Search
DevOps & Cloud · Authorization and RBAC
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything. | kubesphere/ | 17k | 1 repo | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 2 | Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create. | huggingface/ | 11k | 1 repo | ~1.8k | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 3 | Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes. | Cybereason-Public/ | 280 | 12 repos | ~2k | Automated safety check: Pass | GPL-2.0 | yesterday |
| 4 | Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps. | Jeffallan/ | 12k | 1 repo | ~2.1k | Automated safety check: Pass | MIT | 4 days ago |
| 5 | A skill your agent uses when running a previously designed distributed-systems test plan against a real or simulated cluster — driving fault injection, workload, chaos scenarios, linearizability /… | shenli/ | 231 | — | ~5.1k | Automated safety check: Notes | MIT | 2 mo ago |
| 6 | Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants. | google/ | 21k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard. | fullstackhero/ | 6.8k | — | ~849 | Automated safety check: Pass | MIT | 8 days ago |
| 8 | Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work. | swimmwatch/ | 161 | — | ~1.9k | Automated safety check: Pass | MIT | 6 days ago |
| 9 | Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. | microsoft/ | 255 | 1 repo | ~6.7k | Automated safety check: Pass | MIT | today |
| 10 | How Kopiur writes and maintains user-facing docs — the MkDocs Material site under docs/ and the example manifests under deploy/examples/. | home-operations/ | 113 | — | ~2.5k | Automated safety check: Pass | AGPL-3.0 | today |
| 11 | Run Warden security scans in this repo using Sentry's warden-skills. | UsefulSoftwareCo/ | 4.1k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 12 | Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. | BlkLeg/ | 201 | — | ~2.1k | Automated safety check: Pass | MIT | 2 days ago |
| 13 | Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments. | timothywarner-org/ | 224 | — | ~4.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 14 | Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. | grafana/ | 279 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 15 | Implement a new or changed Supercheck feature end to end across schema, auth/RBAC, services, routes/actions, UI, queues/workers, CLI/recorder, tests, docs, and deployment contracts. | supercheck-io/ | 215 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | today |
| 16 | Reference guidance for Azure Advisor work: recommendations, alerts and digests, workbooks, RBAC access and sovereign-cloud limits, fetched from Microsoft Learn. | MicrosoftDocs/ | 777 | — | ~1.7k | Automated safety check: Pass | CC-BY-4.0 | 2 days ago |
| 17 | Azure Resource Manager SDK for Cosmos DB in .NET. An agent skill from microsoft/skills. | microsoft/ | 3.1k | 5 repos | ~2.1k | Automated safety check: Pass | MIT | yesterday |
| 18 | Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 19 | Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments. | affaan-m/ | 275k | 1 repo | ~5k | Automated safety check: Pass | MIT | 3 days ago |
| 20 | Review pull requests in the SAP Deployment Automation Framework. | Azure/ | 145 | — | ~7k | Automated safety check: Pass | MIT | yesterday |
| 21 | Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and… | hardw00t/ | 104 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 22 | Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection. | arpitg1304/ | 368 | — | ~7.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 23 | 23.Policy Opa Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA). | AgentSecOps/ | 220 | 1 repo | ~3.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 24 | Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Assesses the security posture of the etcd cluster backing Kubernetes: encryption at rest, TLS peer and client transport, access control, backup encryption, and network isolation. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules… | mukul975/ | 34k | — | ~654 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Hardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | 32.Ops Operate servers and services with read-only-first diagnosis, explicit authorization, auditable inventory, operation records, rollback, and verification. | holon-run/ | 153 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
| 33 | Provision, verify, and connect a self-hosted Temps platform instance on an explicitly authorized machine. | gotempsh/ | 826 | — | ~4.7k | Automated safety check: Notes | Apache-2.0 | today |
| 34 | Operating production Kubernetes clusters effectively with resource management, advanced scheduling, networking, storage, security hardening, and autoscaling. | ancoleman/ | 526 | — | ~3.6k | Automated safety check: Pass | MIT | 10 mo ago |
| 35 | Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure, covering vault architecture, session isolation… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network… | mukul975/ | 34k | — | ~732 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | Pre-deployment validation for Azure readiness. An agent skill from microsoft/GitHub-Copilot-for-Azure. | microsoft/ | 255 | 1 repo | ~880 | Automated safety check: Pass | MIT | today |
| 39 | Configures and diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or… | google/ | 21k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | today |
| 40 | Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2). | google/ | 21k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 41 | Generate/create/scaffold Kubernetes YAML — Deployment, Service, ConfigMap, Ingress, RBAC, StatefulSet, CRDs. | akin-ozer/ | 319 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 42 | 42.Kubernetes Kubernetes operations: debugging, security, RBAC, and infrastructure tooling. | notque/ | 438 | — | ~1.5k | Automated safety check: Pass | MIT | 5 days ago |
| 43 | Secures Helm chart deployments by verifying chart signatures and provenance, rendering and linting templates for misconfiguration, enforcing pod security contexts through values.yaml, moving secrets… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 44 | DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning… | modu-ai/ | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | today |
| 45 | ANALYSIS SKILL — Find the right Azure RBAC role for an identity with least-privilege access; generate CLI, Bicep, and Terraform code to assign it. | jonathan-vella/ | 217 | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 46 | 46.Azure Policy Guidance for Azure Policy — enforcing and auditing governance and security guardrails at scale across Azure with definitions, initiatives, assignments, and remediation tasks. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 47 | Provides Bicep coding standards for Azure infrastructure in this repository. | microsoft-foundry/ | 127 | — | ~1.2k | Automated safety check: Pass | MIT | 5 mo ago |
| 48 | WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. | jonathan-vella/ | 217 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |