Agent skill

Ops

by holon-run in holon-run/holon

Operate servers and services with read-only-first diagnosis, explicit authorization, auditable inventory, operation records, rollback, and verification.

Apache-2.0Auto-check passedDevOps & Cloud

Install Ops

skills CLI
$ npx skills add holon-run/holon --skill ops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install holon-run/holon ops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/holon-run/holon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ops .claude/skills/ops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ops
GitHub stars
153
Token cost
~1.7k tokens
SKILL.md length
635 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

Operate servers and services with read-only-first diagnosis, explicit authorization, auditable inventory, operation records, rollback, and verification.

  • Works in 7 steps: Identify the exact environment, hosts,… → Determine the authorization level before… → Prefer read-only discovery and preflight… → …
  • Tasks that involve Authorization and RBAC
  • SKILL.md covers Destructive service operations, Core rules, Inventory layout and Operation records, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ops is an agent skill from holon-run/holon. Operate servers and services with read-only-first diagnosis, explicit authorization, auditable inventory, operation records, rollback, and verification.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Authorization and RBAC. The repository describes itself as: An agent workbench for ongoing work: preserve goals and progress, connect events and schedules, and resume when the next condition is met. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Authorization and RBAC

Example prompts

  • “/ops”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Identify the exact environment, hosts, services, source of truth, and
  2. Determine the authorization level before touching an external system
  3. Prefer read-only discovery and preflight checks. Do not infer repair
  4. Before a change, state targets, expected effect, risk, commands or API
  5. Use a canary and bounded batches for multi-resource work. Verify each batch
  6. Record actual actions, sanitized evidence, results, and deviations.
  7. Verify service health and intended state after the action. Roll back only

What it can do on your machine

Read from SKILL.md and the folder at commit 671bd7a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ops loads about 1.7k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 635 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from holon-run/holon at commit 671bd7a, republished under its Apache-2.0 licence (© holon-run). 635 words, ~1,683 tokens.

Download SKILL.mdSave it as .claude/skills/ops/SKILL.md (or your agent's skills folder).
name
ops
description
Operate servers and services with read-only-first diagnosis, explicit authorization, auditable inventory, operation records, rollback, and verification.

Operations

Use this skill for platform-neutral server and service operations. It defines the workflow and record formats; environment-specific skills and tools own Linux, SSH, containers, Kubernetes, IaC, cloud, and observability commands.

Destructive service operations

When an operation can stop or replace the process performing the operation, schedule it through an external supervisor or transient unit rather than running it synchronously in the service cgroup. Persist a unique operation id and an explicit planned → scheduled phase before dispatch. Recovery must use the idempotency record to verify the target, not replay the destructive command. Never substitute nohup, &, or sleep for a durable lifecycle boundary.

Core rules

  1. Identify the exact environment, hosts, services, source of truth, and operator request.
  2. Determine the authorization level before touching an external system:
    • L0: local inventory and documentation only.
    • L1: read-only checks within an explicitly confirmed scope.
    • L2: reversible changes, requiring per-action approval unless covered by a scoped, expiring, revocable runbook authorization.
    • L3: disruptive, privileged, network, IAM, DNS, data, secret, bulk, or irreversible work, requiring confirmation of the exact action.
  3. Prefer read-only discovery and preflight checks. Do not infer repair authority from diagnosis or urgency.
  4. Before a change, state targets, expected effect, risk, commands or API actions, success criteria, rollback trigger, and rollback steps.
  5. Use a canary and bounded batches for multi-resource work. Verify each batch before proceeding.
  6. Record actual actions, sanitized evidence, results, and deviations.
  7. Verify service health and intended state after the action. Roll back only when authorized or when a confirmed runbook explicitly permits it.

Stop and ask when target identity, current state, authority, impact, rollback, or verification is unclear.

Inventory layout

Create only the files needed for the current environment:

text
work/
  inventory/
    sources.md
    hosts/<host-id>/info.yaml
    hosts/<host-id>/operations.md
    services/<service-id>/info.yaml
    services/<service-id>/operations.md
  runbooks/
  inspections/
  operations/YYYY/YYYY-MM/
  incidents/

sources.md records each authoritative source, owner, refresh method, and last confirmation. Prefer external sources of truth. AgentHome inventory is a cache unless the operator explicitly designates it authoritative.

Use stable IDs and schema_version: 1. A host info.yaml should contain:

yaml
schema_version: 1
id: prod-web-01
display_name: Production Web 01
environment: production
status: active
owners: [platform]
criticality: high
location: {provider: example-cloud, region: us-east-1}
roles: [web]
access:
  ssh_config_alias: prod-web-01
  bastion_alias: prod-bastion
  credential_ref: secret-manager://ops/prod-web
platform: {os: ubuntu, architecture: amd64}
services: [customer-web]
monitoring: {dashboards: [], alerts: []}
source:
  kind: cmdb
  ref: host/prod-web-01
  last_synced_at: 2026-09-06T00:00:00Z
last_confirmed_at: 2026-09-06T00:00:00Z

A service info.yaml should contain:

yaml
schema_version: 1
id: customer-web
display_name: Customer Web
environment: production
status: active
owners: [web-team]
criticality: high
service_type: systemd
runs_on: {hosts: [prod-web-01, prod-web-02]}
dependencies: [customer-api]
repository: github:example/customer-web
deployment_source: gitops:environments/prod/customer-web
runbook: work/runbooks/customer-web.md
monitoring: {dashboards: [], alerts: []}
backup: {policy_ref: backup/customer-web}
maintenance:
  timezone: America/New_York
  windows: []
source:
  kind: gitops
  ref: services/customer-web
  last_synced_at: 2026-09-06T00:00:00Z
last_confirmed_at: 2026-09-06T00:00:00Z

Never store a credential value. credential_ref may contain only a controlled secret-manager reference or local connection alias. Keep permission policies separate from resource facts so an inventory edit cannot expand authority.

When renaming or retiring a resource, preserve its stable ID through a redirect or tombstone so historical links remain valid.

Show full SKILL.md (257 more words)Show less

Operation records

Create one authoritative record per logical operation:

text
work/operations/YYYY/YYYY-MM/OP-<UTC timestamp>-<slug>.md

Record:

  • UTC time and operator-local time with IANA timezone
  • WorkItem, incident, change, or request reference
  • actor, target environment, host IDs, and service IDs
  • request and authorization summary, including standing authorization scope
  • purpose, risk level, preflight results, plan, and rollback plan
  • actual commands or API actions, with secrets and sensitive output redacted
  • exit status, changed resources, verification evidence, and final result
  • rollback status, residual risk, follow-up owner, and due condition

Do not silently rewrite an error. Append a dated correction. Put large raw output in a controlled external log or attachment and retain only a summary and reference.

Append a concise link to each affected resource's operations.md:

markdown
## 2026-09

- `2026-09-06T10:30:00Z` · change · success ·
  [OP-20260906T103000Z-restart-customer-web](../../../operations/2026/2026-09/OP-20260906T103000Z-restart-customer-web.md)
  — Approved rolling restart; health checks passed.

The resource timeline is an index, not a duplicate operation log.

Incidents

Use work/incidents/INC-<UTC timestamp>-<slug>.md for a material anomaly. Record detection, impact, affected resources, evidence, timeline, communications, mitigations, current state, owner, and next update. Keep facts separate from hypotheses. Incident creation and notification do not authorize remediation.

Scheduled inspections

Scheduled inspection is off by default. Before creating a timer or recurring job, confirm:

  • scope and exclusions
  • IANA timezone and frequency or wall-clock time
  • allowed checks, concurrency, and timeouts
  • reporting and anomaly-notification behavior
  • maintenance and silence windows
  • report-only versus explicitly named remediation runbooks
  • review date, end date, and pause/revocation conditions

Persist the confirmed policy in work/inspections/policy.yaml. Reconfirm any change to scope, schedule, notification, or remediation authority. Give every run its own tracked lifecycle and dated inspection record. The default for an anomaly is to report and open an incident, not to repair it.

© holon-run, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ops of holon-run/holon.

Open the folder on GitHubat commit 671bd7a

Compare with similar skills

Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ops this skillholon-run/holon153—~1.7kAutomated safety check: PassApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k1 repos~3.1kAutomated safety check: PassCustom licence
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Executing Distributed System Testsshenli/distributed-system-testing231—~5.1kAutomated safety check: NotesMIT
Documentationhome-operations/kopiur113—~2.5kAutomated safety check: PassAGPL-3.0
Kubernetes Patternstimothywarner-org/claude-code224—~4.5kAutomated safety check: PassMIT

Similar skills

  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub starsUsed in 1 repo~3.1k tokens
    DevOps & CloudAuto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • Executing Distributed System Tests

    shenli/distributed-system-testing

    A skill your agent uses when running a previously designed distributed-systems test plan against a real or simulated cluster — driving fault injection, workload, chaos scenarios, linearizability /…

    231 GitHub stars~5.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Documentation

    home-operations/kopiur

    How Kopiur writes and maintains user-facing docs — the MkDocs Material site under docs/ and the example manifests under deploy/examples/.

    113 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Kubernetes Patterns

    timothywarner-org/claude-code

    Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments.

    224 GitHub stars~4.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Admin

    grafana/skills

    Official

    Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

    279 GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from holon-run/holon

All 13 skills in this repo
  • Video Production

    holon-run/holon

    Assemble existing local images, videos, audio and subtitles into preview/final videos with FFmpeg, technical QC and provenance.

    153 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • GitHub Issue Solve

    holon-run/holon

    Solve a GitHub issue by collecting context, implementing a fix, and opening or updating a pull request.

    153 GitHub stars~912 tokensUpdated today
    Auto-check passed
  • GitHub PR Fix

    holon-run/holon

    Fix a GitHub pull request by addressing feedback or CI failures, pushing changes, and publishing replies.

    153 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Code Health Audit

    holon-run/holon

    Audit code-health and technical-debt signals with evidence, rank proportionate interventions from focused cleanup to broad coordinated refactors, and draft implementation-ready plans without…

    153 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Code Review

    holon-run/holon

    Review a set of code changes using evidence-backed findings, explicit confidence, and a clear coverage summary.

    153 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Ghx

    holon-run/holon

    Guidance for safe, reliable GitHub CLI workflows across issues, pull requests, and reviews.

    153 GitHub stars~1k tokensUpdated today
    Auto-check passed

Categories

Questions about Ops

What does Ops do?

Operate servers and services with read-only-first diagnosis, explicit authorization, auditable inventory, operation records, rollback, and verification. Ops is an agent skill from holon-run/holon. Operate servers and services with read-only-first diagnosis, explicit authorization, auditable inventory, operation records, rollback, and verification.

When should I use Ops?

Ops fits situations like: tasks that involve Authorization and RBAC.

How do I install Ops in Claude Code?

Run `npx skills add holon-run/holon --skill ops -a claude-code`. Or copy the skill folder (skills/ops in holon-run/holon) into .claude/skills/ops in your project. Claude Code loads it when a task matches its description.

How do I install Ops in Codex?

Run `npx skills add holon-run/holon --skill ops -a codex`. Or copy the skill folder (skills/ops in holon-run/holon) into .agents/skills/ops in your project. Codex loads it when a task matches its description.

Can I use Ops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add holon-run/holon --skill ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ops, .gemini/skills/ops, .github/skills/ops and .opencode/skills/ops in your project.

What does Ops need to run?

SKILL.md names no scripts, command-line tools or credentials: Ops is instructions for the agent only.

Does Ops access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ops safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ops use?

Ops is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ops use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ops?

Skills that share tags, products or a category with Ops: KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Kubernetes Specialist (Jeffallan/claude-skills, 12k stars), Executing Distributed System Tests (shenli/distributed-system-testing, 231 stars) and Documentation (home-operations/kopiur, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ops?

holon-run (a GitHub organization) maintains it in holon-run/holon, which has 153 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 8, 2026.

Source: holon-run/holon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.