Terraform and OpenTofu Guide
agentscope-ai/QwenPaw
Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.
Generate a BYOD ownership preferences reference table for a customer.
$ npx skills add datadog-labs/agent-skills --skill k9-ownership-byod-setup -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install datadog-labs/agent-skills k9-ownership-byod-setup --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/datadog-labs/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/dd-security/csm/ownership-agent .claude/skills/k9-ownership-byod-setup && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "k9-ownership-byod-setup" agent skill from https://github.com/datadog-labs/agent-skills/tree/main/dd-security/csm/ownership-agent into .claude/skills/k9-ownership-byod-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k9-ownership-byod-setup", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/datadog-labs/agent-skills/tree/main/dd-security/csm/ownership-agentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add datadog-labs/agent-skills --skill k9-ownership-byod-setup -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install datadog-labs/agent-skills k9-ownership-byod-setup --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/datadog-labs/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/dd-security/csm/ownership-agent .agents/skills/k9-ownership-byod-setup && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "k9-ownership-byod-setup" agent skill from https://github.com/datadog-labs/agent-skills/tree/main/dd-security/csm/ownership-agent into .agents/skills/k9-ownership-byod-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k9-ownership-byod-setup", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add datadog-labs/agent-skills --skill k9-ownership-byod-setup -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install datadog-labs/agent-skills k9-ownership-byod-setup --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/datadog-labs/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/dd-security/csm/ownership-agent .cursor/skills/k9-ownership-byod-setup && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "k9-ownership-byod-setup" agent skill from https://github.com/datadog-labs/agent-skills/tree/main/dd-security/csm/ownership-agent into .cursor/skills/k9-ownership-byod-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k9-ownership-byod-setup", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/datadog-labs/agent-skills.git --path dd-security/csm/ownership-agent--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add datadog-labs/agent-skills --skill k9-ownership-byod-setup -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install datadog-labs/agent-skills k9-ownership-byod-setup --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/datadog-labs/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/dd-security/csm/ownership-agent .gemini/skills/k9-ownership-byod-setup && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "k9-ownership-byod-setup" agent skill from https://github.com/datadog-labs/agent-skills/tree/main/dd-security/csm/ownership-agent into .gemini/skills/k9-ownership-byod-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k9-ownership-byod-setup", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install datadog-labs/agent-skills k9-ownership-byod-setupInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add datadog-labs/agent-skills --skill k9-ownership-byod-setup -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/datadog-labs/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/dd-security/csm/ownership-agent .github/skills/k9-ownership-byod-setup && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "k9-ownership-byod-setup" agent skill from https://github.com/datadog-labs/agent-skills/tree/main/dd-security/csm/ownership-agent into .github/skills/k9-ownership-byod-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k9-ownership-byod-setup", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add datadog-labs/agent-skills --skill k9-ownership-byod-setup -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install datadog-labs/agent-skills k9-ownership-byod-setup --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/datadog-labs/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/dd-security/csm/ownership-agent .opencode/skills/k9-ownership-byod-setup && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "k9-ownership-byod-setup" agent skill from https://github.com/datadog-labs/agent-skills/tree/main/dd-security/csm/ownership-agent into .opencode/skills/k9-ownership-byod-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k9-ownership-byod-setup", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
k9-ownership-byod-setupGenerate a BYOD ownership preferences reference table for a customer.
K9 Ownership Byod Setup is an agent skill from datadog-labs/agent-skills. Generate a BYOD ownership preferences reference table for a customer. Walks through preference types, generates CSV, and provides upload instructions (UI, API, cloud storage, or Terraform). Use when asked about BYOD setup, preferences reference table, k9ownershippreferences, or ownership customization.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files and assets (for example `references/schema.md`).
It sits in DevOps & Cloud, covering CSV and tabular files and Infrastructure as code. It works with Terraform. The repository describes itself as: Public repository for Datadog Agent Skills. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d2411cc. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBashFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.datadoghq.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
K9 Ownership Byod Setup loads about 1.5k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 736 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from datadog-labs/agent-skills at commit d2411cc, republished under its MIT licence (© datadog-labs). 736 words, ~1,495 tokens.
.claude/skills/k9-ownership-byod-setup/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Help customers create and upload a k9_ownership_preferences reference table to customize how the Ownership Agent determines resource owners.
references/schema.md — full schema, column details, validation rules, and per-type examplesassets/example.csv — complete working CSV with all three preference typesThe Ownership Agent infers owners for cloud resources with security findings. Ownership preferences let customers customize this by providing rules in a Datadog reference table. The agent reads them automatically.
With preferences you can:
k9_ownership_preferences (exact name, must match)references/schema.md for detailsAsk the customer:
cost-center, team, project)"Read references/schema.md for the full column spec and assets/example.csv for a working template. Build a CSV with all 12 column headers. Each row gets a unique sequential id and fills columns relevant to its preference_type, leaving the rest empty.
Option A — CSV Upload (UI):
k9_ownership_preferencespreference_type, tag_key, tag_value, handleManual uploads support files up to 4 MB.
Option B — Cloud Storage Sync (S3, Azure Blob, GCS): Best for automated, recurring updates. Store your CSV in a cloud storage bucket and Datadog periodically imports it.
k9_ownership_preferencesCloud storage uploads support files up to 200 MB.
Option C — Terraform:
Use the datadog_reference_table resource in the Datadog Terraform provider to manage the table as infrastructure-as-code.
Option D — API: You can manage reference tables programmatically through the Reference Tables API. See the API documentation for available endpoints. Replace the API domain with your Datadog site URL if applicable.
Changes take effect within 24 hours. To verify:
team: or service: tags) take precedence. Tag mappings augment, not replace| Problem | Likely cause | Fix |
|---|---|---|
| Preferences not taking effect after 24h | Table name is wrong | Must be exactly k9_ownership_preferences |
| Preferences not taking effect after 24h | Missing column headers | All 12 columns must exist as CSV headers |
| Preferences not taking effect after 24h | Feature not enabled for org | Contact support to enable ownership preferences |
| All preferences rejected | Invalid characters | See references/schema.md Allowed Characters. No angle brackets, curly braces, or pipes |
| All preferences rejected | Missing required field | Check required fields for each preference type in references/schema.md |
| All preferences rejected | Duplicate or conflicting rows | See Duplicate Detection in references/schema.md |
| All preferences rejected | Size limit exceeded | 50 tag mappings, 20 exclusions, 3 prompt texts. 1024 bytes/field, 4096/prompt |
| Tag mapping not matching | Spelling mismatch | Matching is case-insensitive but verify exact tag key/value on resource |
| Exclusion not applying | Scoping too narrow | All non-empty fields must match (AND). Leave filters empty for broad exclusions |
| Preferences cleared unexpectedly | Table emptied or deleted | Both cause cached preferences to expire. Upload a valid CSV to restore |
© datadog-labs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references, assets) in dd-security/csm/ownership-agent of datadog-labs/agent-skills.
Open the folder on GitHubat commit d2411cc
K9 Ownership Byod Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| K9 Ownership Byod Setup this skilldatadog-labs/agent-skills | 177 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Terraform and OpenTofu Guideagentscope-ai/QwenPaw | 36k | 6 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Terraform Skillantonbabenko/terraform-skill | 2.4k | 1 repos | ~5.1k | Automated safety check: Pass | Apache-2.0 | |
| Review Docshashicorp/terraform-provider-aws | 11k | — | ~1.3k | Automated safety check: Pass | MPL-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| Cloudflarehodgef/apiker | 127 | 7 repos | ~2.2k | Automated safety check: Pass | MIT |
agentscope-ai/QwenPaw
Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.
antonbabenko/terraform-skill
A skill your agent uses when writing, reviewing, or debugging Terraform/OpenTofu modules, tests, CI, scans, or state ops - diagnoses failure mode (identity churn, secrets, blast radius, CI drift…
hashicorp/terraform-provider-aws
Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
hodgef/apiker
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
datadog-labs/agent-skills
Bootstrap a reproducible LLM Observability experiment through the Python ddtrace SDK or the Node dd-trace SDK.
datadog-labs/agent-skills
Ensure the user has an authenticated Datadog account with a valid DDAPIKEY on the right region before any Datadog setup or instrumentation.
datadog-labs/agent-skills
Entry point for Datadog onboarding. An agent skill from datadog-labs/agent-skills.
datadog-labs/agent-skills
APM - install, onboard, instrument, enable, set up, configure, traces, services, dependencies, performance analysis, Data Streams Monitoring (DSM), queue lag, pipeline latency.
datadog-labs/agent-skills
Install the Datadog Agent on Kubernetes using the Datadog Operator — required before enabling Single Step Instrumentation (SSI), which automatically instruments applications for APM without code…
datadog-labs/agent-skills
Set up the Datadog AWS integration with Terraform - creates the cross-account IAM role Datadog assumes (external ID, no stored credentials), attaches the permission policies Datadog publishes, and…
Works with
Categories
Generate a BYOD ownership preferences reference table for a customer. K9 Ownership Byod Setup is an agent skill from datadog-labs/agent-skills. Generate a BYOD ownership preferences reference table for a customer.
K9 Ownership Byod Setup fits situations like: asked about BYOD setup; preferences reference table; K9ownershippreferences; ownership customization.
Run `npx skills add datadog-labs/agent-skills --skill k9-ownership-byod-setup -a claude-code`. Or copy the skill folder (dd-security/csm/ownership-agent in datadog-labs/agent-skills) into .claude/skills/k9-ownership-byod-setup in your project. Claude Code loads it when a task matches its description.
Run `npx skills add datadog-labs/agent-skills --skill k9-ownership-byod-setup -a codex`. Or copy the skill folder (dd-security/csm/ownership-agent in datadog-labs/agent-skills) into .agents/skills/k9-ownership-byod-setup in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add datadog-labs/agent-skills --skill k9-ownership-byod-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k9-ownership-byod-setup, .gemini/skills/k9-ownership-byod-setup, .github/skills/k9-ownership-byod-setup and .opencode/skills/k9-ownership-byod-setup in your project.
SKILL.md names no scripts, command-line tools or credentials: K9 Ownership Byod Setup is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Bash.
SKILL.md names 1 domain. As links in the text: docs.datadoghq.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
K9 Ownership Byod Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with K9 Ownership Byod Setup: Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Terraform Skill (antonbabenko/terraform-skill, 2.4k stars), Review Docs (hashicorp/terraform-provider-aws, 11k stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
datadog-labs (a GitHub organization) maintains it in datadog-labs/agent-skills, which has 177 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on October 8, 2026.
Source: datadog-labs/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.