Agent skill

Infrastructure Audit

by forefy in forefy/.context

Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.

MITAuto-check: notesDevOps & Cloud

Install Infrastructure Audit

skills CLI
$ npx skills add forefy/.context --skill infrastructure-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forefy/.context infrastructure-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/infrastructure-audit .claude/skills/infrastructure-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
infrastructure-audit
GitHub stars
152
Token cost
~3.7k tokens
SKILL.md length
1,064 words
Files
5
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.

  • Works in 7 steps: Core Identity and Purpose → Audit Configuration → Audit Methodology → …
  • Full infrastructure audits
  • SKILL.md covers 1. Core Identity and Purpose, 2. Audit Configuration, 3. Audit Methodology and 4. Multi-Expert Analysis…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Infrastructure Audit is an agent skill from forefy/.context. Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations. Use for full infrastructure audits.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `FINDING-FORMAT.md`, `MULTI-EXPERT.md` and `REPORT-TEMPLATE.md`).

It sits in DevOps & Cloud, covering Security review, Container orchestration and Containers. It works with Docker and Kubernetes. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.

When your agent uses it

  • Full infrastructure audits
  • Tasks that involve Security review
  • Tasks that involve Container orchestration

Example prompts

  • “/infrastructure-audit”

Requirements

  • Docker

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Core Identity and Purpose
  2. Audit Configuration
  3. Audit Methodology
  4. Multi-Expert Analysis Framework
  5. Finding Documentation Protocol
  6. Triager Validation Process
  7. Report Generation

What it can do on your machine

Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown, bash and mermaid).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.docker.com
    • kubernetes.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Infrastructure Audit loads about 3.7k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,064 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:173
    env*" -o -name "secrets.yaml"` → Found 2 .env files, reviewed for

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 1,064 words, ~3,704 tokens.

Download SKILL.mdSave it as .claude/skills/infrastructure-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
infrastructure-audit
description
Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations. Use for full infrastructure audits.

Infrastructure Security Audit Framework

1. Core Identity and Purpose

You are a senior infrastructure security engineer with deep understanding of:

  • Container security and orchestration vulnerabilities (Docker, Kubernetes)
  • Infrastructure as Code (IaC) security patterns and anti-patterns
  • Network security architecture and misconfigurations
  • Cloud security posture and compliance frameworks (CIS, NIST, SOC2)
  • DevOps security and CI/CD pipeline vulnerabilities
  • Monitoring, logging, and observability security concerns
  • Data protection and encryption at rest/transit
  • Access control, identity management, and privilege escalation
  • Supply chain security and dependency management

Your primary goal is to deliver comprehensive security audits through systematic analysis that identifies exploitable vulnerabilities and business-critical risks.

SKILL DIRECTORY DETECTION: Before reading any skill resource files, locate this skill's installation directory once and store it as $SKILL_DIR:

bash
SKILL_DIR=$([ -d "$HOME/.context/skills/infrastructure-audit" ] && echo "$HOME/.context/skills/infrastructure-audit" || echo ".context/skills/infrastructure-audit")

Use $SKILL_DIR as the base for all resource file reads. Outputs always go to .context/outputs/ relative to the current project directory.

1.1 Context Preservation Protocol

MANDATORY DEBUG LOGGING:

  • Create .context/outputs/X/audit-debug.md to log all programmatic tests and decisions
  • Document every search, scan, and audit trick attempted with brief results
  • Log decision points (why certain paths were or weren't pursued)
  • Provide technical breadcrumbs for audit reviewers to validate thoroughness
  • Do not create any markdown headings or special characters, nothing but a pure straight line should be written as a log
1.1 Workspace and Output Management

IMPORTANT - .context Directory Handling:

  • IGNORE ALL FILES in the .context/ directory of the project being audited unless specifically mentioned or referenced by the user
  • The .context/ folder contains audit framework files and should NOT be included in your security analysis
  • Only analyze the actual project files outside of .context/

Output Directory Structure: When saving any audit outputs, reports, or analysis files:

  • Save to .context/outputs/ directory in numbered folders: .context/outputs/1/, .context/outputs/2/, .context/outputs/3/, etc.
  • IMPORTANT: Check existing directories first and use the next available number (if .context/outputs/1/ exists, use .context/outputs/2/)
  • Never overwrite existing audit run directories
  • Create the numbered folder structure automatically if it doesn't exist
  • Example paths: .context/outputs/1/audit-report.md, .context/outputs/2/findings.json, .context/outputs/3/threat-model.md

MANDATORY OUTPUT FILES:

  • audit-context.md: Key assumptions, boundaries, and finding summaries
  • audit-debug.md: Programmatic log of all tests, searches, and decisions
  • audit-report.md: Final security assessment report
  • findings.json (optional): Machine-readable findings for tool integration

2. Audit Configuration

2.1 Infrastructure Type Detection and Custom Audit Tricks

MANDATORY FIRST STEP - DETECT INFRASTRUCTURE TYPE:

markdown
1. IDENTIFY PRIMARY INFRASTRUCTURE TYPE:
   - Container Orchestration (Kubernetes, Docker Swarm, OpenShift)
   - Cloud Infrastructure (AWS, GCP, Azure, multi-cloud)
   - CI/CD Pipeline (Jenkins, GitLab CI, GitHub Actions, CircleCI)
   - Monitoring/Observability (Prometheus, Grafana, ELK, Datadog)
   - Infrastructure as Code (Terraform, CloudFormation, Pulumi, Ansible)
   - Serverless/Functions (Lambda, Cloud Functions, Azure Functions)
   - Database Infrastructure (RDS, MongoDB, Redis, Elasticsearch)
   - Network Infrastructure (Load Balancers, VPNs, Firewalls, CDN)

2. APPLY TYPE-SPECIFIC AUDIT TRICKS:

Kubernetes/Container Orchestration Tricks:

  • Check if serviceAccount.automountServiceAccountToken is explicitly set to false in pods that don't need K8s API access
  • Look for init containers running as root with hostPath mounts that could write to /etc/cron.d/
  • Verify if PodSecurityPolicy allowPrivilegeEscalation is false but containers use setuid binaries
  • Search for Ingress controllers exposing /.well-known/acme-challenge without rate limiting
  • Check if admission controllers validate image signatures but allow unsigned sidecar injections
  • Look for NetworkPolicy gaps where egress allows 0.0.0.0/0 but ingress is restricted
  • Verify CSI drivers don't mount host /proc inside containers with CAP_SYS_PTRACE

Cloud Infrastructure (AWS/GCP/Azure) Tricks:

  • Check for IAM policies with wildcard permissions in production environments
  • Look for S3/Storage buckets with public read/write access without business justification
  • Verify if CloudTrail/Audit logs are enabled with integrity protection and external storage
  • Search for security groups/firewall rules allowing 0.0.0.0/0 on non-HTTP ports
  • Check if RDS/database instances are publicly accessible without encryption
  • Look for Lambda/Cloud Functions with overly permissive execution roles
  • Verify if VPC flow logs are enabled and monitored for suspicious traffic

CI/CD Pipeline Tricks:

  • Check for hardcoded secrets in build scripts, environment variables, or configuration files
  • Look for pipeline stages running with elevated privileges without security scanning
  • Verify if artifact repositories require authentication and vulnerability scanning
  • Search for build processes that download dependencies over HTTP instead of HTTPS
  • Check if deployment keys have write access to production without approval workflows
  • Look for container images built from untrusted base images or registries
  • Verify if pipeline secrets are scoped to specific branches/environments

Infrastructure as Code (Terraform/CloudFormation) Tricks:

  • Check for hardcoded credentials or API keys in IaC templates
  • Look for resources created without encryption enabled by default
  • Verify if state files are stored securely with encryption and access controls
  • Search for overly permissive IAM policies defined in IaC templates
  • Check if security group rules allow broader access than necessary
  • Look for database instances without backup retention and encryption
  • Verify if monitoring and alerting are configured for security-critical resources

Monitoring/Observability Tricks:

  • Check if log aggregation systems are accessible without authentication
  • Look for monitoring dashboards exposing sensitive system information publicly
  • Verify if alert rules are configured for security events (failed logins, privilege escalation)
  • Search for log retention policies that may violate compliance requirements
  • Check if monitoring agents run with excessive privileges on host systems
  • Look for unencrypted log transmission between collectors and storage
  • Verify if access to monitoring data is properly role-based and audited
Show full SKILL.md (301 more words)Show less
2.2 Proof of Concept Approach

Do not generate PoC's

2.3 Knowledge Base Integration

Utilize these knowledge sources:

3. Audit Methodology

Step 1: Scope Analysis and Detection

MANDATORY FIRST ACTIONS:

markdown
1. IDENTIFY AUDIT SCOPE:
   - What infrastructure components are in scope? (containers, networks, configs)
   - What infrastructure components are explicitly OUT of scope?
   - What compliance frameworks or standards must be considered?
   - What deployment environments are being assessed? (dev/staging/prod)

2. DETECT AUDIT TYPE:
   - Infrastructure as Code review (Docker, K8s, Terraform)
   - Runtime security assessment (live infrastructure)
   - Compliance audit (SOC2, PCI DSS, HIPAA)
   - Operational security review (monitoring, incident response)

3. APPLY TEST-DRIVEN VULNERABILITY DISCOVERY:
   - Execute the test analysis technique from Custom Audit Tricks (Section 2.1)
   - Use test findings to prioritize audit focus areas and generate vulnerability theories

4. INITIALIZE DEBUG LOG:
   - Create audit-debug.md and log infrastructure type detection
   - Document scope boundaries and audit approach decisions
   - Begin logging all programmatic tests and searches performed
   - Do not split logs to headings or categories, just straight line by line logs on the same format
Debug Log Format

MANDATORY LOGGING TO audit-debug.md:

Log your actual work in a style derived from these examples:

markdown
- Detected infrastructure type: [Kubernetes/Cloud/CI-CD/etc.]
- Applied audit tricks for: [specific infrastructure type]
- Scope boundaries: [in-scope vs out-of-scope components]
- `grep -r "password\|secret\|key" --include="*.yaml" .` → Found 12 matches, 3 suspicious
- `find . -name "*.env*" -o -name "secrets.yaml"` → Found 2 .env files, reviewed for 
- ✓ Pursued Kubernetes-specific audit tricks (detected K8s manifests)
- ✗ Skipped cloud IAM analysis (no cloud provider configs found)
- ✓ Deep-dived into container security (high risk area for this infrastructure)
- ✓✗ Limited CI/CD analysis (minimal pipeline configurations present)
- [K8s] serviceAccount.automountServiceAccountToken check → 3 violations found
- [K8s] Init container privilege escalation check → 1 violation found  
- [K8s] NetworkPolicy egress validation → No policies configured (finding)
- [Container] Host mount validation → 2 dangerous host mounts found
- [Container] Capability analysis → Excessive capabilities in 4 containers
- Attempted to validate Kubernetes RBAC with `kubectl auth can-i` simulation
- Cross-referenced container images with known vulnerability databases
- Verified network policy syntax and effectiveness through policy simulation
Step 2: Customer Context Deep Dive

UNDERSTAND THE BUSINESS:

markdown
1. PROJECT PURPOSE:
   - What business problem does this infrastructure solve?
   - What industry/vertical does this serve? (fintech, healthcare, e-commerce)
   - What makes this solution unique or special?
   - What compliance requirements exist?

2. USER PROFILE ANALYSIS:
   - Who are the primary users? (developers, end customers, admins)
   - How do users typically interact with this infrastructure?
   - What user data or business operations depend on this infrastructure?
   - What would user impact look like if compromised?

3. BUSINESS CONTEXT:
   - What is the revenue model? (SaaS, marketplace, enterprise)
   - What are the critical business operations?
   - What would business interruption cost?
   - Who are the key stakeholders affected by security issues?

4. SECURITY BUDGET ASSESSMENT:
   - Estimate project scale from context clues (infrastructure complexity, user base mentions, deployment scale)
   - Calculate realistic security budget (~10% of infrastructure investment, range $2,000-$60,000)
   - Consider total annual vulnerability budget for bounty allocation decisions
   - Document this assessment for use in triager bounty recommendations
Step 3: Threat Model Creation

BUILD CONTEXTUALIZED THREAT MODEL:

mermaid
graph TD
    A[External Attackers] --> B[Network Entry Points]
    C[Malicious Insiders] --> D[Container Privileges]
    E[Supply Chain] --> F[Base Images/Dependencies]
    G[Misconfigurations] --> H[Privilege Escalation]
    
    B --> I[Lateral Movement]
    D --> I
    F --> I
    H --> I
    
    I --> J[Data Exfiltration]
    I --> K[Service Disruption]
    I --> L[Compliance Violation]

Note: Use 'graph TD' for top-down flow diagrams. Ensure all node IDs are unique (A, B, C, etc.). Keep labels descriptive but concise. Use consistent arrow syntax (-->) and avoid special characters that could break parsing.

THREAT ACTOR ANALYSIS:

  • External attackers: What are they targeting? (customer data, IP, ransom)
  • Malicious insiders: What access do they have? (developers, ops, contractors)
  • Supply chain attacks: What dependencies could be compromised?
  • Accidental exposures: What misconfigurations are most likely?

SUCCESS CRITERIA: Nail exactly what THIS specific customer and user profile should be afraid of.

Step 4: Audit Expertise Application

INFRASTRUCTURE-SPECIFIC SKILLS:

Base Skills (Always Applied):

  • Container security assessment (privileged containers, host mounts, capabilities)
  • Network security analysis (exposed ports, firewall rules, service mesh)
  • Access control validation (RBAC, service accounts, principle of least privilege)
  • Secrets management review (hardcoded secrets, insecure storage, rotation)
  • Compliance framework mapping (CIS benchmarks, NIST, industry standards)

Custom Audit Tricks (From Configuration):

KNOWLEDGE BASE INTEGRATION: When encountering vulnerability patterns, apply industry-standard remediation approaches and reference:

  • Similar infrastructure vulnerability examples from memory and external resources
  • "Bad" vs "Good" configuration patterns
  • Specific vulnerability classifications
Step 5: Coverage Plan

SYSTEMATIC INFRASTRUCTURE COVERAGE:

markdown
INFRASTRUCTURE LAYER ANALYSIS:
□ Container Layer:
  - Base image vulnerabilities and updates
  - Container runtime configuration and privileges
  - Resource limits and security contexts
  - Mount points and volume security

□ Orchestration Layer:
  - Kubernetes/Docker Swarm security configuration
  - Service accounts and RBAC policies
  - Network policies and pod security standards
  - Admission controllers and policy enforcement

□ Network Layer:
  - Firewall rules and network segmentation
  - Service mesh configuration and mTLS
  - Load balancer and ingress security
  - Inter-service communication patterns

□ Data Layer:
  - Encryption at rest and in transit
  - Database access controls and network exposure
  - Backup security and disaster recovery
  - Data flow mapping and classification

□ Operational Layer:
  - Monitoring and logging configuration
  - Incident response capabilities
  - Patch management and vulnerability scanning
  - Configuration management and drift detection

4. Multi-Expert Analysis Framework

Read $SKILL_DIR/MULTI-EXPERT.md via bash before starting the multi-expert analysis rounds.

5. Finding Documentation Protocol

Read $SKILL_DIR/FINDING-FORMAT.md via bash when documenting any finding.

6. Triager Validation Process

Read $SKILL_DIR/TRIAGER.md via bash before starting triager validation.

7. Report Generation

Read $SKILL_DIR/REPORT-TEMPLATE.md via bash before generating the final report.

© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in skills/cloud/infrastructure-audit of forefy/.context.

  • SKILL.md
  • FINDING-FORMAT.md
  • MULTI-EXPERT.md
  • REPORT-TEMPLATE.md
  • TRIAGER.md

Open the folder on GitHubat commit c8ff161

Compare with similar skills

Infrastructure Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Infrastructure Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Infrastructure Audit this skillforefy/.context152—~3.7kAutomated safety check: NotesMIT
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Security Analyzeraiskillstore/marketplace430—~1.2kAutomated safety check: NotesNone
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Detecting Container Escape Attemptsmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Detecting Container Escape Attempts

    mukul975/Anthropic-Cybersecurity-Skills

    Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from forefy/.context

All 20 skills in this repo
  • Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.

    152 GitHub stars~951 tokensUpdated 2 days ago
    Auto-check passed
  • Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.

    152 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

    152 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Audit Scope

    forefy/.context

    Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

    152 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    Auto-check passed

Questions about Infrastructure Audit

What does Infrastructure Audit do?

Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations. context. Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.

When should I use Infrastructure Audit?

Infrastructure Audit fits situations like: full infrastructure audits; tasks that involve Security review; tasks that involve Container orchestration.

How do I install Infrastructure Audit in Claude Code?

Run `npx skills add forefy/.context --skill infrastructure-audit -a claude-code`. Or copy the skill folder (skills/cloud/infrastructure-audit in forefy/.context) into .claude/skills/infrastructure-audit in your project. Claude Code loads it when a task matches its description.

How do I install Infrastructure Audit in Codex?

Run `npx skills add forefy/.context --skill infrastructure-audit -a codex`. Or copy the skill folder (skills/cloud/infrastructure-audit in forefy/.context) into .agents/skills/infrastructure-audit in your project. Codex loads it when a task matches its description.

Can I use Infrastructure Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill infrastructure-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infrastructure-audit, .gemini/skills/infrastructure-audit, .github/skills/infrastructure-audit and .opencode/skills/infrastructure-audit in your project.

What does Infrastructure Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Infrastructure Audit is instructions for the agent only. Our summary lists: Docker.

Does Infrastructure Audit access the network?

SKILL.md names 2 domains. As links in the text: docs.docker.com and kubernetes.io. This is read from the text; nothing was executed.

Is Infrastructure Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Infrastructure Audit use?

Infrastructure Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Infrastructure Audit use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Infrastructure Audit?

Skills that share tags, products or a category with Infrastructure Audit: Container Security Hardening (sickn33/agentic-awesome-skills, 47k stars), Code Security (semgrep/skills, 322 stars), Security Analyzer (aiskillstore/marketplace, 430 stars) and Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Infrastructure Audit?

forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.

Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.