Agent skill

Drift Detection

by bolivian-peru in bolivian-peru/os-moda

Detect configuration drift — manual changes that exist outside NixOS management.

Apache-2.0Auto-check passedDevOps & Cloud

Install Drift Detection

skills CLI
$ npx skills add bolivian-peru/os-moda --skill drift-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bolivian-peru/os-moda drift-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bolivian-peru/os-moda.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/drift-detection .claude/skills/drift-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
drift-detection
GitHub stars
119
Token cost
~584 tokens
SKILL.md length
169 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detect configuration drift — manual changes that exist outside NixOS management.

  • Works in 5 steps: Imperatively installed packages → Manual files outside NixOS → Manual cron jobs → …
  • Tasks that involve GitOps
  • SKILL.md covers Checks, Remediation and Why This Matters
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Drift Detection is an agent skill from bolivian-peru/os-moda. Detect configuration drift — manual changes that exist outside NixOS management. Offer to bring imperative changes into declarative config.

Its SKILL.md is about 580 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering GitOps. The repository describes itself as: An operating system built for AI agents — talk to your NixOS server instead of SSH-ing in. Typed, audited tool access with atomic rollback on every change. Research-grade; run it… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve GitOps

Example prompts

  • “/drift-detection”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Imperatively installed packages
  2. Manual files outside NixOS
  3. Manual cron jobs
  4. Stale NixOS generations
  5. Orphaned systemd units

What it can do on your machine

Read from SKILL.md and the folder at commit b8e418f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Drift Detection loads about 584 tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 169 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~584

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bolivian-peru/os-moda at commit b8e418f, republished under its Apache-2.0 licence (© bolivian-peru). 169 words, ~584 tokens.

Download SKILL.mdSave it as .claude/skills/drift-detection/SKILL.md (or your agent's skills folder).
name
drift-detection
description
Detect configuration drift — manual changes that exist outside NixOS management. Offer to bring imperative changes into declarative config.
tools
shell_exec, file_read, file_write, memory_store, memory_recall
activation
auto

Configuration Drift Detection

NixOS is declarative — the config should be the single source of truth. But reality drifts: manual edits, imperative installs, ad-hoc cron jobs. Detect and reconcile.

Checks

1. Imperatively installed packages
shell_exec({ command: "nix-env -q 2>/dev/null || echo 'none'" })

If packages found: offer to add them to environment.systemPackages in NixOS config.

2. Manual files outside NixOS
shell_exec({ command: "find /etc -newer /etc/NIXOS -not -path '/etc/nixos/*' -not -path '/etc/resolv.conf' -type f 2>/dev/null | head -20" })

Files modified after last NixOS rebuild may be manual edits.

3. Manual cron jobs
shell_exec({ command: "ls /etc/cron.d/ /var/spool/cron/crontabs/ 2>/dev/null" })

Offer to convert to systemd timers in NixOS config.

4. Stale NixOS generations
shell_exec({ command: "nixos-rebuild list-generations 2>/dev/null | wc -l" })

More than 20 generations → suggest cleanup.

5. Orphaned systemd units
shell_exec({ command: "systemctl list-units --state=failed --no-pager" })

Remediation

For each drift finding, offer to bring it into NixOS:

Drift Report:

⚠️ 3 packages installed via nix-env: htop, ncdu, tree
   → Add to environment.systemPackages? [Y/n]

⚠️ /etc/cron.d/backup exists outside NixOS
   → Convert to systemd timer in NixOS config? [Y/n]

⚠️ 47 old NixOS generations (using 18GB)
   → Keep current + last 5, remove rest? [Y/n]

✅ No unauthorized file changes in /etc/nixos/
✅ All systemd services match NixOS config

Why This Matters

On Ubuntu, configuration drift is invisible and irreversible. On NixOS with osModa, you can:

  1. Detect that something was changed manually
  2. Reconcile by adding it to the declarative config
  3. Prove with the audit ledger that nothing unauthorized happened
  4. Reproduce the exact system state on new hardware

This is useful supporting evidence for compliance programs (SOC 2, etc.) — though not by itself proof of regulatory readiness.

© bolivian-peru, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/drift-detection of bolivian-peru/os-moda.

Open the folder on GitHubat commit b8e418f

Compare with similar skills

Drift Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Drift Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Drift Detection this skillbolivian-peru/os-moda119—~584Automated safety check: PassApache-2.0
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Kubernetes ArchitectCybereason-Public/owLSM2809 repos~2.6kAutomated safety check: PassGPL-2.0
Docs Corpus Auditmicrosoft/apm4k—~2.6kAutomated safety check: PassMIT
Devopsnicepkg/auto-company1952 repos~814Automated safety check: PassMIT
Gitops Repo Auditfluxcd/agent-skills231—~3.8kAutomated safety check: PassApache-2.0

Similar skills

  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • Kubernetes Architect

    Cybereason-Public/owLSM

    Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.

    280 GitHub starsUsed in 9 repos~2.6k tokens
    DevOps & CloudAuto-check passed
  • Docs Corpus Audit

    microsoft/apm

    Official

    A skill your agent uses to run a holistic regrounding pass on the entire microsoft/apm documentation corpus against current source code, page-by-page, and emit surgical fixes for stale claims.

    4k GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    195 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • Gitops Repo Audit

    fluxcd/agent-skills

    Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets…

    231 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.

    40k GitHub starsUsed in 12 repos~1.5k tokens
    DevOps & CloudAuto-check passed

More from bolivian-peru/os-moda

All 17 skills in this repo
  • App Deployer

    bolivian-peru/os-moda

    Deploy and manage user applications as managed systemd services

    119 GitHub stars~774 tokensUpdated 3 mo ago
    Auto-check passed
  • Deploy AI Agent

    bolivian-peru/os-moda

    Deploy and manage AI agent workloads with GPU checks, API key management, and health monitoring

    119 GitHub stars~1.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Flight Recorder

    bolivian-peru/os-moda

    Black box flight recorder for the server. An agent skill from bolivian-peru/os-moda.

    119 GitHub stars~624 tokensUpdated 3 mo ago
    Auto-check passed
  • Generation Timeline

    bolivian-peru/os-moda

    NixOS generation-aware debugging and time-travel. An agent skill from bolivian-peru/os-moda.

    119 GitHub stars~777 tokensUpdated 3 mo ago
    Auto-check passed
  • Morning Briefing

    bolivian-peru/os-moda

    Generate a concise daily infrastructure briefing. An agent skill from bolivian-peru/os-moda.

    119 GitHub stars~897 tokensUpdated 3 mo ago
    Auto-check passed
  • Natural Language Config

    bolivian-peru/os-moda

    Translate natural language requests into NixOS configuration changes.

    119 GitHub stars~761 tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Drift Detection

What does Drift Detection do?

Detect configuration drift — manual changes that exist outside NixOS management. Drift Detection is an agent skill from bolivian-peru/os-moda. Detect configuration drift — manual changes that exist outside NixOS management.

When should I use Drift Detection?

Drift Detection fits situations like: tasks that involve GitOps.

How do I install Drift Detection in Claude Code?

Run `npx skills add bolivian-peru/os-moda --skill drift-detection -a claude-code`. Or copy the skill folder (skills/drift-detection in bolivian-peru/os-moda) into .claude/skills/drift-detection in your project. Claude Code loads it when a task matches its description.

How do I install Drift Detection in Codex?

Run `npx skills add bolivian-peru/os-moda --skill drift-detection -a codex`. Or copy the skill folder (skills/drift-detection in bolivian-peru/os-moda) into .agents/skills/drift-detection in your project. Codex loads it when a task matches its description.

Can I use Drift Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bolivian-peru/os-moda --skill drift-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/drift-detection, .gemini/skills/drift-detection, .github/skills/drift-detection and .opencode/skills/drift-detection in your project.

What does Drift Detection need to run?

SKILL.md names no scripts, command-line tools or credentials: Drift Detection is instructions for the agent only.

Does Drift Detection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Drift Detection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Drift Detection use?

Drift Detection is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Drift Detection use?

About 584 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Drift Detection?

Skills that share tags, products or a category with Drift Detection: Kubernetes Specialist (Jeffallan/claude-skills, 12k stars), Kubernetes Architect (Cybereason-Public/owLSM, 280 stars), Docs Corpus Audit (microsoft/apm, 4k stars) and Devops (nicepkg/auto-company, 195 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Drift Detection?

bolivian-peru (a GitHub user) maintains it in bolivian-peru/os-moda, which has 119 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on June 24, 2026.

Source: bolivian-peru/os-moda on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.