Platform Engineering
magnus919/agent-skills
A skill your agent uses when building or operating internal developer platforms: infrastructure as code, CI/CD, container orchestration, service networking, secrets, and observability, or when…
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
$ npx skills add kubeshark/kubeshark --skill kfl -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kubeshark/kubeshark kfl --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kubeshark/kubeshark.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kfl .claude/skills/kfl && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kfl" agent skill from https://github.com/kubeshark/kubeshark/tree/master/skills/kfl into .claude/skills/kfl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kfl", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kubeshark/kubeshark/tree/master/skills/kflType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kubeshark/kubeshark --skill kfl -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kubeshark/kubeshark kfl --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubeshark/kubeshark.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kfl .agents/skills/kfl && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kfl" agent skill from https://github.com/kubeshark/kubeshark/tree/master/skills/kfl into .agents/skills/kfl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kfl", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kubeshark/kubeshark --skill kfl -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kubeshark/kubeshark kfl --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubeshark/kubeshark.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kfl .cursor/skills/kfl && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kfl" agent skill from https://github.com/kubeshark/kubeshark/tree/master/skills/kfl into .cursor/skills/kfl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kfl", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kubeshark/kubeshark.git --path skills/kfl--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kubeshark/kubeshark --skill kfl -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kubeshark/kubeshark kfl --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubeshark/kubeshark.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kfl .gemini/skills/kfl && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kfl" agent skill from https://github.com/kubeshark/kubeshark/tree/master/skills/kfl into .gemini/skills/kfl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kfl", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kubeshark/kubeshark kflInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kubeshark/kubeshark --skill kfl -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kubeshark/kubeshark.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kfl .github/skills/kfl && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kfl" agent skill from https://github.com/kubeshark/kubeshark/tree/master/skills/kfl into .github/skills/kfl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kfl", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kubeshark/kubeshark --skill kfl -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kubeshark/kubeshark kfl --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubeshark/kubeshark.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kfl .opencode/skills/kfl && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kfl" agent skill from https://github.com/kubeshark/kubeshark/tree/master/skills/kfl into .opencode/skills/kfl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kfl", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kflSyntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
KFL2 is built on Google's Common Expression Language and works as a display filter: it changes what you see, not what Kubeshark captures. The skill makes the agent write filters from the reference instead of guessing, since the language is statically typed and a wrong field name or syntax error fails silently or raises an error. An empty filter matches everything.
The core section lists comparison, logical, arithmetic, membership and ternary operators, string functions such as contains, startsWith and endsWith, collection functions like size and key lookup, and time functions for timestamps, durations and now. It also shows negation patterns, for example excluding health-check paths from HTTP results. A table of protocol flags (http, dns, tls, tcp, udp, grpc, redis, kafka, mongodb, postgresql and more) is meant to be the first term of a filter. The full field reference sits in `references/kfl2-reference.md`; the excerpt is cut off after the protocol table.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2d8a22d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
mysqlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kubeshark KFL2 Filter Reference loads about 3.6k tokens when it runs, and up to ~9k if it reads all its reference files. Until then it costs about 234 tokens; SKILL.md has 632 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kubeshark/kubeshark at commit 2d8a22d, republished under its Apache-2.0 licence (© kubeshark). 632 words, ~3,588 tokens.
.claude/skills/kfl/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.You are a KFL2 expert. KFL2 is built on Google's CEL (Common Expression Language) and is the query language for all Kubeshark traffic analysis. It operates as a display filter — it doesn't affect what's captured, only what you see.
Think of KFL the way you think of SQL for databases or Google search syntax for the web. Kubeshark captures and indexes all cluster traffic; KFL is how you search it.
For the complete variable and field reference, see references/kfl2-reference.md.
KFL expressions are boolean CEL expressions. An empty filter matches everything.
| Category | Operators |
|---|---|
| Comparison | ==, !=, <, <=, >, >= |
| Logical | &&, ||, ! |
| Arithmetic | +, -, *, /, % |
| Membership | in |
| Ternary | condition ? true_val : false_val |
str.contains(substring) // Substring search
str.startsWith(prefix) // Prefix match
str.endsWith(suffix) // Suffix match
str.matches(regex) // Regex match
size(str) // String lengthsize(collection) // List/map/string length
key in map // Key existence
map[key] // Value access
map_get(map, key, default) // Safe access with default
value in list // List membershiptimestamp("2026-03-14T22:00:00Z") // Parse ISO timestamp
duration("5m") // Parse duration
now() // Current time (snapshot at filter creation)!http // Everything that is NOT HTTP
http && status_code != 200 // HTTP responses that aren't 200
http && !path.contains("/health") // Exclude health checks
!(src.pod.namespace == "kube-system") // Exclude system namespaceBoolean flags that indicate which protocol was detected. Use these as the first filter term — they're fast and narrow the search space immediately.
| Flag | Protocol | Flag | Protocol |
|---|---|---|---|
http | HTTP/1.1, HTTP/2 | redis | Redis |
dns | DNS | kafka | Kafka |
tls | eBPF TLS interception | amqp | AMQP |
tcp | TCP | ldap | LDAP |
udp | UDP | ws | WebSocket |
sctp | SCTP | gql | GraphQL (v1+v2) |
icmp | ICMP | gqlv1 / gqlv2 | GraphQL version-specific |
grpc | gRPC (HTTP/2 sub-protocol) | mongodb | MongoDB |
mysql | MySQL | postgresql | PostgreSQL |
radius | RADIUS | ||
diameter | Diameter | conn / flow | L4 connection/flow tracking |
tcp_conn / udp_conn | Transport-specific connections |
The most common starting point. Filter by where traffic originates or terminates.
src.pod.name == "orders-594487879c-7ddxf"
dst.pod.namespace == "production"
src.service.name == "api-gateway"
dst.service.namespace == "payments"Pod fields fall back to service data when pod info is unavailable, so
dst.pod.namespace works even for service-level entries.
Convenience variables that pick the best available identity for a peer:
src.name == "api-gateway" // pod > service > dns > process
dst.name.contains("payment") // works across identity types
src.namespace == "production" // pod namespace, falls back to service
dst.namespace != "kube-system" // exclude system namespaceMatch against any direction (src or dst):
"production" in namespaces // Any namespace match
"orders" in pods // Any pod name match
"api-gateway" in services // Any service name matchmap_get(local_labels, "app", "") == "checkout" // Safe access with default
map_get(remote_labels, "version", "") == "canary"
"tier" in local_labels // Label existence checkAlways use map_get() for labels and annotations — direct access like
local_labels["app"] errors if the key doesn't exist.
node_name == "ip-10-0-25-170.ec2.internal"
local_process_name == "nginx"
remote_process_name.contains("postgres")src.dns == "api.example.com"
dst.dns.contains("redis")HTTP is the most common protocol for API-level investigation.
| Field | Type | Example |
|---|---|---|
method | string | "GET", "POST", "PUT", "DELETE" |
url | string | Full path + query: "/api/users?id=123" |
path | string | Path only: "/api/users" |
status_code | int | 200, 404, 500 |
http_version | string | "HTTP/1.1", "HTTP/2" |
request.headers | map | request.headers["content-type"] |
response.headers | map | response.headers["server"] |
request.cookies | map | request.cookies["session"] |
response.cookies | map | response.cookies["token"] |
query_string | map | query_string["id"] |
request_body_size | int | Request body bytes |
response_body_size | int | Response body bytes |
elapsed_time | int | Duration in microseconds |
// Error investigation
http && status_code >= 500 // Server errors
http && status_code == 429 // Rate limiting
http && status_code >= 400 && status_code < 500 // Client errors
// Endpoint targeting
http && method == "POST" && path.contains("/orders")
http && url.matches(".*/api/v[0-9]+/users.*")
// Performance
http && elapsed_time > 5000000 // > 5 seconds
http && response_body_size > 1000000 // > 1MB responses
// Header inspection
http && "authorization" in request.headers
http && request.headers["content-type"] == "application/json"
// GraphQL (subset of HTTP)
gql && method == "POST" && status_code >= 400
// Only eBPF-intercepted TLS traffic (decrypted HTTPS)
tls && http && status_code >= 500Note on
tls: Thetlsflag is an alias forcapture_source == "ebpf_tls". It indicates traffic captured via eBPF TLS interception, not TLS protocol dissection.
DNS issues are often the hidden root cause of outages.
| Field | Type | Description |
|---|---|---|
dns_questions | []string | Question domain names |
dns_answers | []string | Answer domain names |
dns_question_types | []string | Record types: A, AAAA, CNAME, MX, TXT, SRV, PTR |
dns_request | bool | Is request |
dns_response | bool | Is response |
dns_request_length | int | Request size |
dns_response_length | int | Response size |
dns && "api.external-service.com" in dns_questions
dns && dns_response && status_code != 0 // Failed lookups
dns && "A" in dns_question_types // A record queries
dns && size(dns_questions) > 1 // Multi-questionredis && redis_type == "GET" // Command type
redis && redis_key.startsWith("session:") // Key pattern
redis && redis_command.contains("DEL") // Command search
redis && redis_total_size > 10000 // Large operationskafka && kafka_api_key_name == "PRODUCE" // Produce operations
kafka && kafka_client_id == "payment-processor" // Client filtering
kafka && kafka_request_summary.contains("orders") // Topic filtering
kafka && kafka_size > 10000 // Large messagesmongodb && mongodb_command == "find" // Find operations
mongodb && mongodb_collection == "users" // Collection filtering
mongodb && mongodb_database == "mydb" // Database filtering
mongodb && !mongodb_success // Failed operations
mongodb && mongodb_error_code != 0 // Error code filtering
mongodb && mongodb_total_size > 10000 // Large operationsmysql && mysql_command == "COM_QUERY" // SQL queries
mysql && mysql_query.contains("SELECT") // SELECT statements
mysql && mysql_database == "orders_db" // Database filtering
mysql && !mysql_success // Failed queries
mysql && mysql_error_code != 0 // Error code filtering
mysql && mysql_total_size > 10000 // Large queriespostgresql && postgresql_command == "COM_QUERY" // Query commands
postgresql && postgresql_query.contains("SELECT") // SELECT statements
postgresql && postgresql_database == "orders_db" // Database filtering
postgresql && postgresql_user == "admin" // User filtering
postgresql && !postgresql_success // Failed queries
postgresql && postgresql_error_code != "" // Error code filtering (SQLSTATE string)
postgresql && postgresql_total_size > 10000 // Large queriesNote:
postgresql_error_codeis a string (SQLSTATE code like"23505"), not an int. This differs from MySQL'smysql_error_codewhich is an int.
gRPC is a sub-protocol of HTTP/2. All HTTP variables are also available on gRPC entries.
grpc && grpc_method == "SayHello" // Method filtering
grpc && grpc_status != 0 // Non-OK status codes
grpc && grpc_status == 14 // UNAVAILABLE
grpc && grpc_method.contains("Create") // Method pattern
grpc && elapsed_time > 1000000 // Slow gRPC calls (>1s)amqp && amqp_method == "basic.publish" // AMQP publish
ldap && ldap_type == "bind" // LDAP bind requests
radius && radius_code_name == "Access-Request" // RADIUS auth
diameter && diameter_method.contains("Credit") // Diameter credit controlFor the full variable list for these protocols, see references/kfl2-reference.md.
tcp && tcp_error_type != "" // TCP errors
udp && udp_length > 1000 // Large UDP packetsconn && conn_state == "open" // Active connections
conn && conn_local_bytes > 1000000 // High-volume
conn && "HTTP" in conn_l7_detected // L7 protocol detection
tcp_conn && conn_state == "closed" // Closed TCP connectionsflow && flow_local_pps > 1000 // High packet rate
flow && flow_local_bps > 1000000 // High bandwidth
flow && flow_state == "closed" && "TLS" in flow_l7_detected
tcp_flow && flow_local_bps > 5000000 // High-throughput TCPsrc.ip == "10.0.53.101"
dst.ip.startsWith("192.168.")
src.port == 8080
dst.port >= 8000 && dst.port <= 9000timestamp > timestamp("2026-03-14T22:00:00Z")
timestamp >= timestamp("2026-03-14T22:00:00Z") && timestamp <= timestamp("2026-03-14T23:00:00Z")
timestamp > now() - duration("5m") // Last 5 minutes
elapsed_time > 2000000 // Latency > 2 secondsThe most effective investigation technique — start broad, add constraints:
// Step 1: Protocol + namespace
http && dst.pod.namespace == "production"
// Step 2: Add error condition
http && dst.pod.namespace == "production" && status_code >= 500
// Step 3: Narrow to service
http && dst.pod.namespace == "production" && status_code >= 500 && dst.service.name == "payment-service"
// Step 4: Narrow to endpoint
http && dst.pod.namespace == "production" && status_code >= 500 && dst.service.name == "payment-service" && path.contains("/charge")
// Step 5: Add timing
http && dst.pod.namespace == "production" && status_code >= 500 && dst.service.name == "payment-service" && path.contains("/charge") && elapsed_time > 2000000http && ... is faster than ... && httpstartsWith/endsWith over contains — prefix/suffix checks are fasterdst.port == 80 is cheaper than url.contains(...)map_get for labels — avoids errors on missing keys&&, so put cheap checks firstKFL2 is statically typed. Common gotchas:
status_code is int, not string — use status_code == 200, not "200"elapsed_time is in microseconds — 5 seconds = 5000000timestamp requires timestamp() function — not a raw stringkey in map or map_get() firstvalue in list — not list.contains(value)© kubeshark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/kfl of kubeshark/kubeshark.
Open the folder on GitHubat commit 2d8a22d
Kubeshark KFL2 Filter Reference next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kubeshark KFL2 Filter Reference this skillkubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Platform Engineeringmagnus919/agent-skills | 111 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Intrinsic Core Debuggingintrinsic-ai/intrinsic-core | 552 | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | |
| Kratos Developmentaide-family/moon | 253 | — | ~1.5k | Automated safety check: Pass | None | |
| Nginx To Higress Migrationhigress-group/higress | 9.5k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress | 5.1k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
magnus919/agent-skills
A skill your agent uses when building or operating internal developer platforms: infrastructure as code, CI/CD, container orchestration, service networking, secrets, and observability, or when…
intrinsic-ai/intrinsic-core
Meta-level debugging workflows, architectural layer isolation, and progressive disclosure routing across Envoy ingress, Kubernetes pods, Behavior Trees, ObjectWorld synchronization, ICON real-time…
aide-family/moon
Develops Go microservices with Kratos v2 following official design philosophy, DDD/Clean Architecture layout, Protobuf API, error/config/middleware patterns, and observability.
higress-group/higress
Migrate from ingress-nginx to Higress in Kubernetes environments.
nginx/kubernetes-ingress
Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.
nginx/kubernetes-ingress
Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
kubeshark/kubeshark
Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
Works with
Categories
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written. KFL2 is built on Google's Common Expression Language and works as a display filter: it changes what you see, not what Kubeshark captures. The skill makes the agent write filters from the reference instead of guessing, since the language is statically typed and a wrong field name or syntax error fails silently or raises an error.
Kubeshark KFL2 Filter Reference fits situations like: writing a filter to show only failing HTTP responses in a namespace; narrowing captured traffic by pod, service, label or annotation; searching for DNS lookups, Redis commands or Kafka topics in cluster traffic; building time-bounded traffic queries during an incident.
Run `npx skills add kubeshark/kubeshark --skill kfl -a claude-code`. Or copy the skill folder (skills/kfl in kubeshark/kubeshark) into .claude/skills/kfl in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kubeshark/kubeshark --skill kfl -a codex`. Or copy the skill folder (skills/kfl in kubeshark/kubeshark) into .agents/skills/kfl in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubeshark/kubeshark --skill kfl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kfl, .gemini/skills/kfl, .github/skills/kfl and .opencode/skills/kfl in your project.
Going by SKILL.md and its folder, Kubeshark KFL2 Filter Reference needs the command-line tools its instructions call (mysql). Our summary lists: A Kubeshark deployment capturing cluster traffic.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Kubeshark KFL2 Filter Reference is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Kubeshark KFL2 Filter Reference: Platform Engineering (magnus919/agent-skills, 111 stars), Intrinsic Core Debugging (intrinsic-ai/intrinsic-core, 552 stars), Kratos Development (aide-family/moon, 253 stars) and Nginx To Higress Migration (higress-group/higress, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kubeshark (a GitHub organization) maintains it in kubeshark/kubeshark, which has 12,094 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 30, 2026.
Source: kubeshark/kubeshark on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.