Senior DevOps Toolkit
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website).
$ npx skills add macalbert/envilder --skill common-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install macalbert/envilder common-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/common-security .claude/skills/common-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "common-security" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-security into .claude/skills/common-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/macalbert/envilder/tree/main/.github/skills/common-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add macalbert/envilder --skill common-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install macalbert/envilder common-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/common-security .agents/skills/common-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "common-security" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-security into .agents/skills/common-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add macalbert/envilder --skill common-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install macalbert/envilder common-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/common-security .cursor/skills/common-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "common-security" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-security into .cursor/skills/common-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/macalbert/envilder.git --path .github/skills/common-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add macalbert/envilder --skill common-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install macalbert/envilder common-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/common-security .gemini/skills/common-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "common-security" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-security into .gemini/skills/common-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install macalbert/envilder common-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add macalbert/envilder --skill common-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/common-security .github/skills/common-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "common-security" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-security into .github/skills/common-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add macalbert/envilder --skill common-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install macalbert/envilder common-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/common-security .opencode/skills/common-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "common-security" agent skill from https://github.com/macalbert/envilder/tree/main/.github/skills/common-security into .opencode/skills/common-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "common-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
common-securitySecurity guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website).
Common Security is an agent skill from macalbert/envilder. Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website). Covers secret handling, credential hygiene, supply chain safety, input validation, and CI/CD security. Use when reviewing code for security, handling secrets, validating CLI input, or reviewing GitHub Actions workflows.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering CI/CD and Supply chain security. It works with GitHub Actions, Amazon Web Services and Azure Key Vault. The repository describes itself as: One secret mapping for local dev, CI/CD, and runtime. Envilder resolves cloud secrets from your own vaults without SaaS middlemen, duplicated config, or .env drift. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b6a0327. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
AWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYLOCALSTACK_AUTH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Common Security loads about 1.6k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 729 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
rofile → SSM (via `envilder.json`) | In `.env` files committed to Git |Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from macalbert/envilder at commit b6a0327, republished under its MIT licence (© macalbert). 729 words, ~1,595 tokens.
.claude/skills/common-security/SKILL.md (or your agent's skills folder).Security guardrails adapted to the Envilder project: a CLI + GitHub Action + multi-runtime SDK platform that manages secrets from AWS SSM and Azure Key Vault.
EnvironmentVariable.maskedValue (shows last 3 chars) for loggingenvilder.json to resolve test tokens; never hardcode tokens| Context | Where secrets live | Never |
|---|---|---|
| Production | AWS SSM Parameter Store (encrypted) | In code, env vars, or config files |
| Production (Azure) | Azure Key Vault | In code or checked-in files |
| CI | GitHub Secrets → OIDC → SSM | As plaintext in workflow YAML |
| Local dev | AWS profile → SSM (via envilder.json) | In .env files committed to Git |
| Tests | TestContainers (LocalStack/Lowkey Vault) | Real credentials in test code |
Secretlint runs on every pnpm lint invocation and scans all files for
credential patterns (AWS keys, tokens, private keys). If Secretlint fails,
the commit is blocked.
aws-actions/configure-aws-credentials with role-to-assumeAWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY as GitHub Secretsprocess.env.INPUT_*: validate before usemap input (file path) must be validated to prevent path traversalpermissions: block in every workflowcontents: read for checkout, id-token: write for OIDCpermissions: write-all--map path must exist and be a .json file--provider must be one of aws | azure (case-insensitive)--vault-url must be a valid HTTPS URL matching *.vault.azure.netInvalidArgumentError): not generic exceptionsInvalidArgumentError| Stack | Mechanism | File |
|---|---|---|
| TypeScript | pnpm-lock.yaml + catalog: versions | pnpm-workspace.yaml |
| .NET | Central Package Management | Directory.Packages.props |
| Python | uv.lock (deterministic) | uv.lock |
.gitignore thempnpm verify:gha)@v4 tags) in production workflowsaws-cdk-lib up to date: security patches affect deployed infracdk.out/) is .gitignored: never commit CloudFormation templatesWithDecryption: true for SecureString parametersprofile is specified, only use CredentialProfileStoreChain: don't mixDefaultAzureCredential: never hardcode clientId/clientSecrethttps://*.vault.azure.netEnvilderOptions overrides $config: validate that overrides don't
introduce insecure combinations (e.g., disabling encryption)null/None (silent). Validation is opt-in via
validateSecrets(): document this to users clearlyrel="noopener noreferrer" on target="_blank" linksdangerouslySetInnerHTML equivalentsLOCALSTACK_AUTH_TOKEN resolved via Envilder itself (dogfooding): stored
in SSM, never in codeBefore merging any PR, verify:
pnpm lint)maskedValue (last 3 chars visible)permissions:shell=True or unsanitized argument interpolation in scripts© macalbert, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/common-security of macalbert/envilder.
Open the folder on GitHubat commit b6a0327
Common Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Common Security this skillmacalbert/envilder | 138 | — | ~1.6k | Automated safety check: Notes | MIT | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 259 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| GitHub Actions Supply Chain Pinningasyncapi/generator | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Vibe CI Supply Chainmistralai/mistral-vibe | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | |
| Managing Workflow Secretsbitwarden/ai-plugins | 154 | — | ~4k | Automated safety check: Pass | Custom licence | |
| CI/CD Pipeline Principlesirahardianto/awesome-agv | 157 | — | ~2.7k | Automated safety check: Notes | MIT |
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
asyncapi/generator
A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).
mistralai/mistral-vibe
Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.
bitwarden/ai-plugins
Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
sickn33/agentic-awesome-skills
DevOps e deploy de aplicacoes — Docker, CI/CD com GitHub Actions, AWS Lambda, SAM, Terraform, infraestrutura como codigo e monitoramento.
macalbert/envilder
Five independent analysis perspectives for code review: correctness, architecture, security, conventions, and complexity.
macalbert/envilder
Index of Architecture Decision Records (ADRs) for cross-cutting technical decisions.
macalbert/envilder
Git commit messages, PR workflow, and branching strategy using Conventional Commits and Semantic Versioning.
macalbert/envilder
Mandatory testing conventions including the narrow diagnostic exception for testing test-only code, AAA pattern, test naming, and assertions across all stacks (.NET, TypeScript, Python).
macalbert/envilder
Workflow for maintaining changelogs, READMEs, and documentation files.
macalbert/envilder
Audit and synchronize documentation across website, READMEs, and docs/.
Categories
Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website). Common Security is an agent skill from macalbert/envilder. Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website).
Common Security fits situations like: reviewing code for security; handling secrets; validating CLI input; reviewing GitHub Actions workflows.
Run `npx skills add macalbert/envilder --skill common-security -a claude-code`. Or copy the skill folder (.github/skills/common-security in macalbert/envilder) into .claude/skills/common-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add macalbert/envilder --skill common-security -a codex`. Or copy the skill folder (.github/skills/common-security in macalbert/envilder) into .agents/skills/common-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add macalbert/envilder --skill common-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/common-security, .gemini/skills/common-security, .github/skills/common-security and .opencode/skills/common-security in your project.
Going by SKILL.md and its folder, Common Security needs the command-line tools its instructions call (pnpm) and credentials named AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and LOCALSTACK_AUTH_TOKEN. Our summary lists: Python 3; A credential in AWS_SECRET_ACCESS_KEY; A credential in LOCALSTACK_AUTH_TOKEN.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Common Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Common Security: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars), GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), Vibe CI Supply Chain (mistralai/mistral-vibe, 5.1k stars) and Managing Workflow Secrets (bitwarden/ai-plugins, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
macalbert (a GitHub user) maintains it in macalbert/envilder, which has 138 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 5, 2026.
Source: macalbert/envilder on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.