Provider Bug Review
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
Guides kcli configuration and provider setup. An agent skill from karmab/kcli.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add karmab/kcli --skill kcli-configuration -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install karmab/kcli kcli-configuration --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kcli-configuration .claude/skills/kcli-configuration && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kcli-configuration" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli-configuration into .claude/skills/kcli-configuration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli-configuration", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/karmab/kcli/tree/main/skills/kcli-configurationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add karmab/kcli --skill kcli-configuration -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install karmab/kcli kcli-configuration --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kcli-configuration .agents/skills/kcli-configuration && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kcli-configuration" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli-configuration into .agents/skills/kcli-configuration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli-configuration", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add karmab/kcli --skill kcli-configuration -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install karmab/kcli kcli-configuration --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kcli-configuration .cursor/skills/kcli-configuration && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kcli-configuration" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli-configuration into .cursor/skills/kcli-configuration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli-configuration", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/karmab/kcli.git --path skills/kcli-configuration--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add karmab/kcli --skill kcli-configuration -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install karmab/kcli kcli-configuration --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kcli-configuration .gemini/skills/kcli-configuration && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kcli-configuration" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli-configuration into .gemini/skills/kcli-configuration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli-configuration", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install karmab/kcli kcli-configurationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add karmab/kcli --skill kcli-configuration -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kcli-configuration .github/skills/kcli-configuration && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kcli-configuration" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli-configuration into .github/skills/kcli-configuration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli-configuration", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add karmab/kcli --skill kcli-configuration -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install karmab/kcli kcli-configuration --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kcli-configuration .opencode/skills/kcli-configuration && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kcli-configuration" agent skill from https://github.com/karmab/kcli/tree/main/skills/kcli-configuration into .opencode/skills/kcli-configuration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kcli-configuration", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kcli-configurationGuides kcli configuration and provider setup. An agent skill from karmab/kcli.
Kcli Configuration is an agent skill from karmab/kcli. Guides kcli configuration and provider setup. Use when setting up ~/.kcli/config.yml, configuring providers (KVM, AWS, GCP, Azure, etc.), or managing profiles.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud. It works with Amazon Web Services, Microsoft Azure, Google Cloud and Kubernetes. The repository describes itself as: Management tool for virtualization and kubernetes platforms. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 30a28e3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml and bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GOOGLE_APPLICATION_CREDENTIALSAWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kcli Configuration loads about 1.5k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 143 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
├── id_rsa / id_rsa.pub # SSH keys for VM access├── id_ed25519 # Alternative SSH keysudo systemctl status libvirtdssh-keygen -t rsa -N '' -f ~/.kcli/id_rsassh-keygen -t ed25519 -N '' -f ~/.kcli/id_ed25519Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from karmab/kcli at commit 30a28e3, republished under its Apache-2.0 licence (© karmab). 143 words, ~1,522 tokens.
.claude/skills/kcli-configuration/SKILL.md (or your agent's skills folder).~/.kcli/
├── config.yml # Main configuration (clients/providers)
├── profiles.yml # VM profiles (optional, can be in config.yml)
├── id_rsa / id_rsa.pub # SSH keys for VM access
├── id_ed25519 # Alternative SSH key
└── clusters/ # Cluster state (created by kcli)default:
client: localhost # Default provider to use
numcpus: 2
memory: 512
pool: default
nets:
- default
disks:
- size: 10
# Provider definitions
localhost:
type: kvm
host: 127.0.0.1| Type | Description | Required Fields |
|---|---|---|
kvm | Local/remote libvirt | host |
aws | Amazon Web Services | access_key_id, access_key_secret, region |
gcp | Google Cloud Platform | credentials, project, zone |
azure | Microsoft Azure | subscription_id, credentials (file) |
kubevirt | VMs on Kubernetes | context, host |
openstack | OpenStack cloud | auth_url, user, password, project |
ovirt | oVirt/RHV | host, user, password, datacenter |
vsphere | VMware vSphere | host, user, password, datacenter |
proxmox | Proxmox VE | host, user, password |
hcloud | Hetzner Cloud | token |
ibm | IBM Cloud | iam_api_key, region, vpc |
# Local libvirt
localhost:
type: kvm
host: 127.0.0.1
pool: default
# Remote libvirt via SSH
remote-kvm:
type: kvm
host: 192.168.1.100
protocol: ssh # ssh (default), tcp, or tls
user: root # SSH user
pool: default
# url: qemu+ssh://root@host/system # Or custom URImyaws:
type: aws
access_key_id: AKIAIOSFODNN7EXAMPLE
access_key_secret: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
region: us-east-1
keypair: mykey # EC2 key pair namemygcp:
type: gcp
credentials: ~/service-account.json # Service account JSON
project: my-project-id
zone: us-central1-a
region: us-central1 # Optional, derived from zonemyazure:
type: azure
subscription_id: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
credentials: ~/.azure/credentials.json
# Or use environment: AZURE_AUTH_LOCATION
location: eastus
resource_group: my-rg # Optional, created if neededmykubevirt:
type: kubevirt
context: my-k8s-context # kubectl context
host: api.cluster.local # API server for SSH tunneling
pool: my-storageclass # StorageClass name
multus: true # Use Multus CNI
cdi: true # Use CDI for imagesmyopenstack:
type: openstack
auth_url: https://openstack:5000/v3
user: admin
password: secret
project: myproject
domain: Defaultmyovirt:
type: ovirt
host: ovirt-engine.local
user: admin@internal
password: secret
datacenter: Default
cluster: Default
pool: DataDomain
ca_file: ~/ovirt.pem # Engine CA certificatedefault:
# Client selection
client: localhost
# Compute
numcpus: 2
memory: 512 # MB
cpumodel: host-model
nested: true # Nested virtualization
# Storage
pool: default
disks:
- size: 10
diskinterface: virtio
diskthin: true
# Network
nets:
- default
reservedns: false
reservehost: false
reserveip: false
# OS/Cloud-init
cloudinit: true
keys: [] # SSH public keys
cmds: [] # Post-boot commands
files: [] # Files to inject
# Access
tunnel: false # SSH tunneling for console
insecure: false # Ignore SSH host keys
enableroot: true # Allow root SSH
# Metadata
storemetadata: false
planview: false# In ~/.kcli/profiles.yml or config.yml profiles section
small:
numcpus: 1
memory: 1024
disks:
- size: 10
medium:
numcpus: 2
memory: 2048
disks:
- size: 20
large:
numcpus: 4
memory: 4096
disks:
- size: 40
- size: 100
webserver:
image: centos9stream
numcpus: 2
memory: 4096
nets:
- default
cmds:
- dnf -y install nginx
- systemctl enable --now nginx
base: medium # Inherit from another profiledefault:
client: local-kvm # Default client
local-kvm:
type: kvm
host: 127.0.0.1
remote-kvm:
type: kvm
host: 192.168.1.100
myaws:
type: aws
access_key_id: ...
access_key_secret: ...
region: us-east-1Switch clients:
kcli switch local-kvm # Change default
kcli -C myaws list vm # Use specific client# List configured clients
kcli list client
# Check client connectivity
kcli list host
# Info about current client
kcli info host
# Switch default client
kcli switch <client>
# Test with specific client
kcli -C <client> list vmSome values can come from environment:
GOOGLE_APPLICATION_CREDENTIALS - GCP credentials pathAWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY - AWS credentialsAZURE_AUTH_LOCATION - Azure credentials pathOS_* - OpenStack credentials (standard OS_ vars)Connection refused (KVM):
# Check libvirt is running
sudo systemctl status libvirtd
# Test virsh connection
virsh -c qemu:///system listSSH key issues:
# Generate kcli SSH key
ssh-keygen -t rsa -N '' -f ~/.kcli/id_rsa
# Or use ed25519
ssh-keygen -t ed25519 -N '' -f ~/.kcli/id_ed25519Debug mode:
kcli -d list vm # Shows provider connection details© karmab, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/kcli-configuration of karmab/kcli.
Open the folder on GitHubat commit 30a28e3
Kcli Configuration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kcli Configuration this skillkarmab/kcli | 653 | — | ~1.5k | Automated safety check: Warn | Apache-2.0 | |
| Provider Bug Reviewmondoohq/mql | 411 | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Extend Discovery Typerunwhen-contrib/runwhen-local | 163 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Multi Cloud ArchitectureHermeticOrmus/LibreUIUX-Claude-Code | 111 | 10 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Staged Discoverymondoohq/mql | 411 | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Azure Arcvinayaklatthe/microsoft-security-skills | 175 | — | ~1.9k | Automated safety check: Pass | MIT |
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
runwhen-contrib/runwhen-local
Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes).
HermeticOrmus/LibreUIUX-Claude-Code
Design multi-cloud architectures using a decision framework to select and integrate services across AWS, Azure, and GCP.
mondoohq/mql
Add staged discovery support to a provider. An agent skill from mondoohq/mql.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
mondoohq/mql
A skill your agent uses when a provider scan is slow, times out, or trips rate limits (429, throttling, Retry-After), when the same request URL appears many times in a debug log, when an asset's…
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
karmab/kcli
Comprehensive guide for kcli usage. An agent skill from karmab/kcli.
karmab/kcli
Guides creation of kcli plan files for deploying VMs, networks, and infrastructure.
karmab/kcli
Guides implementation of new virtualization providers for kcli.
karmab/kcli
Guides interaction with kcli VMs via ksushy (Redfish emulator).
karmab/kcli
Guides testing and code quality for kcli. An agent skill from karmab/kcli.
Categories
Guides kcli configuration and provider setup. An agent skill from karmab/kcli. Kcli Configuration is an agent skill from karmab/kcli. Guides kcli configuration and provider setup.
Kcli Configuration fits situations like: setting up ~/.kcli/config.yml; configuring providers (KVM; managing profiles.
Run `npx skills add karmab/kcli --skill kcli-configuration -a claude-code`. Or copy the skill folder (skills/kcli-configuration in karmab/kcli) into .claude/skills/kcli-configuration in your project. Claude Code loads it when a task matches its description.
Run `npx skills add karmab/kcli --skill kcli-configuration -a codex`. Or copy the skill folder (skills/kcli-configuration in karmab/kcli) into .agents/skills/kcli-configuration in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add karmab/kcli --skill kcli-configuration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kcli-configuration, .gemini/skills/kcli-configuration, .github/skills/kcli-configuration and .opencode/skills/kcli-configuration in your project.
Going by SKILL.md and its folder, Kcli Configuration needs credentials named GOOGLE_APPLICATION_CREDENTIALS, AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY. Our summary lists: A credential in AWS_SECRET_ACCESS_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 4 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Kcli Configuration is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Kcli Configuration: Provider Bug Review (mondoohq/mql, 411 stars), Extend Discovery Type (runwhen-contrib/runwhen-local, 163 stars), Multi Cloud Architecture (HermeticOrmus/LibreUIUX-Claude-Code, 111 stars) and Staged Discovery (mondoohq/mql, 411 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
karmab (a GitHub user) maintains it in karmab/kcli, which has 653 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.
Source: karmab/kcli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.