Cloud Infra Supply Chain
zhaji2333/CkSKILLS
当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。
A skill your agent uses when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming…
$ npx skills add grafana/skills --skill admission-control -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install grafana/skills admission-control --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-app-sdk/admission-control .claude/skills/admission-control && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "admission-control" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-app-sdk/admission-control into .claude/skills/admission-control/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admission-control", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/grafana/skills/tree/main/skills/grafana-app-sdk/admission-controlType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add grafana/skills --skill admission-control -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install grafana/skills admission-control --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/grafana-app-sdk/admission-control .agents/skills/admission-control && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "admission-control" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-app-sdk/admission-control into .agents/skills/admission-control/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admission-control", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/skills --skill admission-control -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install grafana/skills admission-control --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/grafana-app-sdk/admission-control .cursor/skills/admission-control && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "admission-control" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-app-sdk/admission-control into .cursor/skills/admission-control/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admission-control", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/grafana/skills.git --path skills/grafana-app-sdk/admission-control--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add grafana/skills --skill admission-control -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install grafana/skills admission-control --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/grafana-app-sdk/admission-control .gemini/skills/admission-control && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "admission-control" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-app-sdk/admission-control into .gemini/skills/admission-control/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admission-control", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install grafana/skills admission-controlInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add grafana/skills --skill admission-control -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/grafana-app-sdk/admission-control .github/skills/admission-control && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "admission-control" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-app-sdk/admission-control into .github/skills/admission-control/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admission-control", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/skills --skill admission-control -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install grafana/skills admission-control --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/grafana-app-sdk/admission-control .opencode/skills/admission-control && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "admission-control" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-app-sdk/admission-control into .opencode/skills/admission-control/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admission-control", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
admission-controlA skill your agent uses when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming…
Admission Control is an agent skill from grafana/skills, published by the product's own GitHub organization. Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate resources before they are persisted in a grafana-app-sdk app. Provides guidance on implementing validation and mutation admission handlers for grafana-app-sdk apps.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/admission-patterns.md`).
It sits in DevOps & Cloud, covering Monitoring and alerting, Webhooks and Cloud networking. It works with Grafana and Kubernetes. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are go and bash).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.compkg.go.devFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Admission Control loads about 1.7k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 348 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 348 words, ~1,716 tokens.
.claude/skills/admission-control/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Admission control intercepts resource create/update requests before they are persisted. In grafana-app-sdk there are two types:
The app business logic for admission is identical whether the app runs as a standalone operator or inside grafana/apps. The only difference is the runtime: standalone apps stand up their own webhook server; grafana/apps apps have admission auto-registered as a Kubernetes plugin.
For standalone apps, if pkg/app/app.go does not yet exist, a stub App can be generated with:
grafana-app-sdk project component add operatorThis creates scaffolded simple.App which admission handlers can be added to for each kind in ManagedKinds.
// Implement this interface for each kind you want to validate
type Validator interface {
Validate(ctx context.Context, request *app.AdmissionRequest) error
}nil to admit the requestapp.AdmissionRequest provides access to the incoming object and operation typek8s.NewAdmissionError(err error, statusCode int, reason string) (from "github.com/grafana/grafana-app-sdk/k8s") to better control the returned error informationtype MyKindValidator struct{}
func (v *MyKindValidator) Validate(ctx context.Context, req *app.AdmissionRequest) error {
obj, ok := req.Object.(*v1.MyKind)
if !ok {
return fmt.Errorf("admission request object was of invalid type %T (expected *v1.MyKind)", req.Object)
}
// Validate spec fields
if obj.Spec.Title == "" {
return fmt.Errorf("spec.title is required")
}
if obj.Spec.Count < 0 {
return fmt.Errorf("spec.count must be non-negative, got %d", obj.Spec.Count)
}
// Distinguish create vs update
if req.Action == resource.AdmissionActionUpdate && req.OldObject != nil {
old, ok := req.OldObject.(*v1.MyKind)
if !ok {
return fmt.Errorf("admission request old object was of invalid type %T (expected *v1.MyKind)", req.OldObject)
}
if old.Spec.Title != obj.Spec.Title {
return fmt.Errorf("spec.title is immutable after creation")
}
}
return nil
}// Implement this interface to mutate resources before persistence
type Mutator interface {
Mutate(ctx context.Context, request *app.AdmissionRequest) (*app.MutatingResponse, error)
}MutatingResponse containing the (optionally modified) objecttype MyKindMutator struct{}
func (m *MyKindMutator) Mutate(
ctx context.Context,
req *app.AdmissionRequest,
) (*app.MutatingResponse, error) {
obj, ok := req.Object.(*v1.MyKind)
if !ok {
return nil, fmt.Errorf("admission request object was of invalid type %T (expected *v1.MyKind)", req.Object)
}
// Set defaults on create
if req.Action == resource.AdmissionActionCreate {
if obj.Spec.Description == "" {
obj.Spec.Description = "No description provided"
}
}
return &app.MutatingResponse{UpdatedObject: obj}, nil
}Register validators and mutators when building the app in pkg/app/app.go:
func New(cfg app.Config) (app.App, error) {
cfg.KubeConfig.APIPath = "/apis"
a, err := simple.NewApp(simple.AppConfig{
ManagedKinds: []simple.AppManagedKind{
{
Kind: v1.MyKindKind(),
Validator: &MyKindValidator{},
Mutator: &MyKindMutator{},
},
},
})
if err != nil {
return nil, fmt.Errorf("error creating app: %w", err)
}
if err = a.ValidateManifest(cfg.ManifestData); err != nil {
return nil, fmt.Errorf("app manifest validation failed: %w", err)
}
return a, nil
}Note that mutation and validation must also be enabled in the kind's CUE definition (mutation.operations and validation.operations fields) — see the cue-kind-definition skill for details.
Key fields available on app.AdmissionRequest:
| Field | Type | Description |
|---|---|---|
Object | resource.Object | The incoming resource (after decoding) |
OldObject | resource.Object | Previous state (only on UPDATE operations) |
Action | resource.AdmissionAction | AdmissionActionCreate, AdmissionActionUpdate, AdmissionActionDelete, AdmissionActionConnect |
UserInfo | resource.AdmissionUserInfo | The user making the request |
Kind | string | The Object kind |
Group | string | The Object API Group |
Version | string | The Object API Version |
Common patterns to implement:
// Immutability check
if req.Action == resource.AdmissionActionUpdate && old.Spec.ImmutableField != obj.Spec.ImmutableField {
return fmt.Errorf("spec.immutableField cannot be changed after creation")
}
// Cross-field validation
if obj.Spec.StartTime.After(obj.Spec.EndTime) {
return fmt.Errorf("spec.startTime must be before spec.endTime")
}
// Referential validation (e.g. check referenced resource exists)
if _, err := v.client.Get(ctx, resource.Identifier{Name: obj.Spec.RefName, Namespace: obj.Namespace}); err != nil {
return fmt.Errorf("referenced resource %q not found", obj.Spec.RefName)
}| Mode | Admission runtime |
|---|---|
| Standalone operator | App starts a webhook server; Kubernetes routes admission requests to it |
grafana/apps | Admission handlers are auto-registered as a Kubernetes in-process plugin — no separate server required |
The handler code itself is identical in both cases.
© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/grafana-app-sdk/admission-control of grafana/skills.
Open the folder on GitHubat commit 1ccacf2
Admission Control next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Admission Control this skillgrafana/skills | 282 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Cloud Infra Supply Chainzhaji2333/CkSKILLS | 115 | — | ~688 | Automated safety check: Warn | MIT | |
| Prometheus GrafanaBagelHole/DevOps-Security-Agent-Skills | 1.2k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Grafana Dashboardpando85/kaniop | 132 | — | ~987 | Automated safety check: Pass | AGPL-3.0 | |
| Qdrant Monitoring Setupqdrant/skills | 254 | 2 repos | ~874 | Automated safety check: Pass | Apache-2.0 | |
| Loki Loggingsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.6k | Automated safety check: Pass | MIT |
zhaji2333/CkSKILLS
当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。
BagelHole/DevOps-Security-Agent-Skills
Set up metrics collection and visualization with Prometheus and Grafana.
pando85/kaniop
Improve and validate the Kaniop Grafana dashboard against repository metrics and the grigri live cluster.
qdrant/skills
Guides Qdrant monitoring setup including Prometheus scraping, health probes, Hybrid Cloud metrics, alerting, and log centralization.
sickn33/agentic-awesome-skills
Configure Grafana Loki for log aggregation and analysis. An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Set up metrics collection and visualization with Prometheus and Grafana.
grafana/skills
Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).
grafana/skills
Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…
grafana/skills
Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…
grafana/skills
A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.
grafana/skills
Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.
grafana/skills
Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…
Works with
Categories
A skill your agent uses when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming…. Admission Control is an agent skill from grafana/skills, published by the product's own GitHub organization. Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate resources before they are persisted in a grafana-app-sdk app.
Admission Control fits situations like: the user asks to write a validator; implement admission control; write a mutating webhook; add a mutation handler.
Run `npx skills add grafana/skills --skill admission-control -a claude-code`. Or copy the skill folder (skills/grafana-app-sdk/admission-control in grafana/skills) into .claude/skills/admission-control in your project. Claude Code loads it when a task matches its description.
Run `npx skills add grafana/skills --skill admission-control -a codex`. Or copy the skill folder (skills/grafana-app-sdk/admission-control in grafana/skills) into .agents/skills/admission-control in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill admission-control -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/admission-control, .gemini/skills/admission-control, .github/skills/admission-control and .opencode/skills/admission-control in your project.
SKILL.md names no scripts, command-line tools or credentials: Admission Control is instructions for the agent only.
SKILL.md names 2 domains. As links in the text: github.com and pkg.go.dev. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Admission Control is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Admission Control: Cloud Infra Supply Chain (zhaji2333/CkSKILLS, 115 stars), Prometheus Grafana (BagelHole/DevOps-Security-Agent-Skills, 1.2k stars), Grafana Dashboard (pando85/kaniop, 132 stars) and Qdrant Monitoring Setup (qdrant/skills, 254 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 282 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.
Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.