Agent skill

T Cloud Public

by HybridAIOne in HybridAIOne/hybridclaw

Read T Cloud Public (formerly Open Telekom Cloud) infrastructure inventory and prepare guarded DevOps operations through gateway-managed OTC API signing.

MITAuto-check passed

Install T Cloud Public

skills CLI
$ npx skills add HybridAIOne/hybridclaw --skill t-cloud-public -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HybridAIOne/hybridclaw t-cloud-public --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/t-cloud-public .claude/skills/t-cloud-public && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
t-cloud-public
GitHub stars
159
Token cost
~2.9k tokens
SKILL.md length
702 words
Files
4 (incl. references)
Skills in repo
72
Repo updated
First seen
Licence
MIT

At a glance

Read T Cloud Public (formerly Open Telekom Cloud) infrastructure inventory and prepare guarded DevOps operations through gateway-managed OTC API signing.

  • Works in 11 steps: Start with read-only inventory or plan.… → Treat t_cloud_public.cjs as the API… → For prompt/user testing, stop after plan… → …
  • SKILL.md covers Default Workflow, Command Contract, Inventory Coverage and Readiness Checks, plus 3 more sections
  • Runs JavaScript scripts from its folder; calls node and python3; reaches api-enterprise-dashboard.otc-service.com; needs OTC_ACCESS_KEY_ID and OTC_SECRET_ACCESS_KEY

What it does

T Cloud Public is an agent skill from HybridAIOne/hybridclaw. Read T Cloud Public (formerly Open Telekom Cloud) infrastructure inventory and prepare guarded DevOps operations through gateway-managed OTC API signing.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `evals/scenarios.json` and `references/operator-setup.md`).

The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.

Example prompts

  • “/t-cloud-public”

Requirements

  • Python 3
  • A credential in OTC_SECRET_ACCESS_KEY
  • A credential in OTC_ENTERPRISE_DASHBOARD_TOKEN

Workflow steps

11 steps, taken from the first numbered list in SKILL.md.

  1. Start with read-only inventory or plan. V1 helper operations are
  2. Treat t_cloud_public.cjs as the API wrapper. Do not handcraft OTC API
  3. For prompt/user testing, stop after plan or helper http-request payload
  4. For real user requests that need live OTC data, use helper run. The helper
  5. Use http-request only to inspect the generated gateway payload or when
  6. If a live helper run or http_request call returns 401, 403, or a
  7. If a live call returns 429, stop fan-out and report retry guidance from
  8. For account billing, current spend, charges, and consumption, use the
  9. Mutating actions are outside v1 execution. For create/delete/reboot,
  10. Never paste, print, inspect, or ask for OTC signing material, passwords, API
  11. Treat region as plain configuration. Pass --region eu-de explicitly or

What it can do on your machine

Read from SKILL.md and the folder at commit 8162701. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api-enterprise-dashboard.otc-service.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OTC_ACCESS_KEY_ID
    • OTC_SECRET_ACCESS_KEY
    • OTC_SECURITY_TOKEN
    • OTC_ENTERPRISE_DASHBOARD_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

T Cloud Public loads about 2.9k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 42 tokens; SKILL.md has 702 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HybridAIOne/hybridclaw at commit 8162701, republished under its MIT licence (© HybridAIOne). 702 words, ~2,938 tokens.

Download SKILL.mdSave it as .claude/skills/t-cloud-public/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
t-cloud-public
description
Read T Cloud Public (formerly Open Telekom Cloud) infrastructure inventory and prepare guarded DevOps operations through gateway-managed OTC API signing.
user-invocable
true
requires.bins
node

T Cloud Public

Use this skill for T Cloud Public, formerly Open Telekom Cloud, infrastructure inventory, deployment-readiness checks, incident summaries, and guarded DevOps request planning. Invoke it as t-cloud-public. The helper path uses the current product name; credential names intentionally keep established OTC_* identifiers because the public API docs, domains, and customer terminology still use OTC/Open Telekom Cloud names.

Default Workflow

  1. Start with read-only inventory or plan. V1 helper operations are read/list/describe only.
  2. Treat t_cloud_public.cjs as the API wrapper. Do not handcraft OTC API URLs, service endpoints, signing metadata, request tiers, or SecretRefs from memory.
  3. For prompt/user testing, stop after plan or helper http-request payload generation. Do not call helper run or the built-in http_request tool.
  4. For real user requests that need live OTC data, use helper run. The helper constructs an allowlisted request and sends it through the HybridClaw gateway http_request route. For IaaS/API inventory, the gateway resolves OTC_ACCESS_KEY_ID, OTC_SECRET_ACCESS_KEY, optional OTC_SECURITY_TOKEN, and OTC_PROJECT_ID, then signs the request server-side.
  5. Use http-request only to inspect the generated gateway payload or when the active runtime cannot give the helper gateway access.
  6. If a live helper run or http_request call returns 401, 403, or a signature/authentication failure, stop after that first failed call. Do not retry or fan out to more OTC endpoints. Ask the operator to verify credentials, project ID, region, IAM permissions, and clock skew.
  7. If a live call returns 429, stop fan-out and report retry guidance from Retry-After or rate-limit response headers when present.
  8. For account billing, current spend, charges, and consumption, use the documented Enterprise Dashboard API v2 through helper operations billing-daily-consumption and billing-hourly-consumption. These calls use https://api-enterprise-dashboard.otc-service.com/, bearer secret OTC_ENTERPRISE_DASHBOARD_TOKEN, and NDJSON responses from /v2/daily/consumption/ or /v2/hourly/consumption/.
  9. Mutating actions are outside v1 execution. For create/delete/reboot, network/security group, volume/backup restore, DNS/load-balancer, IAM/KMS, database, or container mutations, produce a plan with exact region, project, resource IDs, intended action, rollback, blast radius, and the required F8/F14 operator approval text. Do not execute the mutation.
  10. Never paste, print, inspect, or ask for OTC signing material, passwords, API tokens, AK/SK pairs, project IDs stored as secrets, or session tokens.
  11. Treat region as plain configuration. Pass --region eu-de explicitly or set OTC_REGION=eu-de in the helper environment; do not store region in the encrypted secret store.

See references/operator-setup.md for operator setup, credential scope, companion tooling, autonomy defaults, and rate-limit handling.

Command Contract

Run the helper:

bash
node skills/t-cloud-public/t_cloud_public.cjs --help

Plan without contacting OTC:

bash
node skills/t-cloud-public/t_cloud_public.cjs --format json plan \
  "deploy-check for eu-de production"

Build dry-run gateway payloads:

bash
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request regions
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request service-endpoints --region eu-de
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request service-status
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request quotas --region eu-de
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request servers --region eu-de --limit 50
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request networks --region eu-de --limit 50
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request volumes --region eu-de --limit 50
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request cloud-eye-alarms --region eu-de --limit 50
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request billing-daily-consumption --date 2026-05-24
node skills/t-cloud-public/t_cloud_public.cjs --format json http-request billing-hourly-consumption --date 2026-05-24 --hour 13

Run live read requests through the gateway:

bash
node skills/t-cloud-public/t_cloud_public.cjs --format json run servers --region eu-de --limit 50
node skills/t-cloud-public/t_cloud_public.cjs --format json run security-groups --region eu-de
node skills/t-cloud-public/t_cloud_public.cjs --format json run backups --region eu-de --limit 50
node skills/t-cloud-public/t_cloud_public.cjs --format json run rds-instances --region eu-de --limit 50
node skills/t-cloud-public/t_cloud_public.cjs --format json run billing-daily-consumption --date 2026-05-24
Show full SKILL.md (285 more words)Show less

Inventory Coverage

  • ECS: servers, server details, flavors, quotas
  • VPC/network: VPCs, subnets, security groups, EIPs, load balancers
  • Storage: EVS volumes, EVS snapshots, Cloud Backup and Recovery backups, OBS bucket/object listings, SFS shares
  • Containers and databases: CCE clusters/nodes and RDS instances
  • Observability/audit: Cloud Eye alarms, Cloud Trace events, and Log Tank Service log groups
  • Security/platform checks: IAM regions/projects, IAM service endpoints and service catalog, public status dashboard checks, KMS keys, WAF policies, regional endpoints, and service-status oriented readiness summaries
  • Billing/spend: Enterprise Dashboard daily and hourly consumption streams. Parse each NDJSON line, then sum amount for the requested period.

Readiness Checks

For deployment or incident summaries, gather only the minimum inventory needed:

  • region/project/auth readiness without exposing secrets
  • quota pressure before deploys
  • unhealthy ECS/RDS/CCE resources
  • missing recent backups or snapshots
  • public EIPs and security groups that expose admin ports
  • missing or disabled Cloud Eye alarms
  • recent Cloud Trace changes around the incident window

Summaries should be suitable for R29 cards and R32/R33 server-maintenance handoff: include evidence, region, project, affected resource IDs, recommended next action, and whether operator approval is needed.

Guarded Operations

All write-like operations are amber/red and require exact F8/F14 approval before any future write-capable helper may run:

  • create/update/delete/reboot compute resources
  • modify VPC, security group, EIP, load-balancer, or DNS state
  • attach, detach, resize, delete, or restore storage resources
  • mutate databases, containers, IAM, KMS, or WAF configuration

The approval text must include target region, project, service, resource IDs, action, expected blast radius, rollback, and stop conditions. Stop immediately on authentication failures.

Companion Workflows

Terraform/OpenTofu, Ansible, Cloud Create, official SDKs, Gophercloud, and python-otcextensions are valid companion workflows for operator-owned changes and audits. This bundled skill owns its helper contract and should not shell out to those tools by default.

Validation

bash
python3 skills/skill-creator/scripts/quick_validate.py skills/t-cloud-public
node skills/t-cloud-public/t_cloud_public.cjs --help
node skills/t-cloud-public/t_cloud_public.cjs --format json eval-scenarios

© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/t-cloud-public of HybridAIOne/hybridclaw.

  • SKILL.md
  • evals/scenarios.json
  • references/operator-setup.md
  • t_cloud_public.cjs

Open the folder on GitHubat commit 8162701

Compare with similar skills

T Cloud Public next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

T Cloud Public compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
T Cloud Public this skillHybridAIOne/hybridclaw159—~2.9kAutomated safety check: PassMIT
Model Serving Kubernetessickn33/agentic-awesome-skills47k1 repos~2.3kAutomated safety check: PassMIT
Detecting Lateral Movement With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Alumni Re Hire Trackersickn33/agentic-awesome-skills47k1 repos~3.4kAutomated safety check: PassMIT
Implementing Soar Automation With Phantommukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.0
Detecting Network Anomalies With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Model Serving Kubernetes

    sickn33/agentic-awesome-skills

    Deploy ML models on Kubernetes with KServe (formerly KFServing) and NVIDIA Triton Inference Server.

    47k GitHub starsUsed in 1 repo~2.3k tokens
    DevOps & CloudAuto-check passed
  • Detecting Lateral Movement With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis.

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Alumni Re Hire Tracker

    sickn33/agentic-awesome-skills

    Alumni and re-hire register: former role, last working day, re-hire eligibility, current employer and re-engagement date, as CSV, SQL, JSON Schema or Notion on request.

    47k GitHub starsUsed in 1 repo~3.4k tokens
    Documents & OfficeAuto-check passed
  • Implementing Soar Automation With Phantom

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Network Anomalies With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy and configure Zeek (formerly Bro) to passively analyze network traffic, generate structured connection/DNS/HTTP/SSL/file logs, detect anomalous behavior, and write custom scripts for…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Performing Network Traffic Analysis With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check: notes

More from HybridAIOne/hybridclaw

All 72 skills in this repo
  • Hermes3000 Writing

    HybridAIOne/hybridclaw

    Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.

    159 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Manim Video

    HybridAIOne/hybridclaw

    Plan, script, render, and stitch Manim Community Edition videos in Python.

    159 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Skill Creator

    HybridAIOne/hybridclaw

    Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.

    159 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • XLSX

    HybridAIOne/hybridclaw

    Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.

    159 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Excalidraw

    HybridAIOne/hybridclaw

    Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.

    159 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Google Ads

    HybridAIOne/hybridclaw

    Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.

    159 GitHub stars~4k tokensUpdated today
    Auto-check passed

Questions about T Cloud Public

What does T Cloud Public do?

Read T Cloud Public (formerly Open Telekom Cloud) infrastructure inventory and prepare guarded DevOps operations through gateway-managed OTC API signing. T Cloud Public is an agent skill from HybridAIOne/hybridclaw. Read T Cloud Public (formerly Open Telekom Cloud) infrastructure inventory and prepare guarded DevOps operations through gateway-managed OTC API signing.

How do I install T Cloud Public in Claude Code?

Run `npx skills add HybridAIOne/hybridclaw --skill t-cloud-public -a claude-code`. Or copy the skill folder (skills/t-cloud-public in HybridAIOne/hybridclaw) into .claude/skills/t-cloud-public in your project. Claude Code loads it when a task matches its description.

How do I install T Cloud Public in Codex?

Run `npx skills add HybridAIOne/hybridclaw --skill t-cloud-public -a codex`. Or copy the skill folder (skills/t-cloud-public in HybridAIOne/hybridclaw) into .agents/skills/t-cloud-public in your project. Codex loads it when a task matches its description.

Can I use T Cloud Public in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill t-cloud-public -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/t-cloud-public, .gemini/skills/t-cloud-public, .github/skills/t-cloud-public and .opencode/skills/t-cloud-public in your project.

What does T Cloud Public need to run?

Going by SKILL.md and its folder, T Cloud Public needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and python3) and credentials named OTC_ACCESS_KEY_ID, OTC_SECRET_ACCESS_KEY, OTC_SECURITY_TOKEN and OTC_ENTERPRISE_DASHBOARD_TOKEN. Our summary lists: Python 3; A credential in OTC_SECRET_ACCESS_KEY; A credential in OTC_ENTERPRISE_DASHBOARD_TOKEN.

Does T Cloud Public access the network?

SKILL.md names 1 domain. In commands or code: api-enterprise-dashboard.otc-service.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is T Cloud Public safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does T Cloud Public use?

T Cloud Public is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does T Cloud Public use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to T Cloud Public?

Skills that share tags, products or a category with T Cloud Public: Model Serving Kubernetes (sickn33/agentic-awesome-skills, 47k stars), Detecting Lateral Movement With Zeek (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Alumni Re Hire Tracker (sickn33/agentic-awesome-skills, 47k stars) and Implementing Soar Automation With Phantom (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains T Cloud Public?

HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 159 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 9, 2026.

Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.