Agent skill

Oraclecloud Prod Checklist

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Pre-production readiness checklist for OCI — backup policies, security audit, key rotation, encryption, and Cloud Guard.

MITAuto-check passedSecurity

Install Oraclecloud Prod Checklist

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill oraclecloud-prod-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace oraclecloud-prod-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/oraclecloud-prod-checklist .claude/skills/oraclecloud-prod-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oraclecloud-prod-checklist
GitHub stars
2.8k
Token cost
~2.6k tokens
SKILL.md length
542 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Pre-production readiness checklist for OCI — backup policies, security audit, key rotation, encryption, and Cloud Guard.

  • Works in 8 steps: Compartment Isolation Audit → Backup Policy Verification → Security List and NSG Audit → …
  • Preparing an OCI environment for production workloads
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Calls pip

What it does

Oraclecloud Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Pre-production readiness checklist for OCI — backup policies, security audit, key rotation, encryption, and Cloud Guard. Use when preparing an OCI environment for production workloads or auditing an existing deployment. Trigger with "oraclecloud prod checklist", "oci production ready", "oci security audit", "oci well-architected".

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/one-pager.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Security review and Cloud architecture. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Preparing an OCI environment for production workloads
  • Auditing an existing deployment
  • With oraclecloud prod checklist
  • Oci production ready

Example prompts

  • “oraclecloud prod checklist”
  • “oci production ready”
  • “oci security audit”
  • “/oraclecloud-prod-checklist”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(oci:*), Bash(python3:*), Grep

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Compartment Isolation Audit
  2. Backup Policy Verification
  3. Security List and NSG Audit
  4. API Key Rotation Check
  5. Boot Volume Encryption
  6. OS Management Agent Verification
  7. Cloud Guard Status
  8. Vulnerability Scanning

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(oci:*)
    • Bash(python3:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.oracle.com
    • ocistatus.oraclecloud.com
    • oracle.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Oraclecloud Prod Checklist loads about 2.6k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 542 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 542 words, ~2,569 tokens.

Download SKILL.mdSave it as .claude/skills/oraclecloud-prod-checklist/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
oraclecloud-prod-checklist
description
Pre-production readiness checklist for OCI — backup policies, security audit, key rotation, encryption, and Cloud Guard. Use when preparing an OCI environment for production workloads or auditing an existing deployment. Trigger with "oraclecloud prod checklist", "oci production ready", "oci security audit", "oci well-architected".
allowed-tools
Read, Write, Edit, Bash(oci:*), Bash(python3:*), Grep
compatibility
Designed for Claude Code
version
1.8.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, oraclecloud, oci

Oracle Cloud Production Checklist

Overview

OCI has no "Well-Architected Review" equivalent to AWS. This is the pre-production gate: a comprehensive checklist covering backup policies, security list audit, API key rotation, compartment isolation, boot volume encryption, OS Management agent, Cloud Guard, and Vulnerability Scanning. Every item is verifiable via CLI or Python SDK — no subjective assessments, only pass/fail checks.

Purpose: Validate that an OCI environment meets production-grade security, resilience, and operational standards before going live.

Prerequisites

  • OCI CLI installed and configured — ~/.oci/config validated (see oraclecloud-install-auth)
  • Python 3.8+ with the OCI SDK — pip install oci
  • Administrator-level IAM policies — the checks require inspect and read across most service families
  • Target compartment OCID — the compartment being audited
  • Cloud Guard must be enabled at the tenancy level (Administration > Cloud Guard)

Instructions

Step 1: Compartment Isolation Audit

Production workloads must be in a dedicated compartment, not the root:

bash
# List compartments — production should NOT be the root compartment
oci iam compartment list \
  --compartment-id "$TENANCY_OCID" \
  --query 'data[].{name:name, id:id, state:"lifecycle-state"}' \
  --output table

# Verify prod compartment has policies restricting access
oci iam policy list \
  --compartment-id "$PROD_COMPARTMENT_OCID" \
  --query 'data[].{name:name, statements:statements}' \
  --output json

Pass criteria: Production compartment is NOT the root tenancy. Policies follow least-privilege (no manage all-resources in tenancy).

Step 2: Backup Policy Verification
python
import oci

config = oci.config.from_file("~/.oci/config")
blockstorage = oci.core.BlockstorageClient(config)

# List all boot volumes in prod compartment
boot_volumes = blockstorage.list_boot_volumes(
    compartment_id="PROD_COMPARTMENT_OCID",
    availability_domain="AD-1",
).data

for vol in boot_volumes:
    # Check backup policy assignment
    try:
        assignments = blockstorage.get_volume_backup_policy_asset_assignment(
            asset_id=vol.id
        ).data
        if assignments:
            print(f"PASS: {vol.display_name} — backup policy assigned")
        else:
            print(f"FAIL: {vol.display_name} — no backup policy")
    except oci.exceptions.ServiceError:
        print(f"FAIL: {vol.display_name} — cannot check backup policy")

Pass criteria: Every boot volume and block volume has an assigned backup policy (Bronze minimum: weekly backups, 5-week retention).

Step 3: Security List and NSG Audit
bash
# List all security lists in the VCN
oci network security-list list \
  --compartment-id "$PROD_COMPARTMENT_OCID" \
  --vcn-id "$VCN_OCID" \
  --query 'data[].{name:"display-name", ingress:"ingress-security-rules[?source==\`0.0.0.0/0\`]"}' \
  --output json

# FAIL if any rule allows 0.0.0.0/0 ingress on ports other than 80/443
oci network nsg rules list \
  --network-security-group-id "$NSG_OCID" \
  --query 'data[?source==`0.0.0.0/0` && "tcp-options"."destination-port-range".min!=`443`]' \
  --output table

Pass criteria: No security list allows unrestricted ingress (0.0.0.0/0) except ports 80 and 443. Prefer NSGs over security lists for production workloads.

Step 4: API Key Rotation Check
python
import oci
from datetime import datetime, timezone, timedelta

config = oci.config.from_file("~/.oci/config")
identity = oci.identity.IdentityClient(config)

# List API keys for all users in the tenancy
users = identity.list_users(compartment_id=config["tenancy"]).data
max_age = timedelta(days=90)
now = datetime.now(timezone.utc)

for user in users:
    keys = identity.list_api_keys(user_id=user.id).data
    for key in keys:
        age = now - key.time_created
        status = "PASS" if age < max_age else "FAIL"
        print(f"  {status}: {user.name} — key {key.fingerprint} — {age.days} days old")

Pass criteria: No API key older than 90 days. Automated rotation via OCI Vault recommended.

Step 5: Boot Volume Encryption
bash
# Check that all boot volumes use customer-managed keys (not Oracle-managed)
oci bv boot-volume list \
  --compartment-id "$PROD_COMPARTMENT_OCID" \
  --query 'data[].{name:"display-name", kms:"kms-key-id"}' \
  --output table

# FAIL if kms-key-id is null (Oracle-managed default encryption)

Pass criteria: All boot volumes encrypted with customer-managed keys from OCI Vault. Oracle-managed encryption is the default but does not meet most compliance frameworks (SOC 2, PCI-DSS).

Step 6: OS Management Agent Verification
bash
# Check if instance agent plugins are enabled
oci instance-agent plugin list \
  --instanceagent-id "$INSTANCE_OCID" \
  --compartment-id "$PROD_COMPARTMENT_OCID" \
  --query 'data[].{name:name, status:status}' \
  --output table

# Required plugins: Vulnerability Scanning, OS Management Service Agent, Compute Instance Run Command

Pass criteria: OS Management Service Agent, Vulnerability Scanning, and Run Command plugins are all RUNNING.

Step 7: Cloud Guard Status
bash
# Verify Cloud Guard is enabled and detector recipes are active
oci cloud-guard target list \
  --compartment-id "$PROD_COMPARTMENT_OCID" \
  --query 'data.items[].{name:"display-name", state:"lifecycle-state"}' \
  --output table

# Check for open problems
oci cloud-guard problem list \
  --compartment-id "$PROD_COMPARTMENT_OCID" \
  --lifecycle-state "ACTIVE" \
  --query 'data.items[].{label:"resource-name", risk:"risk-level", detail:"additional-details"}' \
  --output table

Pass criteria: Cloud Guard target is ACTIVE with Oracle-managed detector recipes. Zero CRITICAL or HIGH risk problems.

Step 8: Vulnerability Scanning
bash
# List scan recipes and recent results
oci vulnerability-scanning host scan recipe list \
  --compartment-id "$PROD_COMPARTMENT_OCID" \
  --output table

oci vulnerability-scanning host vulnerability list \
  --compartment-id "$PROD_COMPARTMENT_OCID" \
  --query 'data.items[?severity==`CRITICAL`].{name:name, severity:severity, cve:"cve-reference"}' \
  --output table

Pass criteria: Scan recipes assigned to all compute instances. Zero CRITICAL vulnerabilities.

Show full SKILL.md (218 more words)Show less

Output

Successful completion produces:

  • An 8-point pass/fail checklist covering compartment isolation, backups, security rules, key rotation, encryption, OS agents, Cloud Guard, and vulnerability scanning
  • Specific FAIL findings with remediation commands for each item
  • A clear go/no-go decision for production deployment

Error Handling

ErrorCodeCauseSolution
NotAuthorizedOrNotFound404Insufficient IAM policies for auditAdd allow group auditors to inspect all-resources in compartment prod
NotAuthenticated401API key expired or misconfiguredRotate key per Step 4 and update ~/.oci/config
Cloud Guard not enabled—Cloud Guard never activated at tenancy levelEnable via Console: Administration > Cloud Guard > Enable
TooManyRequests429Rate limited when scanning all compartmentsAdd 1-second delay between API calls — no Retry-After header from OCI
InternalError500OCI service issueRetry after 60 seconds; check https://ocistatus.oraclecloud.com
Vulnerability Scanning not available—Not enabled for the region/compartmentEnable: Console > Security > Vulnerability Scanning > Create Recipe

Examples

Quick pre-flight check (CLI one-liners):

bash
# Check compartment isolation
oci iam compartment get --compartment-id "$PROD_COMPARTMENT_OCID" \
  --query 'data.name' --raw-output

# Count boot volumes without backup policies
oci bv boot-volume list --compartment-id "$PROD_COMPARTMENT_OCID" \
  --query 'length(data[?!"backup-policy-id"])' --raw-output

# Count open Cloud Guard problems
oci cloud-guard problem list --compartment-id "$PROD_COMPARTMENT_OCID" \
  --lifecycle-state ACTIVE --query 'length(data.items)' --raw-output

Automated audit script:

python
import oci

config = oci.config.from_file("~/.oci/config")
results = {"pass": 0, "fail": 0}

# Check 1: Compartment exists and is not root
identity = oci.identity.IdentityClient(config)
compartments = identity.list_compartments(compartment_id=config["tenancy"]).data
results["pass" if len(compartments) > 0 else "fail"] += 1
print(f"Compartment isolation: {'PASS' if len(compartments) > 0 else 'FAIL'}")

print(f"\nResults: {results['pass']} passed, {results['fail']} failed")

Resources

Next Steps

After the checklist passes, review oraclecloud-observability to set up monitoring and alerting, or oraclecloud-incident-runbook to prepare your incident response process before going live.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/oraclecloud-prod-checklist of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/one-pager.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Oraclecloud Prod Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oraclecloud Prod Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oraclecloud Prod Checklist this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.6kAutomated safety check: PassMIT
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0
AWS Advisordiegosouzapw/awesome-omni-skills159—~4.3kAutomated safety check: PassMIT
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Vpn Security CheckSergei-thinker/vpn-setup189—~1.5kAutomated safety check: NotesMIT

Similar skills

  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • AWS Advisor

    diegosouzapw/awesome-omni-skills

    AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4.3k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Vpn Security Check

    Sergei-thinker/vpn-setup

    Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.

    189 GitHub stars~1.5k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.5k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Oraclecloud Prod Checklist

What does Oraclecloud Prod Checklist do?

Pre-production readiness checklist for OCI — backup policies, security audit, key rotation, encryption, and Cloud Guard. Oraclecloud Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Pre-production readiness checklist for OCI — backup policies, security audit, key rotation, encryption, and Cloud Guard.

When should I use Oraclecloud Prod Checklist?

Oraclecloud Prod Checklist fits situations like: preparing an OCI environment for production workloads; auditing an existing deployment; with oraclecloud prod checklist; oci production ready.

How do I install Oraclecloud Prod Checklist in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill oraclecloud-prod-checklist -a claude-code`. Or copy the skill folder (skills/.curated/oraclecloud-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/oraclecloud-prod-checklist in your project. Claude Code loads it when a task matches its description.

How do I install Oraclecloud Prod Checklist in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill oraclecloud-prod-checklist -a codex`. Or copy the skill folder (skills/.curated/oraclecloud-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/oraclecloud-prod-checklist in your project. Codex loads it when a task matches its description.

Can I use Oraclecloud Prod Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill oraclecloud-prod-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oraclecloud-prod-checklist, .gemini/skills/oraclecloud-prod-checklist, .github/skills/oraclecloud-prod-checklist and .opencode/skills/oraclecloud-prod-checklist in your project.

What does Oraclecloud Prod Checklist need to run?

Going by SKILL.md and its folder, Oraclecloud Prod Checklist needs the command-line tools its instructions call (pip). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(oci:*), Bash(python3:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Oraclecloud Prod Checklist access the network?

SKILL.md names 3 domains. As links in the text: docs.oracle.com, ocistatus.oraclecloud.com and oracle.com. This is read from the text; nothing was executed.

Is Oraclecloud Prod Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Oraclecloud Prod Checklist use?

Oraclecloud Prod Checklist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oraclecloud Prod Checklist use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 435 tokens, read only when the agent opens those files.

What are the alternatives to Oraclecloud Prod Checklist?

Skills that share tags, products or a category with Oraclecloud Prod Checklist: AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars), AWS Advisor (diegosouzapw/awesome-omni-skills, 159 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars) and Cyberowlai (karimhabush/cyberowl, 263 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oraclecloud Prod Checklist?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.