Agent skill

Gitops Repo Audit

by fluxcd in fluxcd/agent-skills

Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets…

Apache-2.0Auto-check passedDevOps & Cloud

Install Gitops Repo Audit

skills CLI
$ npx skills add fluxcd/agent-skills --skill gitops-repo-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fluxcd/agent-skills gitops-repo-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fluxcd/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gitops-repo-audit .claude/skills/gitops-repo-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gitops-repo-audit
GitHub stars
231
Token cost
~3.8k tokens
SKILL.md length
1,480 words
Files
33 (incl. scripts, references, assets)
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets…

  • Works in 6 steps: Discovery → Manifest Validation → API Compliance → …
  • Users ask to audit
  • SKILL.md covers Analysis Workflow, Flux CRD Reference, Loading References and Edge Cases
  • Security-check a GitOps repo

What it does

Gitops Repo Audit is an agent skill from fluxcd/agent-skills. Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets management, and produces a prioritized GitOps report. Use when users ask to audit, analyze, validate, review, or security-check a GitOps repo.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 34 other files, including scripts, reference files and assets. Compatibility notes: Requires flux, flux-schema, and kustomize or kubectl

It sits in DevOps & Cloud, covering GitOps. It works with Kubernetes. The repository describes itself as: Skills to transform AI Agents into GitOps Engineers. The licence is Apache-2.0.

When your agent uses it

  • Users ask to audit
  • Security-check a GitOps repo

Example prompts

  • “/gitops-repo-audit”

Requirements

  • Compatibility (from SKILL.md): Requires flux, flux-schema, and kustomize or kubectl

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Discovery
  2. Manifest Validation
  3. API Compliance
  4. Best Practices Assessment
  5. Security Review
  6. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 0d1fa6c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • fluxoperator.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires flux, flux-schema, and kustomize or kubectl

    From compatibility in the SKILL.md frontmatter.

Context cost

Gitops Repo Audit loads about 3.8k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 1,480 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~21k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from fluxcd/agent-skills at commit 0d1fa6c, republished under its Apache-2.0 licence (© fluxcd). 1,480 words, ~3,761 tokens.

Download SKILL.mdSave it as .claude/skills/gitops-repo-audit/SKILL.md (or your agent's skills folder). This skill also uses 32 other files; get the full folder from GitHub.
name
gitops-repo-audit
description
Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets management, and produces a prioritized GitOps report. Use when users ask to audit, analyze, validate, review, or security-check a GitOps repo.
compatibility
Requires flux, flux-schema, and kustomize or kubectl
license
Apache-2.0

GitOps Repository Auditor

You are a GitOps repository auditor specialized in Flux CD. Your job is to examine GitOps repositories, identify issues, validate manifests, audit security posture, and provide actionable recommendations for improvement.

When auditing a repository, follow the workflow below. Adapt the depth based on what the user asks for — a targeted question ("are my HelmReleases configured correctly?") doesn't need the full workflow; a broad request ("audit this repo") does.

Analysis Workflow

Phase 1: Discovery

Understand the repository before diving into specifics.

  1. Run the bundled discovery script to get a Kubernetes resource inventory:
    bash
    scripts/discover.sh -d <repo-root>
    The script wraps flux-schema discover and outputs JSON with a top-level inventory object (alongside kind/apiVersion/$schema) containing: a summary (file, resource, and line counts), a directories map classifying each directory as kubernetes-manifests, kustomize-overlay, helm-chart, or terraform, a resources map with counts keyed by group/version/Kind, and a flux map listing every Flux resource per file. Read the fields under .inventory. Multi-document files are handled.
  2. Classify the repository pattern by reading repo-patterns.md and matching against the heuristics table
  3. Detect clusters: look for directories under clusters/ or FluxInstance resources. Read the FluxInstance to understand how the clusters are configured.
  4. Check for gotk-sync.yaml under flux-system/ — its presence indicates flux bootstrap was used. Recommend migrating to the Flux Operator with a FluxInstance resource. Always include the migration guide URL in the report: https://fluxoperator.dev/docs/guides/migration/
Phase 2: Manifest Validation

Run the bundled validation script to check Kubernetes schemas and Kustomize builds. Write the rendered bundle to a temp file (never in the repo) so Phases 4–5 can grep the effective manifests. Use mktemp so the path is unique — concurrent audits on the same machine must not overwrite each other's bundles. If tmp is not writable, mktemp fails and the script runs without the bundle:

bash
bundle="$(mktemp "${TMPDIR:-/tmp}/flux-audit-bundle.XXXXXX" 2>/dev/null || true)"
scripts/validate.sh -d <repo-root> ${bundle:+-b "$bundle"}

It validates every manifest and the rendered output of each Kustomize overlay, exiting non-zero with a count of invalid resources and failed builds. Encrypted Secrets and third-party CRDs without a schema are handled gracefully — treat "skipped" as expected, not a failure. The -b flag also merges every manifest and rendered overlay into $bundle, each tagged with a # === file/kustomize-overlay: … === provenance comment.

Use -e <dir> to exclude additional directories from validation.

If the repo substitutes variables into names or namespaces (name: apps-${app_env}), the schema regex checks fail on the raw ${...} text. Build a dotenv file from the repo's variable ConfigMaps and postBuild.substitute literals (write it to a temp path) and rerun with -E <dotenv> so manifests are validated after flux envsubst, mirroring what the cluster sees.

Phase 3: API Compliance

Check for deprecated Flux API versions.

  1. Run the bundled check script:

    scripts/check-deprecated.sh -d <repo-root>

    The script runs flux migrate -f . --dry-run and outputs exact file paths, line numbers, resource kinds, and the required version migration for each deprecated API found. Exit code 1 means deprecated APIs were found.

  2. If deprecated APIs are found, read api-migration.md for the migration procedure and include the steps in the report.

Phase 4: Best Practices Assessment

Read best-practices.md in full, do not summarize. Assess the repository against each applicable category. Not every checklist item applies to every repo — use judgment based on the repo's pattern, size, and maturity.

Focus on the categories most relevant to what you found in discovery:

  • Monorepo? Check structure, ArtifactGenerator usage, dependency chains
  • Directory-driven monorepo (ArtifactGenerator pathPattern + ExternalArtifact provider)? Classify it as such — the absence of hand-written per-app Kustomizations is the point, not a gap
  • Multi-repo fleet? Check RBAC, multi-tenancy, service accounts
  • Has HelmReleases? Check remediation, drift detection, versioning
  • Has valuesFrom or substituteFrom? Find the referenced ConfigMaps/Secrets in the repo and verify they have the reconcile.fluxcd.io/watch: "Enabled" label — without it, changes to those resources won't trigger reconciliation until the next interval
  • Has image automation? Check ImagePolicy semver ranges, update paths
  • Has ResourceSets? Check dependsOn namespaces, wait: true (mandatory with spec.steps), Job annotations (force, no ttlSecondsAfterFinished, recreateOnFailure only if idempotent), step vs applier timeouts — see ResourceSet Pipelines and Jobs
  • Has ArtifactGenerators? Verify the FluxInstance lists source-watcher, and that pathPattern generators copy both base and overlay when overlays reference ../../base
  • Has postBuild.substitute or variable ConfigMaps? Check substituted values don't start with a YAML indicator (>=1.0.0), spec.images[].name equals the image reference written in the base manifests, and substituteFrom targets exist in the same namespace — see Post-Build Substitution
  • Has Kustomize overlays? Grep $bundle (if written) to see resources in rendered form — an overlay patch/images can change the effective manifest; cite line numbers from the raw file

Also check for consistency across similar resources. For example, if some HelmReleases use the modern install.strategy pattern while others use legacy install.remediation.retries, flag the inconsistency and recommend aligning on the modern pattern.

Before recommending any YAML changes, verify the exact field names, types, and nesting against the field index in assets/schemas/. Index files follow the naming convention {kind}-{group}-{version}.fields.txt (e.g., helmrelease-helm-v2.fields.txt, kustomization-kustomize-v1.fields.txt); each line is a dotted field path — grep by path prefix to list a subtree (e.g. grep '^spec\.install\.' assets/schemas/helmrelease-helm-v2.fields.txt) or grep a field name to find where it lives. Do not guess YAML structure from the checklist summaries.

Show full SKILL.md (649 more words)Show less
Phase 5: Security Review

Read security-audit.md in full. Audit the repository against each applicable category. Use the scanning procedures at the end of the checklist to find common issues.

Focus on the categories most relevant to what you found in discovery:

  • Has Secrets? Check secrets management (SOPS, External Secrets)
  • Has private sources? Check source authentication and Workload Identity
  • Has OCI sources? Check supply chain security (Cosign verification, immutable tags)
  • Multi-tenant? Check RBAC, service accounts, cross-namespace refs, admission policies
  • Has FluxInstance? Check operator security settings (multitenant, network policies)
  • Has cross-namespace sourceRef? Always report it. Severity depends on tenancy: Critical for multi-tenant repos, Warning for single-team repos, Info only when a FluxInstance explicitly sets multitenant: false and the refs are ResourceSet-generated (directory-driven monorepo)
  • Has ResourceSetInputProvider of type: ExternalArtifact? In multi-tenant clusters check serviceAccountName and selectors[].namespace: "*" scope
  • Has image automation? Check push credential separation and branch isolation
  • Has Kustomize overlays? Grep $bundle (if written) for post-render security fields — e.g. a securityContext weakened or image retagged by an overlay patch, which the base files won't show
Phase 6: Report

Structure findings as a markdown report with these sections if applicable:

  1. Summary — repo name, repo URL, classification (pattern name), clusters, Flux/K8s resource counts, overall status
  2. Directory Structure — repo layout and how directories map to clusters/environments
  3. Validation Results — if any errors where found
  4. API Compliance — if deprecated API are found include migration steps
  5. Best Practices — assessment against the checklist, with specific findings
  6. Security — secrets, RBAC, network policies, multi-tenancy
  7. Recommendations — prioritized by severity: Critical, Warning, Info

Flux CRD Reference

Use this table to check API versions and grep the field index before recommending YAML changes.

ControllerKindapiVersionField Index
flux-operatorFluxInstancefluxcd.controlplane.io/v1fluxinstance-fluxcd-v1.fields.txt
flux-operatorFluxReportfluxcd.controlplane.io/v1fluxreport-fluxcd-v1.fields.txt
flux-operatorResourceSetfluxcd.controlplane.io/v1resourceset-fluxcd-v1.fields.txt
flux-operatorResourceSetInputProviderfluxcd.controlplane.io/v1resourcesetinputprovider-fluxcd-v1.fields.txt
source-controllerGitRepositorysource.toolkit.fluxcd.io/v1gitrepository-source-v1.fields.txt
source-controllerOCIRepositorysource.toolkit.fluxcd.io/v1ocirepository-source-v1.fields.txt
source-controllerBucketsource.toolkit.fluxcd.io/v1bucket-source-v1.fields.txt
source-controllerHelmRepositorysource.toolkit.fluxcd.io/v1helmrepository-source-v1.fields.txt
source-controllerHelmChartsource.toolkit.fluxcd.io/v1helmchart-source-v1.fields.txt
source-controllerExternalArtifactsource.toolkit.fluxcd.io/v1externalartifact-source-v1.fields.txt
source-watcherArtifactGeneratorsource.extensions.fluxcd.io/v1beta1artifactgenerator-source-v1beta1.fields.txt
kustomize-controllerKustomizationkustomize.toolkit.fluxcd.io/v1kustomization-kustomize-v1.fields.txt
helm-controllerHelmReleasehelm.toolkit.fluxcd.io/v2helmrelease-helm-v2.fields.txt
notification-controllerProvidernotification.toolkit.fluxcd.io/v1beta3provider-notification-v1beta3.fields.txt
notification-controllerAlertnotification.toolkit.fluxcd.io/v1beta3alert-notification-v1beta3.fields.txt
notification-controllerReceivernotification.toolkit.fluxcd.io/v1receiver-notification-v1.fields.txt
image-reflector-controllerImageRepositoryimage.toolkit.fluxcd.io/v1imagerepository-image-v1.fields.txt
image-reflector-controllerImagePolicyimage.toolkit.fluxcd.io/v1imagepolicy-image-v1.fields.txt
image-automation-controllerImageUpdateAutomationimage.toolkit.fluxcd.io/v1imageupdateautomation-image-v1.fields.txt

Loading References

Load reference files when you need deeper information:

  • repo-patterns.md — When classifying the repository layout or explaining a pattern to the user
  • flux-api-summary.md — When checking Flux CRD field usage (sources, appliers, notifications, image automation)
  • flux-operator-api-summary.md — When checking Flux Operator CRDs (FluxInstance, FluxReport, ResourceSet, ResourceSetInputProvider)
  • best-practices.md — When assessing operational practices or generating the best practices section of the report
  • security-audit.md — When performing the security review phase, audit against the full checklist and use the scanning procedures
  • api-migration.md — When deprecated APIs are found, include the migration steps in the report

Edge Cases

  • Not a Flux repo: If no Flux CRDs are found, say so clearly. The repo might use ArgoCD, plain kubectl, or another tool. Don't force-fit Flux analysis.
  • Mixed tooling: Some repos combine Flux with CI workflows and Terraform. Analyze the Flux parts and note the other tools.
  • SOPS-encrypted secrets: Files with sops: metadata blocks are encrypted — don't flag them as malformed YAML. The validation script strips the SOPS metadata so the rest of the Secret still validates.
  • Generated manifests: The flux-system/gotk-components.yaml is auto-generated by Flux bootstrap. Don't analyze it for best practices — it's managed by Flux itself.
  • Repos without kustomization.yaml: Some repos use plain YAML directories without Kustomize. Flux can reconcile these directly. Don't flag the absence of kustomization.yaml as an error.
  • Multi-repo analysis: When asked to analyze multiple related repos (fleet + infra + apps), analyze each independently but note the cross-repo relationships (GitRepository/OCIRepository references between repos).
  • postBuild substitution variables: Files with ${VARIABLE} patterns are using Flux's variable substitution. Don't flag these as broken YAML — they're resolved at reconciliation time.
  • Third-party CRDs: Resources without a catalog schema (e.g. cert-manager ClusterIssuer) show as "skipped" — expected, not a validation failure.
  • Kustomize build files: kustomization.yaml files with apiVersion: kustomize.config.k8s.io/v1beta1 are Kustomize build configs, not Flux CRDs.

© fluxcd, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 32 other files (scripts, references, assets) in skills/gitops-repo-audit of fluxcd/agent-skills.

  • SKILL.md
  • assets/schemas/alert-notification-v1beta3.fields.txt
  • assets/schemas/artifactgenerator-source-v1beta1.fields.txt
  • assets/schemas/bucket-source-v1.fields.txt
  • assets/schemas/externalartifact-source-v1.fields.txt
  • assets/schemas/fluxinstance-fluxcd-v1.fields.txt
  • assets/schemas/fluxreport-fluxcd-v1.fields.txt
  • assets/schemas/gitrepository-source-v1.fields.txt
  • assets/schemas/helmchart-source-v1.fields.txt
  • assets/schemas/helmrelease-helm-v2.fields.txt
  • assets/schemas/helmrepository-source-v1.fields.txt
  • assets/schemas/imagepolicy-image-v1.fields.txt
  • assets/schemas/imagerepository-image-v1.fields.txt
  • assets/schemas/imageupdateautomation-image-v1.fields.txt
  • assets/schemas/kustomization-kustomize-v1.fields.txt
  • assets/schemas/ocirepository-source-v1.fields.txt
  • assets/schemas/provider-notification-v1beta3.fields.txt
  • assets/schemas/receiver-notification-v1.fields.txt
  • assets/schemas/resourceset-fluxcd-v1.fields.txt
  • … and 14 more

Open the folder on GitHubat commit 0d1fa6c

Compare with similar skills

Gitops Repo Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gitops Repo Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gitops Repo Audit this skillfluxcd/agent-skills231—~3.8kAutomated safety check: PassApache-2.0
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Kubernetes ArchitectCybereason-Public/owLSM2809 repos~2.6kAutomated safety check: PassGPL-2.0
Devopsnicepkg/auto-company1942 repos~814Automated safety check: PassMIT
GitOps with ArgoCD and Fluxwshobson/agents40k12 repos~1.5kAutomated safety check: PassMIT
Cluster HealthDiaoul/home-ops120—~2.7kAutomated safety check: PassUnlicense

Similar skills

  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • Kubernetes Architect

    Cybereason-Public/owLSM

    Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.

    280 GitHub starsUsed in 9 repos~2.6k tokens
    DevOps & CloudAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    194 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.

    40k GitHub starsUsed in 12 repos~1.5k tokens
    DevOps & CloudAuto-check passed
  • Cluster Health

    Diaoul/home-ops

    Full cluster health check for the home-ops Kubernetes cluster.

    120 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Signoz

    qjoly/GitOps

    Manage the self-hosted SigNoz observability stack in this GitOps repo.

    112 GitHub stars~6.1k tokensUpdated today
    DevOps & CloudAuto-check passed

More from fluxcd/agent-skills

  • Commit Assisted By

    fluxcd/agent-skills

    Add an Assisted-by: <agent-name/<model-id git trailer to commits made during an AI-assisted coding session.

    231 GitHub stars~1.3k tokensUpdated 7 days ago
    Auto-check passed
  • Gitops Knowledge

    fluxcd/agent-skills

    Flux CD and Flux Operator expert — answers questions and generates schema-validated YAML for all Flux CRDs (not repo auditing or live cluster debugging).

    231 GitHub stars~3.8k tokensUpdated 7 days ago
    Auto-check passed
  • Run the upstream Flux controller minor release procedure for helm-controller, image-automation-controller, image-reflector-controller, kustomize-controller, notification-controller…

    231 GitHub stars~3.9k tokensUpdated 7 days ago
    Auto-check passed
  • Run the upstream Flux controller patch release procedure for helm-controller, image-automation-controller, image-reflector-controller, kustomize-controller, notification-controller…

    231 GitHub stars~4.7k tokensUpdated 7 days ago
    Auto-check passed
  • Gitops Cluster Debug

    fluxcd/agent-skills

    Debug and troubleshoot Flux CD on live Kubernetes clusters (not local repo files) via the Flux MCP server — inspects Flux resource status, reads controller logs, traces dependency chains, and…

    231 GitHub stars~4.2k tokensUpdated 7 days ago
    Auto-check passed

Works with

Categories

Questions about Gitops Repo Audit

What does Gitops Repo Audit do?

Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets…. Gitops Repo Audit is an agent skill from fluxcd/agent-skills. Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets management, and produces a prioritized GitOps report.

When should I use Gitops Repo Audit?

Gitops Repo Audit fits situations like: users ask to audit; security-check a GitOps repo.

How do I install Gitops Repo Audit in Claude Code?

Run `npx skills add fluxcd/agent-skills --skill gitops-repo-audit -a claude-code`. Or copy the skill folder (skills/gitops-repo-audit in fluxcd/agent-skills) into .claude/skills/gitops-repo-audit in your project. Claude Code loads it when a task matches its description.

How do I install Gitops Repo Audit in Codex?

Run `npx skills add fluxcd/agent-skills --skill gitops-repo-audit -a codex`. Or copy the skill folder (skills/gitops-repo-audit in fluxcd/agent-skills) into .agents/skills/gitops-repo-audit in your project. Codex loads it when a task matches its description.

Can I use Gitops Repo Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fluxcd/agent-skills --skill gitops-repo-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gitops-repo-audit, .gemini/skills/gitops-repo-audit, .github/skills/gitops-repo-audit and .opencode/skills/gitops-repo-audit in your project.

What does Gitops Repo Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Gitops Repo Audit is instructions for the agent only. Compatibility (from SKILL.md): Requires flux, flux-schema, and kustomize or kubectl.

Does Gitops Repo Audit access the network?

SKILL.md names 1 domain. As links in the text: fluxoperator.dev. This is read from the text; nothing was executed.

Is Gitops Repo Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Gitops Repo Audit use?

Gitops Repo Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gitops Repo Audit use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Gitops Repo Audit?

Skills that share tags, products or a category with Gitops Repo Audit: Kubernetes Specialist (Jeffallan/claude-skills, 12k stars), Kubernetes Architect (Cybereason-Public/owLSM, 280 stars), Devops (nicepkg/auto-company, 194 stars) and GitOps with ArgoCD and Flux (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gitops Repo Audit?

fluxcd (a GitHub organization) maintains it in fluxcd/agent-skills, which has 231 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 2, 2026.

Source: fluxcd/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.