Cloudflare
hodgef/apiker
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…
Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant.
$ npx skills add marin-community/marin --skill review-grant -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install marin-community/marin review-grant --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-grant .claude/skills/review-grant && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/review-grant into .claude/skills/review-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-grant", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/marin-community/marin/tree/main/.agents/skills/review-grantType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add marin-community/marin --skill review-grant -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install marin-community/marin review-grant --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/review-grant .agents/skills/review-grant && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/review-grant into .agents/skills/review-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-grant", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marin-community/marin --skill review-grant -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install marin-community/marin review-grant --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/review-grant .cursor/skills/review-grant && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/review-grant into .cursor/skills/review-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-grant", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/marin-community/marin.git --path .agents/skills/review-grant--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add marin-community/marin --skill review-grant -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install marin-community/marin review-grant --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/review-grant .gemini/skills/review-grant && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/review-grant into .gemini/skills/review-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-grant", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install marin-community/marin review-grantInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add marin-community/marin --skill review-grant -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/review-grant .github/skills/review-grant && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/review-grant into .github/skills/review-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-grant", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marin-community/marin --skill review-grant -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install marin-community/marin review-grant --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/review-grant .opencode/skills/review-grant && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/review-grant into .opencode/skills/review-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-grant", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
review-grantReview an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant.
Review Grant is an agent skill from marin-community/marin. Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Infrastructure as code. It works with Pulumi. The repository describes itself as: Open-source framework for the research and development of foundation models. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c468793. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pulumighgituvpythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, git and uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review Grant loads about 1.1k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 447 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from marin-community/marin at commit c468793, republished under its Apache-2.0 licence (© marin-community). 447 words, ~1,050 tokens.
.claude/skills/review-grant/SKILL.md (or your agent's skills folder).A grant PR (usually from the add-grant skill) uses opaque human-NNN
references whose emails are KMS ciphertext in iam_data.yaml. This skill
reveals the real grant, gets an explicit human confirmation, then lands it and
applies it.
Read first:
infra/pulumi/README.md — the marin-iac stacks and the pulumi up
prerequisites (you need roles/cloudkms.cryptoKeyEncrypterDecrypter on the key
and permission to update the marin stack).Never approve or merge before the user confirms the decrypted grant. The whole point is that a second person sees the actual identity and access before it is applied.
gh pr view <n> --repo marin-community/marin --json title,body,headRefName,files,url
gh pr checkout <n> # pull the branch into the worktree
git fetch origin mainConfirm the diff only touches grant surfaces under infra/pulumi/src/iac/gcp/:
iam_data.yaml and/or a deploy-target IAM module. If it
changes anything else (code, other Pulumi resources), stop and review it as an
ordinary PR, not a grant.
Turn the changed opaque principal references into real emails:
git diff origin/main...HEAD -- infra/pulumi/src/iac/gcp \
| uv run --package marin-iac --extra deploy \
python infra/pulumi/iam_principal.py decrypt --diffEach output line is + user:<email> (added) or - user:<email> (removed). Map
each back to the role and resource it sits under in the diff. The decryptor
shows the principal; read the surrounding role and container
(project_grants, a specific bucket/secret/repository/service account, or a
deploy-target module) from the diff hunk.
Print a plain-language summary, one line per grant, and ask the user to confirm. For example:
PR #1234 grants:
+ alice@openathena.ai → roles/storage.objectViewer on project hai-gcp-models
+ alice@openathena.ai → IAP viewer on evaldash.oa.dev
- bob@openathena.ai → roles/bigquery.dataViewer (revoked)
Apply this? (yes/no)Call out anything that looks off: a broader role than the resource needs, a principal you do not recognize, a domain wildcard, or a revocation that might cut off active access. If the user does not clearly approve, stop and report back — do not merge.
After the user confirms:
gh pr review <n> --repo marin-community/marin --approve
gh pr merge <n> --repo marin-community/marin --squash
git checkout main && git pull origin main # land the merged change locallyWait for the merge to land on main and pull it before applying, so pulumi up
runs against the committed state.
The change is not live until pulumi up runs — CI never applies. Identify the
affected stack(s) from the diff:
infra/pulumi/src/iac/gcp/ → the marin stack in
infra/pulumi.Prompt the user: they can run it themselves, or ask you to. If you run it, per stack:
cd infra/<dir>
pulumi stack select <stack>
pulumi preview # confirm ONLY the intended grant is added/removed, no other drift
pulumi upRead the preview before applying. For the marin stack, expect only the
IAMMember create/delete for this grant — any NodePool or other unexpected
replace/delete means stop and reconcile, exactly as the pulumi README
warns. Once up is clean, tell the user the grant is live.
Comment on the merged PR that pulumi up ran and the grant is live, so the
requester and any watcher see the change reached production, not just main:
gh pr comment <n> --repo marin-community/marin \
--body "🤖 \`pulumi up\` on the \`<stack>\` stack succeeded — the grant is live."An agent comment must begin with 🤖 (see AGENTS.md). If pulumi up did not run
(the user is applying it themselves), skip this and let them confirm instead.
© marin-community, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/review-grant of marin-community/marin.
Open the folder on GitHubat commit c468793
Review Grant next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review Grant this skillmarin-community/marin | 3.9k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Cloudflarehodgef/apiker | 127 | 7 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Cloudflaredmmulroy/cloudflare-skill | 727 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Spacectlspacelift-io/spacectl | 173 | — | ~2.3k | Automated safety check: Pass | MIT | |
| AWS Native Runtime Investigationpulumi/pulumi-aws-native | 108 | — | ~753 | Automated safety check: Pass | Apache-2.0 | |
| Devops EngineerYikai-Liao/symusic | 189 | 1 repos | ~1.5k | Automated safety check: Pass | MIT |
hodgef/apiker
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…
dmmulroy/cloudflare-skill
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…
spacelift-io/spacectl
Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.
pulumi/pulumi-aws-native
Use after triage or repository evidence establishes that an issue involves Pulumi AWS Native runtime behavior across the Pulumi provider protocol, generated CloudFormation metadata, and AWS Cloud…
Yikai-Liao/symusic
Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.
cyberful/cyberful
Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.
marin-community/marin
Deslop, simplify, or review low-value tests and prose only when explicitly requested for a branch or diff.
marin-community/marin
Use Iris to submit, inspect, debug, monitor, or recover jobs and tasks; diagnose scheduling and federation; deploy controllers; or reserve dev GPUs and TPUs.
marin-community/marin
Define, validate, submit, or restart a Marin SkyRL experiment through its artifact main.
marin-community/marin
Build, validate, publish, update, inspect, query, roll back, or archive a dynamic Marina applet.
marin-community/marin
Query Finelog logs and telemetry for Iris tasks, workers, profiles, training, vLLM, and cross-cluster forwarding.
marin-community/marin
Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean…
Works with
Categories
Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant. Review Grant is an agent skill from marin-community/marin. Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant.
Review Grant fits situations like: tasks that involve Infrastructure as code.
Run `npx skills add marin-community/marin --skill review-grant -a claude-code`. Or copy the skill folder (.agents/skills/review-grant in marin-community/marin) into .claude/skills/review-grant in your project. Claude Code loads it when a task matches its description.
Run `npx skills add marin-community/marin --skill review-grant -a codex`. Or copy the skill folder (.agents/skills/review-grant in marin-community/marin) into .agents/skills/review-grant in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marin-community/marin --skill review-grant -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-grant, .gemini/skills/review-grant, .github/skills/review-grant and .opencode/skills/review-grant in your project.
Going by SKILL.md and its folder, Review Grant needs the command-line tools its instructions call (pulumi, gh, git, uv and python). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use gh, git and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Review Grant is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review Grant: Cloudflare (hodgef/apiker, 127 stars), Cloudflare (dmmulroy/cloudflare-skill, 727 stars), Spacectl (spacelift-io/spacectl, 173 stars) and AWS Native Runtime Investigation (pulumi/pulumi-aws-native, 108 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
marin-community (a GitHub organization) maintains it in marin-community/marin, which has 3,921 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 10, 2026.
Source: marin-community/marin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.