Agent skill

Oraclecloud Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Master OCI IAM policy syntax, common policy patterns, and API key management.

MITAuto-check passedSecurity

Install Oraclecloud Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill oraclecloud-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace oraclecloud-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/oraclecloud-security-basics .claude/skills/oraclecloud-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oraclecloud-security-basics
GitHub stars
2.8k
Token cost
~2.5k tokens
SKILL.md length
595 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Master OCI IAM policy syntax, common policy patterns, and API key management.

  • Works in 6 steps: Understand the Policy Verb Hierarchy → IAM Policy Syntax → Common Policy Patterns → …
  • Writing IAM policies
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Calls openssl, pip and python3

What it does

Oraclecloud Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Master OCI IAM policy syntax, common policy patterns, and API key management. Use when writing IAM policies, granting access to compartments, or managing API keys. Trigger with "oraclecloud security basics", "oci iam policy", "oci policy syntax", "oci api key setup".

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/one-pager.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Cloud security and Cryptography. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Writing IAM policies
  • Granting access to compartments
  • Managing API keys
  • With oraclecloud security basics

Example prompts

  • “oraclecloud security basics”
  • “oci iam policy”
  • “oci policy syntax”
  • “/oraclecloud-security-basics”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(pip:*), Bash(oci:*), Grep

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Understand the Policy Verb Hierarchy
  2. IAM Policy Syntax
  3. Common Policy Patterns
  4. Key Resource Family Types
  5. API Key Management
  6. Configure ~/.oci/config

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(pip:*)
    • Bash(oci:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl
    • pip
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.oracle.com
    • ocistatus.oraclecloud.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Oraclecloud Security Basics loads about 2.5k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 595 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 595 words, ~2,533 tokens.

Download SKILL.mdSave it as .claude/skills/oraclecloud-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
oraclecloud-security-basics
description
Master OCI IAM policy syntax, common policy patterns, and API key management. Use when writing IAM policies, granting access to compartments, or managing API keys. Trigger with "oraclecloud security basics", "oci iam policy", "oci policy syntax", "oci api key setup".
allowed-tools
Read, Write, Edit, Bash(pip:*), Bash(oci:*), Grep
compatibility
Designed for Claude Code
version
1.8.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, oraclecloud, oci

Oracle Cloud Security Basics

Overview

OCI IAM policy syntax (Allow group X to manage Y in compartment Z) is the number one enterprise complaint. One wrong policy locks you out of your own resources. One missing verb and your automation silently fails with a 404 NotAuthorizedOrNotFound that looks like a missing resource. This skill is the IAM policy cheat sheet with tested patterns for common access scenarios.

Purpose: Write correct IAM policies, manage API keys securely, and understand the OCI permission model.

Prerequisites

  • OCI Python SDK — pip install oci
  • OCI config file at ~/.oci/config with valid credentials (user, fingerprint, tenancy, region, key_file)
  • Tenancy administrator access (to create policies) or membership in a group with manage policies permission
  • Python 3.8+

Instructions

Step 1: Understand the Policy Verb Hierarchy

OCI uses four verbs in ascending order of privilege. Each higher verb includes all lower verbs:

VerbCapabilitiesTypical Use Case
inspectList resources, get metadata onlyAuditors, read-only dashboards
readInspect + get full resource details/contentsMonitoring tools, reporting
useRead + act on existing resources (start/stop, attach)Developers, operators
manageUse + create, delete, move resourcesAdmins, automation service accounts

Critical: use does NOT include create or delete. This trips up every new OCI team.

Step 2: IAM Policy Syntax

Every OCI policy statement follows this exact structure:

Allow <subject> to <verb> <resource-type> in <location> [where <conditions>]

Subject types:

  • group <group-name> — IAM user group
  • dynamic-group <dg-name> — resource principals (instances, functions)
  • any-user — every authenticated user (use with extreme caution)

Location types:

  • tenancy — entire tenancy (root-level policy only)
  • compartment <name> — specific compartment
  • compartment id <ocid> — by OCID (for automation)
Step 3: Common Policy Patterns

Copy these tested patterns directly. Replace group names and compartment names with your values:

python
import oci

config = oci.config.from_file("~/.oci/config")
identity = oci.identity.IdentityClient(config)

# Create a policy with multiple statements
tenancy_id = config["tenancy"]

# --- Pattern 1: Full admin for a compartment ---
admin_policy = identity.create_policy(
    oci.identity.models.CreatePolicyDetails(
        compartment_id=tenancy_id,
        name="compartment-admins",
        description="Full admin access to the dev compartment",
        statements=[
            "Allow group DevAdmins to manage all-resources in compartment dev"
        ]
    )
)

# --- Pattern 2: Read-only access (auditors) ---
readonly_policy = identity.create_policy(
    oci.identity.models.CreatePolicyDetails(
        compartment_id=tenancy_id,
        name="auditor-readonly",
        description="Read-only access for auditors",
        statements=[
            "Allow group Auditors to read all-resources in compartment prod"
        ]
    )
)

# --- Pattern 3: Compute-only operators ---
compute_policy = identity.create_policy(
    oci.identity.models.CreatePolicyDetails(
        compartment_id=tenancy_id,
        name="compute-operators",
        description="Manage compute, read networking",
        statements=[
            "Allow group ComputeOps to manage instance-family in compartment prod",
            "Allow group ComputeOps to use virtual-network-family in compartment prod",
            "Allow group ComputeOps to read volume-family in compartment prod"
        ]
    )
)

# --- Pattern 4: Network admins ---
network_policy = identity.create_policy(
    oci.identity.models.CreatePolicyDetails(
        compartment_id=tenancy_id,
        name="network-admins",
        description="Network management only",
        statements=[
            "Allow group NetAdmins to manage virtual-network-family in compartment prod",
            "Allow group NetAdmins to manage load-balancers in compartment prod",
            "Allow group NetAdmins to read instance-family in compartment prod"
        ]
    )
)

# --- Pattern 5: Restrict deletes (protect production) ---
no_delete_policy = identity.create_policy(
    oci.identity.models.CreatePolicyDetails(
        compartment_id=tenancy_id,
        name="no-delete-prod",
        description="Allow manage but block deletes in production",
        statements=[
            "Allow group DevOps to manage all-resources in compartment prod where request.permission != 'INSTANCE_DELETE'",
            "Allow group DevOps to manage all-resources in compartment prod where request.permission != 'BUCKET_DELETE'"
        ]
    )
)
print("Policies created successfully")
Step 4: Key Resource Family Types

Policies use resource families, not individual resource types:

Resource FamilyIncludes
all-resourcesEverything (use sparingly)
instance-familyInstances, instance configurations, instance pools
volume-familyBlock volumes, volume backups, volume groups
virtual-network-familyVCNs, subnets, route tables, security lists, NSGs
object-familyBuckets, objects, pre-authenticated requests
database-familyDB systems, autonomous databases, backups
load-balancersLoad balancers, backend sets, listeners
function-familyFunctions, applications, invocations
cluster-familyOKE clusters, node pools
Step 5: API Key Management

Generate and upload API keys for secure programmatic access:

bash
# Generate a 2048-bit RSA key pair
mkdir -p ~/.oci
openssl genrsa -out ~/.oci/oci_api_key.pem 2048
chmod 600 ~/.oci/oci_api_key.pem

# Extract the public key (upload this to OCI Console)
openssl rsa -pubout -in ~/.oci/oci_api_key.pem -out ~/.oci/oci_api_key_public.pem

# Get the key fingerprint (needed for ~/.oci/config)
openssl rsa -pubout -outform DER -in ~/.oci/oci_api_key.pem | openssl md5 -c

Upload the public key in OCI Console: Identity > Users > Your User > API Keys > Add API Key.

Show full SKILL.md (224 more words)Show less
Step 6: Configure ~/.oci/config
ini
[DEFAULT]
user=ocid1.user.oc1..exampleuniqueID
fingerprint=aa:bb:cc:dd:ee:ff:00:11:22:33:44:55:66:77:88:99
tenancy=ocid1.tenancy.oc1..exampleuniqueID
region=us-ashburn-1
key_file=~/.oci/oci_api_key.pem

Verify the config:

python
import oci

config = oci.config.from_file("~/.oci/config")
oci.config.validate_config(config)

identity = oci.identity.IdentityClient(config)
user = identity.get_user(config["user"]).data
print(f"Authenticated as: {user.name} ({user.email})")

Output

Successful completion produces:

  • IAM policies granting appropriate access levels per group/role
  • An API key pair with the public key uploaded to OCI Console
  • A validated ~/.oci/config file with correct user, fingerprint, tenancy, region, and key_file
  • Verified authentication confirmed by a successful Identity API call

Error Handling

ErrorCodeCauseSolution
NotAuthenticated401Bad API key, wrong fingerprint, or expired keyRegenerate key pair and re-upload public key
NotAuthorizedOrNotFound404Missing IAM policy — OCI returns 404, not 403Add policy for the group/resource/compartment
InvalidParameter400Policy syntax errorCheck verb, resource-type, and compartment name spelling
TooManyRequests429Rate limited on Identity APIBack off; Identity has ~10 req/sec limit
InternalError500OCI service errorRetry after 30s; check https://ocistatus.oraclecloud.com
CERTIFICATE_VERIFY_FAILED—SSL certificate issueUpdate CA certificates: pip install certifi

Important: OCI returns 404 NotAuthorizedOrNotFound for both "resource doesn't exist" and "you don't have permission." Always check IAM policies first.

Examples

List all policies in a compartment:

python
import oci

config = oci.config.from_file("~/.oci/config")
identity = oci.identity.IdentityClient(config)

policies = identity.list_policies(compartment_id=config["tenancy"]).data
for p in policies:
    print(f"\n{p.name}:")
    for stmt in p.statements:
        print(f"  {stmt}")

Quick policy validation via CLI:

bash
# List all policies in the tenancy root
oci iam policy list --compartment-id <tenancy-ocid> --all

# Check what a specific group can do
oci iam policy list --compartment-id <tenancy-ocid> --all \
  | python3 -c "import sys,json; [print(s) for p in json.load(sys.stdin)['data'] for s in p['statements'] if 'DevOps' in s]"

Resources

Next Steps

After IAM policies are in place, see oraclecloud-enterprise-rbac for compartment hierarchy design and dynamic groups, or oraclecloud-multi-env-setup for profile-based environment separation.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/oraclecloud-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/one-pager.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Oraclecloud Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oraclecloud Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oraclecloud Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.5kAutomated safety check: PassMIT
Azure Security Keyvault Keys Javamicrosoft/skills3.1k5 repos~2.9kAutomated safety check: PassMIT
Azure Security Keyvault Keys Dotnetmicrosoft/skills3.1k5 repos~3.1kAutomated safety check: PassMIT
Google Cloud PAM Helpergoogle/skills21k—~3.2kAutomated safety check: PassApache-2.0
Azure API Management Security Reviewthomast1906/github-copilot-agent-skills202—~3.1kAutomated safety check: PassMIT
Bom Explorecdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    Azure Key Vault Keys Java SDK for cryptographic key management.

    3.1k GitHub starsUsed in 5 repos~2.9k tokens
    SecurityAuto-check passed
  • Official

    Azure Key Vault Keys SDK for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~3.1k tokens
    SecurityAuto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    SecurityAuto-check passed
  • Azure API Management Security Review

    thomast1906/github-copilot-agent-skills

    Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

    202 GitHub stars~3.1k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Oraclecloud Security Basics

What does Oraclecloud Security Basics do?

Master OCI IAM policy syntax, common policy patterns, and API key management. Oraclecloud Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Master OCI IAM policy syntax, common policy patterns, and API key management.

When should I use Oraclecloud Security Basics?

Oraclecloud Security Basics fits situations like: writing IAM policies; granting access to compartments; managing API keys; with oraclecloud security basics.

How do I install Oraclecloud Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill oraclecloud-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/oraclecloud-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/oraclecloud-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Oraclecloud Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill oraclecloud-security-basics -a codex`. Or copy the skill folder (skills/.curated/oraclecloud-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/oraclecloud-security-basics in your project. Codex loads it when a task matches its description.

Can I use Oraclecloud Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill oraclecloud-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oraclecloud-security-basics, .gemini/skills/oraclecloud-security-basics, .github/skills/oraclecloud-security-basics and .opencode/skills/oraclecloud-security-basics in your project.

What does Oraclecloud Security Basics need to run?

Going by SKILL.md and its folder, Oraclecloud Security Basics needs the command-line tools its instructions call (openssl, pip and python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(pip:*), Bash(oci:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Oraclecloud Security Basics access the network?

SKILL.md names 2 domains. As links in the text: docs.oracle.com and ocistatus.oraclecloud.com. This is read from the text; nothing was executed.

Is Oraclecloud Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Oraclecloud Security Basics use?

Oraclecloud Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oraclecloud Security Basics use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 431 tokens, read only when the agent opens those files.

What are the alternatives to Oraclecloud Security Basics?

Skills that share tags, products or a category with Oraclecloud Security Basics: Azure Security Keyvault Keys Java (microsoft/skills, 3.1k stars), Azure Security Keyvault Keys Dotnet (microsoft/skills, 3.1k stars), Google Cloud PAM Helper (google/skills, 21k stars) and Azure API Management Security Review (thomast1906/github-copilot-agent-skills, 202 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oraclecloud Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.