Provider Bug Review
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
Comprehensive guide for kcli usage. An agent skill from karmab/kcli.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add karmab/kcli --skill kcli -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install karmab/kcli kcli --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kcli .claude/skills/kcli && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kcli" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli into .claude/skills/kcli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/karmab/kcli/tree/main/skills/kcliType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add karmab/kcli --skill kcli -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install karmab/kcli kcli --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kcli .agents/skills/kcli && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kcli" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli into .agents/skills/kcli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add karmab/kcli --skill kcli -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install karmab/kcli kcli --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kcli .cursor/skills/kcli && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kcli" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli into .cursor/skills/kcli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/karmab/kcli.git --path skills/kcli--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add karmab/kcli --skill kcli -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install karmab/kcli kcli --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kcli .gemini/skills/kcli && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kcli" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli into .gemini/skills/kcli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install karmab/kcli kcliInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add karmab/kcli --skill kcli -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kcli .github/skills/kcli && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kcli" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli into .github/skills/kcli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add karmab/kcli --skill kcli -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install karmab/kcli kcli --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kcli .opencode/skills/kcli && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kcli" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli into .opencode/skills/kcli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kcliComprehensive guide for kcli usage. An agent skill from karmab/kcli.
Kcli is an agent skill from karmab/kcli. Comprehensive guide for kcli usage. Use when creating VMs, deploying plans, managing clusters, or performing any kcli operations. Covers all common user workflows.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes, Amazon Web Services, Google Cloud and Microsoft Azure. The repository describes itself as: Management tool for virtualization and kubernetes platforms. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6e1c0b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
sshFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kcli loads about 2.6k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 391 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
sudo usermod -aG qemu,libvirt $(id -un)├── id_rsa # SSH private key (auto-used)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from karmab/kcli at commit 6e1c0b5, republished under its Apache-2.0 licence (© karmab). 391 words, ~2,596 tokens.
.claude/skills/kcli/SKILL.md (or your agent's skills folder).kcli is a unified CLI for managing virtual infrastructure across multiple providers (Libvirt/KVM, AWS, GCP, Azure, vSphere, KubeVirt, OpenStack, oVirt, Proxmox, Hetzner, IBM Cloud).
When the user asks to run a kcli command against a specific host that is not defined as a client in ~/.kcli/config.yml, run the command directly on that host via SSH instead of trying to use -C:
# Host not in config — run via SSH
ssh root@myhost "kcli create vm -i centos9stream myvm"
ssh root@myhost "kcli list vm"
ssh root@myhost "kcli create plan -f plan.yml myplan"This is both faster (libvirt calls stay local on the host) and avoids needing to add a client entry.
# VM Operations
kcli create vm -i <image> <name> # Create VM
kcli list vm # List VMs
kcli ssh <name> # SSH into VM
kcli console <name> # Graphical console
kcli start/stop/restart vm <name> # Control VM state
kcli delete vm <name> # Delete VM
# Plans (Infrastructure as Code)
kcli create plan -f plan.yml <name> # Deploy plan
kcli list plan # List plans
kcli delete plan <name> # Delete plan and resources
# Kubernetes Clusters
kcli create kube <type> <name> # Deploy cluster
kcli list kube # List clusters
kcli delete kube <name> # Delete cluster
# Images
kcli list available-images # Show downloadable images
kcli download image <name> # Download cloud image
kcli list image # List local images
# Infrastructure
kcli list network / pool / host # List resources
kcli create network -c <cidr> <name> # Create network
kcli create pool -p <path> <name> # Create storage pool# From cloud image (downloads if needed)
kcli create vm -i fedora40 myvm
# Create multiple VMs at once
kcli create vm -c 3 myvm # Creates myvm-0, myvm-1, myvm-2
# Shorthand (kcli remembers last VM)
kcli ssh # SSH to last created VMkcli create vm -i centos9stream \
-P memory=4096 \
-P numcpus=4 \
-P disks=[20,50] \
myvm| Parameter | Default | Description |
|---|---|---|
numcpus | 2 | Number of CPUs |
memory | 512 | Memory in MB |
disks | [10] | Disk sizes in GB |
nets | [default] | Networks to attach |
pool | default | Storage pool |
cloudinit | true | Enable cloud-init |
start | true | Start VM after creation |
keys | [] | SSH public keys to inject |
cmds | [] | Commands to run at boot |
files | [] | Files to inject |
# With static IP
kcli create vm -i centos9stream \
-P nets=['{"name":"default","ip":"192.168.122.100"}'] \
myvm
# With post-boot commands
kcli create vm -i fedora40 \
-P cmds=['dnf -y install nginx','systemctl enable --now nginx'] \
webserver
# From profile
kcli create vm -p myprofile myvm
# Multiple disks with options
kcli create vm -i ubuntu2204 \
-P disks=['{"size":20}','{"size":100,"pool":"data"}'] \
myvm# List VMs
kcli list vm # Table format
kcli list vm -o yaml # YAML output
kcli list vm -o json # JSON output
# VM Information
kcli info vm myvm # Full details
kcli info vm myvm -f ip # Just IP address
# State Control
kcli start vm myvm
kcli stop vm myvm
kcli restart vm myvm
# Access
kcli ssh myvm # SSH as default user
kcli ssh -u root myvm # SSH as root
kcli console myvm # VNC/SPICE console
kcli console myvm --serial # Serial console
# Modify
kcli update vm myvm -P memory=8192 # Change memory
kcli update vm myvm -P numcpus=8 # Change CPUs
kcli create disk -s 50 myvm # Add 50GB disk
# Snapshots
kcli create snapshot myvm snap1
kcli list snapshot myvm
kcli revert snapshot myvm snap1
kcli delete snapshot myvm snap1
# Delete
kcli delete vm myvm # With confirmation
kcli delete vm myvm --yes # Skip confirmationPlans are YAML files with Jinja2 templating for deploying complete environments.
# myplan.yml
parameters:
base_image: centos9stream
domain: lab.local
# Network (created first)
labnet:
type: network
cidr: 192.168.100.0/24
dhcp: true
# VM (uses the network)
webserver:
image: {{ base_image }}
memory: 2048
numcpus: 2
nets:
- labnet
cmds:
- dnf -y install nginx
- systemctl enable --now nginx# Deploy
kcli create plan -f myplan.yml myplan
# Deploy with parameter overrides
kcli create plan -f myplan.yml -P base_image=fedora40 myplan
# List and manage
kcli list plan
kcli info plan myplan
kcli delete plan myplan # Deletes all resources
# Update existing plan
kcli update plan -f myplan.yml myplanparameters:
cluster_name: web
node_count: 3
{% for i in range(node_count) %}
{{ cluster_name }}-node-{{ i }}:
image: centos9stream
memory: 2048
nets:
- default
{% endfor %}| Type | Description |
|---|---|
| (none) | VM (default if no type specified) |
network | Virtual network |
pool | Storage pool |
image | Download image from URL |
profile | Reusable VM template |
container | Container workload |
kube | Kubernetes cluster |
generic / kubeadm - Standard Kubernetesopenshift / okd - OpenShiftk3s - Lightweight K3srke2 - Rancher RKE2microshift - Edge MicroShifthypershift - Hosted control planesaks / eks / gke - Cloud managed# Generic Kubernetes
kcli create kube generic -P ctlplanes=1 -P workers=2 myk8s
# K3s (lightweight)
kcli create kube k3s -P ctlplanes=1 -P workers=2 myk3s
# OpenShift (requires pull secret)
kcli create kube openshift \
-P pull_secret=~/pull-secret.json \
-P ctlplanes=3 \
-P workers=2 \
myocp# List clusters
kcli list kube
# Get kubeconfig
kcli get kubeconfig mycluster
export KUBECONFIG=~/.kcli/clusters/mycluster/kubeconfig
# Scale workers
kcli scale kube generic -P workers=5 mycluster
# Delete
kcli delete kube mycluster# List available cloud images
kcli list available-images
# Download image
kcli download image fedora40
kcli download image centos9stream
kcli download image ubuntu2204
# List downloaded images
kcli list image
# Delete image
kcli delete image fedora40Common images: fedora40, centos9stream, ubuntu2204, rhel9, debian12, rocky9, almalinux9
# Create network
kcli create network -c 192.168.100.0/24 mynet
kcli create network -c 10.0.0.0/24 --dhcp --nat privatenet
# List and delete
kcli list network
kcli info network mynet
kcli delete network mynet# Create pool
kcli create pool -p /var/lib/libvirt/images default
kcli create pool -p /home/vms myvms
# List and delete
kcli list pool
kcli delete pool myvms# List configured clients
kcli list client
# Switch default client
kcli switch mykvm
# Use specific client for command
kcli -C aws list vm
kcli -C gcp create vm -i ubuntu2204 myvm
# List VMs from all clients
kcli -C all list vm
# Host information
kcli info host
kcli list hostProfiles are reusable VM templates defined in ~/.kcli/profiles.yml:
# ~/.kcli/profiles.yml
small:
numcpus: 1
memory: 1024
disks:
- 10
webserver:
image: centos9stream
numcpus: 2
memory: 4096
cmds:
- dnf -y install nginx
- systemctl enable --now nginxUsage:
kcli create vm -p webserver myweb# Debug mode (verbose output)
kcli -d create vm -i fedora40 myvm
kcli -d list vm
# Check VM details
kcli info vm myvm
# Check cloud-init logs (after SSH)
kcli ssh myvm
cat /var/log/cloud-init.log
# Verify provider connectivity
kcli list host
kcli info hostNo IP address: Check DHCP on network, wait for cloud-init
kcli info network defaultSSH fails: Verify key injection worked
kcli ssh -l myvm # Show SSH commandPermission denied (libvirt): Add user to groups
sudo usermod -aG qemu,libvirt $(id -un)
newgrp libvirt~/.kcli/
├── config.yml # Client/provider configuration
├── profiles.yml # VM profiles
├── id_rsa # SSH private key (auto-used)
└── clusters/ # Cluster state filesdefault:
client: local
local:
type: kvm
host: 127.0.0.1
pool: defaultRun kcli without installation:
# With libvirt socket
alias kcli='podman run --rm -it \
-v ~/.kcli:/root/.kcli:z \
-v /var/run/libvirt:/var/run/libvirt:z \
quay.io/karmab/kcli'
# Then use normally
kcli list vmLast VM shortcut: Many commands work without VM name (uses last created)
kcli ssh # SSH to last VM
kcli console # Console of last VMOutput formats: Most list commands support -o yaml or -o json
Parameter files: Use kcli_parameters.yml alongside plans for defaults
Render plans: Preview templated plans before deploying
kcli render -f myplan.ymlExport VMs: Create images from running VMs
kcli export vm myvm© karmab, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/kcli of karmab/kcli.
Open the folder on GitHubat commit 6e1c0b5
Kcli next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kcli this skillkarmab/kcli | 653 | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | |
| Provider Bug Reviewmondoohq/mql | 411 | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Extend Discovery Typerunwhen-contrib/runwhen-local | 163 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Azure Arcvinayaklatthe/microsoft-security-skills | 175 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Provider API Call Dedupmondoohq/mql | 411 | — | ~7.7k | Automated safety check: Pass | Custom licence | |
| Cloud Devopsdavila7/claude-code-templates | 32k | 4 repos | ~1.4k | Automated safety check: Pass | MIT |
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
runwhen-contrib/runwhen-local
Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes).
vinayaklatthe/microsoft-security-skills
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
mondoohq/mql
A skill your agent uses when a provider scan is slow, times out, or trips rate limits (429, throttling, Retry-After), when the same request URL appears many times in a debug log, when an asset's…
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
ancoleman/ai-design-components
Apply and enforce cloud resource tagging strategies across AWS, Azure, GCP, and Kubernetes for cost allocation, ownership tracking, compliance, and automation.
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
karmab/kcli
Guides creation of kcli plan files for deploying VMs, networks, and infrastructure.
karmab/kcli
Guides implementation of new virtualization providers for kcli.
karmab/kcli
Guides kcli configuration and provider setup. An agent skill from karmab/kcli.
karmab/kcli
Guides interaction with kcli VMs via ksushy (Redfish emulator).
karmab/kcli
Guides testing and code quality for kcli. An agent skill from karmab/kcli.
Categories
Comprehensive guide for kcli usage. An agent skill from karmab/kcli. Kcli is an agent skill from karmab/kcli. Comprehensive guide for kcli usage.
Kcli fits situations like: deploying plans; managing clusters; performing any kcli operations.
Run `npx skills add karmab/kcli --skill kcli -a claude-code`. Or copy the skill folder (skills/kcli in karmab/kcli) into .claude/skills/kcli in your project. Claude Code loads it when a task matches its description.
Run `npx skills add karmab/kcli --skill kcli -a codex`. Or copy the skill folder (skills/kcli in karmab/kcli) into .agents/skills/kcli in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add karmab/kcli --skill kcli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kcli, .gemini/skills/kcli, .github/skills/kcli and .opencode/skills/kcli in your project.
Going by SKILL.md and its folder, Kcli needs the command-line tools its instructions call (ssh).
SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Kcli is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Kcli: Provider Bug Review (mondoohq/mql, 411 stars), Extend Discovery Type (runwhen-contrib/runwhen-local, 163 stars), Azure Arc (vinayaklatthe/microsoft-security-skills, 175 stars) and Provider API Call Dedup (mondoohq/mql, 411 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
karmab (a GitHub user) maintains it in karmab/kcli, which has 653 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 7, 2026.
Source: karmab/kcli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.