Agent skill

Coreweave Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Secure CoreWeave deployments with RBAC, network policies, and secrets management.

MITAuto-check passedBackend & APIs

Install Coreweave Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill coreweave-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace coreweave-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/coreweave-security-basics .claude/skills/coreweave-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
coreweave-security-basics
GitHub stars
2.8k
Token cost
~1.6k tokens
SKILL.md length
419 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Secure CoreWeave deployments with RBAC, network policies, and secrets management.

  • Works in 4 steps: Store API, registry, and model… → Apply namespace-scoped RBAC,… → Validate images and request payloads in… → …
  • Hardening GPU workloads
  • SKILL.md covers Overview, Prerequisites, Instructions and API Key Management, plus 9 more sections
  • Calls kubectl and curl; needs COREWEAVE_API_KEY and COREWEAVE_WEBHOOK_SECRET

What it does

Coreweave Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Secure CoreWeave deployments with RBAC, network policies, and secrets management. Use when hardening GPU workloads, managing model access, or configuring namespace isolation. Trigger with phrases like "coreweave security", "coreweave rbac", "secure coreweave", "coreweave secrets".

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Authorization and RBAC, Deployment and Secrets management. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Hardening GPU workloads
  • Managing model access
  • Configuring namespace isolation
  • With phrases like coreweave security

Example prompts

  • “coreweave security”
  • “coreweave rbac”
  • “secure coreweave”
  • “/coreweave-security-basics”

Requirements

  • A credential in COREWEAVE_API_KEY
  • A credential in COREWEAVE_WEBHOOK_SECRET
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(kubectl:*), Grep

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Store API, registry, and model credentials in the approved secrets manager and
  2. Apply namespace-scoped RBAC, ResourceQuota, and default-deny NetworkPolicy before
  3. Validate images and request payloads in CI, then test webhook signatures with a
  4. Review access events and rotate/revoke the affected secret after suspected exposure.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(kubectl:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.coreweave.com
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • COREWEAVE_API_KEY
    • COREWEAVE_WEBHOOK_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Coreweave Security Basics loads about 1.6k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 419 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 419 words, ~1,588 tokens.

Download SKILL.mdSave it as .claude/skills/coreweave-security-basics/SKILL.md (or your agent's skills folder).
name
coreweave-security-basics
description
Secure CoreWeave deployments with RBAC, network policies, and secrets management. Use when hardening GPU workloads, managing model access, or configuring namespace isolation. Trigger with phrases like "coreweave security", "coreweave rbac", "secure coreweave", "coreweave secrets".
allowed-tools
Read, Write, Edit, Bash(kubectl:*), Grep
compatibility
Designed for Claude Code
version
1.11.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, gpu-cloud, kubernetes, inference, coreweave

CoreWeave Security Basics

Community-contributed. Not affiliated with, endorsed by, or sponsored by CoreWeave, Inc. CoreWeave is a registered trademark of CoreWeave, Inc.

Overview

CoreWeave provides bare-metal GPU cloud on Kubernetes. Security concerns center on compute credential management (kubeconfig, deploy tokens), network isolation between inference workloads, secrets for model registry access (HuggingFace, container registries), and protecting sensitive training data on persistent volumes. A compromised namespace can expose GPU resources, model weights, and customer inference data.

Prerequisites

  • A named namespace owner and a current data classification for the workload.
  • Secrets-manager access for deployment credentials; no credentials in manifests or git.
  • Authority to apply Kubernetes policies in the target namespace and an approved rollback plan.

Instructions

  1. Store API, registry, and model credentials in the approved secrets manager and mount only the minimum secret into the intended workload.
  2. Apply namespace-scoped RBAC, ResourceQuota, and default-deny NetworkPolicy before exposing an inference endpoint.
  3. Validate images and request payloads in CI, then test webhook signatures with a known valid and invalid payload without logging raw secrets.
  4. Review access events and rotate/revoke the affected secret after suspected exposure.

API Key Management

typescript
import { KubeConfig, CoreV1Api } from "@kubernetes/client-node";

function createCoreWeaveClient(): CoreV1Api {
  const apiKey = process.env.COREWEAVE_API_KEY;
  if (!apiKey) {
    throw new Error("Missing COREWEAVE_API_KEY — set via secrets manager");
  }
  const kc = new KubeConfig();
  kc.loadFromDefault();
  const api = kc.makeApiClient(CoreV1Api);
  // Never log kubeconfig or API key contents
  console.log("CoreWeave client initialized for namespace:", process.env.CW_NAMESPACE);
  return api;
}

Webhook Signature Verification

typescript
import crypto from "crypto";
import { Request, Response, NextFunction } from "express";

function verifyCoreWeaveWebhook(req: Request, res: Response, next: NextFunction): void {
  const signature = req.headers["x-coreweave-signature"] as string;
  const secret = process.env.COREWEAVE_WEBHOOK_SECRET!;
  const expected = crypto.createHmac("sha256", secret).update(req.body).digest("hex");
  const supplied = Buffer.from(signature ?? "");
  const expectedBuffer = Buffer.from(expected);
  if (supplied.length !== expectedBuffer.length || !crypto.timingSafeEqual(supplied, expectedBuffer)) {
    res.status(401).send("Invalid signature");
    return;
  }
  next();
}

Input Validation

typescript
import { z } from "zod";

const WorkloadRequestSchema = z.object({
  namespace: z.string().regex(/^[a-z0-9-]+$/).max(63),
  gpu_type: z.enum(["A100_80GB", "A100_40GB", "H100_80GB", "RTX_A6000"]),
  gpu_count: z.number().int().min(1).max(8),
  image: z.string().regex(/^[a-z0-9.\-/]+:[a-z0-9.\-]+$/),
  model_id: z.string().min(1).max(200),
});

function validateWorkloadRequest(data: unknown) {
  return WorkloadRequestSchema.parse(data);
}

Data Protection

typescript
const CW_SENSITIVE_FIELDS = ["kubeconfig", "hf_token", "registry_password", "api_key", "model_weights_url"];

function redactCoreWeaveLog(record: Record<string, unknown>): Record<string, unknown> {
  const redacted = { ...record };
  for (const field of CW_SENSITIVE_FIELDS) {
    if (field in redacted) redacted[field] = "[REDACTED]";
  }
  return redacted;
}

Security Checklist

  • Kubeconfig stored in secrets manager, never in repos
  • Kubernetes Secrets used for model tokens (not env vars in YAML)
  • Network policies restrict inference endpoint access
  • RBAC limits namespace access per team
  • Container images scanned for CVEs before deployment
  • PVCs encrypted at rest for training data
  • GPU workload namespaces isolated with NetworkPolicy
  • Deploy tokens scoped per-namespace, not cluster-wide
Show full SKILL.md (167 more words)Show less

Error Handling

VulnerabilityRiskMitigation
Leaked kubeconfigFull cluster access, GPU resource theftSecrets manager + RBAC scoping
Open inference endpointsUnauthorized model accessNetworkPolicy ingress rules
Unscanned container imagesCVE exploitation in GPU podsCI image scanning before deploy
Overly broad RBACCross-namespace data leakagePer-team namespace RBAC bindings
Unencrypted PVCsTraining data exposureEncrypted storage classes

Output

  • A namespace-level hardening baseline covering secrets, RBAC, network isolation, image validation, and protected persistent storage.
  • A safe signature-validation and input-validation path that rejects malformed requests without leaking credentials or workload data.
  • An incident response path that revokes access, preserves redacted evidence, and verifies recovery with the namespace owner.

Examples

Apply a default-deny ingress policy before adding an explicitly reviewed service exception. Test it in the target namespace with a non-sensitive health endpoint:

bash
kubectl -n inference apply -f networkpolicy-default-deny.yaml
kubectl -n inference get networkpolicy
kubectl -n inference run policy-check --rm -i --restart=Never \
  --image=curlimages/curl -- curl -fsS http://approved-service/health

If the expected workload is blocked, add the smallest labelled ingress rule and retest. Never temporarily open all namespace ingress as a diagnostic workaround.

Resources

Next Steps

See coreweave-prod-checklist.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/.curated/coreweave-security-basics of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Coreweave Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Coreweave Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Coreweave Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMIT
Azure Devtest LabsMicrosoftDocs/Agent-Skills776—~3.5kAutomated safety check: PassCC-BY-4.0
Supercheck Feature Implementationsupercheck-io/supercheck215—~1.1kAutomated safety check: PassAGPL-3.0
Robotics Securityarpitg1304/robotics-agent-skills369—~7.8kAutomated safety check: WarnApache-2.0
Golivemikehasa/golive-skill1.3k—~13kAutomated safety check: NotesMIT
Code Engine SpecialistIBM/CodeEngine118—~3.4kAutomated safety check: PassApache-2.0

Similar skills

  • Azure Devtest Labs

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure DevTest Labs development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations…

    776 GitHub stars~3.5k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Supercheck Feature Implementation

    supercheck-io/supercheck

    Implement a new or changed Supercheck feature end to end across schema, auth/RBAC, services, routes/actions, UI, queues/workers, CLI/recorder, tests, docs, and deployment contracts.

    215 GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Robotics Security

    arpitg1304/robotics-agent-skills

    Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.

    369 GitHub stars~7.8k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: warnings
  • Golive

    mikehasa/golive-skill

    Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).

    1.3k GitHub stars~13k tokensUpdated 7 days ago
    Backend & APIsAuto-check: notes
  • Official

    Deploys, configures, and troubleshoots IBM Cloud Code Engine workloads using the ibmcloud ce CLI.

    118 GitHub stars~3.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Monstermq Broker Config

    vogler75/monster-mq

    Guide for configuring, deploying, and operating the MonsterMQ broker.

    143 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated yesterday
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Questions about Coreweave Security Basics

What does Coreweave Security Basics do?

Secure CoreWeave deployments with RBAC, network policies, and secrets management. Coreweave Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Secure CoreWeave deployments with RBAC, network policies, and secrets management.

When should I use Coreweave Security Basics?

Coreweave Security Basics fits situations like: hardening GPU workloads; managing model access; configuring namespace isolation; with phrases like coreweave security.

How do I install Coreweave Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill coreweave-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/coreweave-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/coreweave-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Coreweave Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill coreweave-security-basics -a codex`. Or copy the skill folder (skills/.curated/coreweave-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/coreweave-security-basics in your project. Codex loads it when a task matches its description.

Can I use Coreweave Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill coreweave-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/coreweave-security-basics, .gemini/skills/coreweave-security-basics, .github/skills/coreweave-security-basics and .opencode/skills/coreweave-security-basics in your project.

What does Coreweave Security Basics need to run?

Going by SKILL.md and its folder, Coreweave Security Basics needs the command-line tools its instructions call (kubectl and curl) and credentials named COREWEAVE_API_KEY and COREWEAVE_WEBHOOK_SECRET. Our summary lists: A credential in COREWEAVE_API_KEY; A credential in COREWEAVE_WEBHOOK_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(kubectl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Coreweave Security Basics access the network?

SKILL.md names 2 domains. As links in the text: docs.coreweave.com and owasp.org. This is read from the text; nothing was executed.

Is Coreweave Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Coreweave Security Basics use?

Coreweave Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Coreweave Security Basics use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Coreweave Security Basics?

Skills that share tags, products or a category with Coreweave Security Basics: Azure Devtest Labs (MicrosoftDocs/Agent-Skills, 776 stars), Supercheck Feature Implementation (supercheck-io/supercheck, 215 stars), Robotics Security (arpitg1304/robotics-agent-skills, 369 stars) and Golive (mikehasa/golive-skill, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Coreweave Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.