Cloud Cost Optimization
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.
$ npx skills add anirudhbiyani/findmytakeover --skill dangling-dns-finder -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install anirudhbiyani/findmytakeover dangling-dns-finder --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/anirudhbiyani/findmytakeover.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dangling-dns-finder .claude/skills/dangling-dns-finder && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dangling-dns-finder" agent skill from https://github.com/anirudhbiyani/findmytakeover/tree/main/skills/dangling-dns-finder into .claude/skills/dangling-dns-finder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dangling-dns-finder", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/anirudhbiyani/findmytakeover/tree/main/skills/dangling-dns-finderType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add anirudhbiyani/findmytakeover --skill dangling-dns-finder -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install anirudhbiyani/findmytakeover dangling-dns-finder --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anirudhbiyani/findmytakeover.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dangling-dns-finder .agents/skills/dangling-dns-finder && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dangling-dns-finder" agent skill from https://github.com/anirudhbiyani/findmytakeover/tree/main/skills/dangling-dns-finder into .agents/skills/dangling-dns-finder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dangling-dns-finder", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anirudhbiyani/findmytakeover --skill dangling-dns-finder -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install anirudhbiyani/findmytakeover dangling-dns-finder --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anirudhbiyani/findmytakeover.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dangling-dns-finder .cursor/skills/dangling-dns-finder && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dangling-dns-finder" agent skill from https://github.com/anirudhbiyani/findmytakeover/tree/main/skills/dangling-dns-finder into .cursor/skills/dangling-dns-finder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dangling-dns-finder", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/anirudhbiyani/findmytakeover.git --path skills/dangling-dns-finder--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add anirudhbiyani/findmytakeover --skill dangling-dns-finder -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install anirudhbiyani/findmytakeover dangling-dns-finder --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anirudhbiyani/findmytakeover.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dangling-dns-finder .gemini/skills/dangling-dns-finder && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dangling-dns-finder" agent skill from https://github.com/anirudhbiyani/findmytakeover/tree/main/skills/dangling-dns-finder into .gemini/skills/dangling-dns-finder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dangling-dns-finder", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install anirudhbiyani/findmytakeover dangling-dns-finderInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add anirudhbiyani/findmytakeover --skill dangling-dns-finder -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/anirudhbiyani/findmytakeover.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dangling-dns-finder .github/skills/dangling-dns-finder && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dangling-dns-finder" agent skill from https://github.com/anirudhbiyani/findmytakeover/tree/main/skills/dangling-dns-finder into .github/skills/dangling-dns-finder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dangling-dns-finder", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anirudhbiyani/findmytakeover --skill dangling-dns-finder -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install anirudhbiyani/findmytakeover dangling-dns-finder --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anirudhbiyani/findmytakeover.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dangling-dns-finder .opencode/skills/dangling-dns-finder && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dangling-dns-finder" agent skill from https://github.com/anirudhbiyani/findmytakeover/tree/main/skills/dangling-dns-finder into .opencode/skills/dangling-dns-finder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dangling-dns-finder", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dangling-dns-finderDetect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.
Dangling DNS Finder is an agent skill from anirudhbiyani/findmytakeover. Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool. Use whenever the user wants to find dangling domains/records, stale CNAMEs, subdomain takeover exposure, orphaned DNS entries, or audit their DNS zones for records pointing at deleted cloud resources — dead load balancers (ELBs), released EC2/GCP/Azure IPs, or expired SaaS targets. Triggers on "dangling domains", "dangling DNS", "subdomain takeover", "audit my DNS", "find…
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Cloud networking and Cloud architecture. It works with Microsoft Azure, Google Cloud and Amazon Web Services. The repository describes itself as: find dangling domains in a multi cloud environment. The licence is GPL-3.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit bf3ff92. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3pip3awsFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip3 and aws, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CLOUDFLARE_API_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dangling DNS Finder loads about 1.8k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 918 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from anirudhbiyani/findmytakeover at commit bf3ff92, republished under its GPL-3.0 licence (© anirudhbiyani). 918 words, ~1,828 tokens.
.claude/skills/dangling-dns-finder/SKILL.md (or your agent's skills folder).Find DNS records that point at infrastructure that no longer exists — the
classic subdomain-takeover setup. A CNAME to a deleted ELB, or an A record
to a released cloud IP, can be silently reclaimed by someone else and used to
serve content under your domain.
This skill drives the repo's own tool, findmytakeover.py.
It enumerates every DNS record and every live infrastructure endpoint
(IPs, ELB/LB hostnames, etc.) across the configured AWS/GCP/Azure accounts,
then reports any DNS record whose value has no matching live resource. No
wordlists, no guessing — a record is dangling because the thing it points at is
not in your inventory.
Do not write new scripts to resolve DNS or probe endpoints — the tool already collects both sides and diffs them. Your job is to configure it, run it, and interpret the output.
ViewOnlyAccess + SecurityAudit (or an assumable IAM role)Viewer (Application Default Credentials, or a service-account key)Reader (Azure CLI login, or tenant/client/secret)CLOUDFLARE_API_TOKEN env, or a token string)read/inspect group (~/.oci/config DEFAULT profile, or a config path)pip3 install . from the repo root (installs from pyproject.toml).The tool reads findmytakeover.config (YAML) —
default path is the repo root, override with -c. Enable only the providers the
user actually has. For each, set enabled: true and pick credentials:
credentials: default — use the local CLI's logged-in creds and auto-discover
accounts/projects/subscriptions. Simplest; prefer this.accounts: explicitly.A provider appears under both dns: and infra: — both must be enabled for the
dangling check to run (it needs both sides to diff). Use exclude: for IP
ranges/domains that are known-safe and should never be flagged (e.g. SaaS email
domains, reserved ranges).
Confirm the config with the user before running — wrong account scope is the main way this wastes time.
python3 findmytakeover.py -c findmytakeover.config
# add -d dump.csv to also save the raw DNS + infrastructure inventoryIt prints how many DNS records and infra resources it collected per provider, then one line per dangling record:
Found dangling DNS record - <name> with value <value> in <cloud> cloud (account/...: <id>)Use -d <file> whenever the user wants to inspect the raw data or when a result
looks surprising — the dump shows exactly what DNS and infra were compared.
Present the dangling records as a table: Subdomain · Value (target) · Cloud ·
Account. Group by cloud. Call out anything sensitive (customer-named
subdomains, *-prod hosts) for manual confirmation before any deletion.
Frame confidence honestly (see Interpreting results) — a value missing from the inventory is a strong signal, not proof, and some classes of record are expected to have no backing infra.
The tool only reports; it does not delete. For each confirmed dangling record,
show the user the deletion command for their DNS provider (e.g.
aws route53 change-resource-record-sets with a change batch, gcloud dns record-sets delete, az network dns record-set ... delete).
DNS deletion is hard to reverse and outward-facing — default to showing the
command and letting the user run it. Only run it yourself if they explicitly say
so, and never batch-delete customer-named or *-prod records without a
record-by-record confirmation.
A record can have no matching infra yet be perfectly fine. Bucket these separately as "stale / out of scope," not as takeover risks:
*.acm-validations.aws, *.authorize.certificatemanager.goog,
_acme-challenge.*. These point at validation zones / single-use tokens, not
service endpoints. Not a takeover vector.*.dkim.*, *.domainkey.*, *.hubspotemail.net, salesforce/highspot/etc.).
Expected to have no infra in your accounts.exclude: once confirmed.A genuine takeover risk is a record pointing at a real endpoint (ELB, cloud host, app) that exists in none of the accounts you scanned.
dns and infra must be enabled (and for the same providers you care
about) or there's nothing to diff — the tool will say so and exit.infra enabled and scanned —
otherwise a live delegation looks dangling.-d if a known-good record
shows up as dangling.© anirudhbiyani, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/dangling-dns-finder of anirudhbiyani/findmytakeover.
Open the folder on GitHubat commit bf3ff92
Dangling DNS Finder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dangling DNS Finder this skillanirudhbiyani/findmytakeover | 180 | — | ~1.8k | Automated safety check: Pass | GPL-3.0 | |
| Cloud Cost Optimizationwshobson/agents | 40k | 14 repos | ~1.7k | Automated safety check: Pass | MIT | |
| Thesvgglincker/thesvg | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Hybrid Cloud Networkingwshobson/agents | 40k | 11 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Terraform Module Librarywshobson/agents | 40k | 11 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Multi Cloud ArchitectureHermeticOrmus/LibreUIUX-Claude-Code | 112 | 11 repos | ~1.2k | Automated safety check: Pass | MIT |
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
glincker/thesvg
Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.
wshobson/agents
Configure secure, high-performance connectivity between on-premises infrastructure and cloud platforms using VPN and dedicated connections.
wshobson/agents
Build reusable, tested Terraform modules for AWS, Azure, GCP and OCI, with a standard file layout, an AWS VPC example, versioning rules and Terratest checks.
HermeticOrmus/LibreUIUX-Claude-Code
Design multi-cloud architectures using a decision framework to select and integrate services across AWS, Azure, and GCP.
Jeffallan/claude-skills
Designs cloud architectures, migration plans, cost optimization recommendations and disaster recovery strategies across AWS, Azure and GCP.
Categories
Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool. Dangling DNS Finder is an agent skill from anirudhbiyani/findmytakeover. Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.
Dangling DNS Finder fits situations like: the user wants to find dangling domains/records; subdomain takeover exposure; orphaned DNS entries; audit their DNS zones for records pointing at deleted cloud resources — dead load balancers (ELBs).
Run `npx skills add anirudhbiyani/findmytakeover --skill dangling-dns-finder -a claude-code`. Or copy the skill folder (skills/dangling-dns-finder in anirudhbiyani/findmytakeover) into .claude/skills/dangling-dns-finder in your project. Claude Code loads it when a task matches its description.
Run `npx skills add anirudhbiyani/findmytakeover --skill dangling-dns-finder -a codex`. Or copy the skill folder (skills/dangling-dns-finder in anirudhbiyani/findmytakeover) into .agents/skills/dangling-dns-finder in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anirudhbiyani/findmytakeover --skill dangling-dns-finder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dangling-dns-finder, .gemini/skills/dangling-dns-finder, .github/skills/dangling-dns-finder and .opencode/skills/dangling-dns-finder in your project.
Going by SKILL.md and its folder, Dangling DNS Finder needs the command-line tools its instructions call (python3, pip3 and aws) and credentials named CLOUDFLARE_API_TOKEN. Our summary lists: Python 3; A credential in CLOUDFLARE_API_TOKEN.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dangling DNS Finder is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dangling DNS Finder: Cloud Cost Optimization (wshobson/agents, 40k stars), Thesvg (glincker/thesvg, 2.8k stars), Hybrid Cloud Networking (wshobson/agents, 40k stars) and Terraform Module Library (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
anirudhbiyani (a GitHub user) maintains it in anirudhbiyani/findmytakeover, which has 180 GitHub stars. The repository was last updated on September 7, 2026.
Source: anirudhbiyani/findmytakeover on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.