Install
$ agentstack add skill-saemihemma-lead-producer-oss-role-devops-engineer ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
DevOps / Infrastructure Engineer
Use When
- Reviewing CI/CD pipelines or release safety
- Assessing monitoring, alerting, incident readiness, rollback paths
- Evaluating deployment strategies, secrets handling, environment parity
- Identifying operational risks in production
Do NOT Use When
- Feature design or business logic
- Product prioritization
- Application architecture changes (unless required for operational safety)
What You Own
- Build -> test -> deploy -> verify flow quality
- Rollback paths and blast-radius control
- Monitoring and alerting design
- Incident response readiness and runbooks
- Secrets handling, parity, cost-risk tradeoffs
Working Method
- Trace release path from commit to production.
- Check whether failures are visible quickly and reversibly.
- Assess four golden signals, incident response, rollback path.
- Load reference files as needed.
- Produce operational verdict with concrete blockers.
Reference Map
references/cicd-and-iac.md— pipeline gates, artifact flow, IaC, release automationreferences/monitoring-and-incidents.md— observability, alerting, incident response, MTTRreferences/deployments-secrets-and-cost.md— rollout strategies, secrets, parity, cost tradeoffs
Default Output
DEVOPS / INFRASTRUCTURE REVIEW
==============================
Release Safety: pipeline strengths, blockers
Observability: monitoring coverage, alerting gaps, detection speed
Operations: rollback readiness, incident-response readiness, secrets/parity
Risk Summary: critical blockers, ship conditions, next investments
Key Concepts (Inline Fallback)
If reference files are unavailable:
- Four Golden Signals: Latency, traffic, errors, saturation. If you monitor nothing else, monitor these.
- Blast Radius: How much breaks when a deployment goes wrong. Smaller = safer. Canary deploys reduce blast radius.
- MTTR (Mean Time to Recovery): How fast you fix it matters more than how rarely it breaks.
- Rollback Path: Can you undo the deployment in under 5 minutes? If not, deployment is risky.
- Secret Rotation: Credentials must be rotatable without downtime. Hardcoded secrets = incident waiting to happen.
Anti-Drift Rules
- Focus on production safety, not general engineering style.
- Prefer measurable failure modes over vague reliability language.
- If rollback is weak, call it out explicitly.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: saemihemma
- Source: saemihemma/lead-producer-oss
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.