply nothing; return proposed file changes, evidence, and validation commands.
Load references
Load every matching reference:
- Terraform/OpenTofu files, modules, state, or plans → [terraform.md](references/terraform.md)
- Kubernetes manifests or
kustomization.yaml→ [kubernetes.md](references/kubernetes.md) Chart.yaml, Helm values, or chart templates → [helm.md](references/helm.md)- GitHub workflow YAML → [github-actions.md](references/github-actions.md)
Dockerfileor container image build/release concerns → [dockerfile.md](references/dockerfile.md)- AWS CLI, EC2, ECS, Lambda, S3, RDS, IAM, or CloudWatch → [aws.md](references/aws.md)
- GCP CLI, GCS, Compute Engine, IAM, quotas, or Cloud Logging → [gcp.md](references/gcp.md)
- Cloud Run services, revisions, traffic, or logs → [cloud-run.md](references/cloud-run.md)
- BigQuery queries, tables, datasets, or cost checks → [bigquery.md](references/bigquery.md)
- Linux services, hosts, processes, disks, or networks → [linux.md](references/linux.md)
Mixed stacks: load all matching references. Unknown stack: use the workflow below only.
Workflow
- Identify scope: files, resources, environment, account/project, region/zone, and owner.
- Verify cloud identity before cloud work; prefer explicit profile/project/region over defaults.
- Inspect current state with read-only evidence: files, plan/diff, list/describe/status, logs, metrics, and recent events.
- For authoring/design: choose the smallest pattern that preserves ownership, state boundaries, and least privilege.
- For troubleshooting: rank likely causes, gather one safe signal, then propose the next step.
- For validation: run relevant gates when tools exist; state skipped gates and why.
- For destructive, costly, or externally visible work: show exact resources and blast radius, then stop for confirmation or hand off to
deploying-infra.
Validation gates
- Terraform/OpenTofu: format, init without backend when possible, validate, plan,
tflint,checkovortrivy config; use plan JSON for policy checks when needed. - Kubernetes/Kustomize: render first, schema-check with
kubeconform, then policy/security-check withkube-linter,kubescape,conftest, orkyverno. - Helm: lint chart, render templates, use
helm diffbefore upgrade planning, validate rendered YAML. - Docker/images: lint Dockerfile with
hadolint; scan images/config withtrivy; usesyft,grype, andcosignwhere SBOM, vulnerability, or signature proof matters. - GitHub Actions: run
actionlintandzizmor; require SHA-pinned actions and least-permission jobs. - Cloud CLI: verify identity, inventory resources, estimate cost or dry-run when available, and check IAM/quota before mutation.
Output
INFRA RESULT
============
Scope:
Identity:
Status: DONE | NEEDS CONFIRMATION | BLOCKED
Evidence:
-
Changes or proposal:
-
Validation:
- — pass/fail/skipped
Next:
-
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: alexei-led
- Source: alexei-led/cc-thingz
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.