Agent skill

Trace Pulumi Diff

by marin-community in marin-community/marin

Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean…

Apache-2.0Auto-check passedDevOps & Cloud

Install Trace Pulumi Diff

skills CLI
$ npx skills add marin-community/marin --skill trace-pulumi-diff -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install marin-community/marin trace-pulumi-diff --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/trace-pulumi-diff .claude/skills/trace-pulumi-diff && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
trace-pulumi-diff
GitHub stars
3.9k
Token cost
~663 tokens
SKILL.md length
237 words
Files
2
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean…

  • A stack has unapplied changes
  • SKILL.md covers Preview current main, Find the deployed commit and Attribute the preview
  • Calls pulumi, git and uv
  • Drift and someone needs to know which PRs explain the preview

What it does

Trace Pulumi Diff is an agent skill from marin-community/marin. Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean Git checkout. Use when a stack has unapplied changes or drift and someone needs to know which PRs explain the preview.

Its SKILL.md is about 660 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in DevOps & Cloud, covering Infrastructure as code and Pull requests. It works with Pulumi and Git. The repository describes itself as: Open-source framework for the research and development of foundation models. The licence is Apache-2.0.

When your agent uses it

  • A stack has unapplied changes
  • Drift and someone needs to know which PRs explain the preview

Example prompts

  • “/trace-pulumi-diff”

What it can do on your machine

Read from SKILL.md and the folder at commit 61bb85c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pulumi
    • git
    • uv
    • jq
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, uv and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Trace Pulumi Diff loads about 663 tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 237 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~663

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from marin-community/marin at commit 61bb85c, republished under its Apache-2.0 licence (© marin-community). 237 words, ~663 tokens.

Download SKILL.mdSave it as .claude/skills/trace-pulumi-diff/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
trace-pulumi-diff
description
Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean Git checkout. Use when a stack has unapplied changes or drift and someone needs to know which PRs explain the preview.

Trace a Pulumi diff

Work only with the marin-iac project in infra/pulumi. Require an explicit stack name.

Preview current main

Read infra/pulumi/README.md and satisfy its credentials and stack-specific prerequisites. Fetch origin/main and run from a clean checkout at that commit. Preserve existing work; use another worktree when necessary.

Prepare the environment from the repository root:

bash
uv sync --package marin-iac --extra deploy --frozen
export PULUMI_PYTHON_CMD="$PWD/.venv/bin/python"

Run the preview without changing the selected stack:

bash
pulumi -C infra/pulumi preview --stack <stack> --diff --color never

Keep the raw preview local. It may contain decrypted identifiers. If the preview is empty, report that the stack has no pending diff and stop.

Find the deployed commit

Read recent history without secrets:

bash
pulumi -C infra/pulumi stack history \
  --stack <stack> --json --page-size 100 > /tmp/marin-pulumi-history-<stack>.json
jq -r '
  map(select(.kind == "update" and .result == "succeeded"))
  | first
  | [.startTime, .environment["git.head"], .environment["git.dirty"]]
  | @tsv
' /tmp/marin-pulumi-history-<stack>.json

Use git.head only when it is a commit on origin/main and git.dirty is false. If either condition fails, report that an exact Git baseline is unavailable and stop attribution.

Attribute the preview

List merged commits after the deployed commit:

bash
git log --first-parent --format='%H%x09%s' <deployed-sha>..origin/main

Inspect each candidate with git show. Match concrete preview resource names and changed properties to the code or configuration diff. Do not attribute a change merely because its commit is in the range.

Map a matching commit to its pull request:

bash
gh api repos/marin-community/marin/commits/<commit>/pulls \
  --jq '.[] | [.number, .title, .html_url] | @tsv'

Report each preview change with its matching PR and the file or hunk that explains it. Report changes with no matching commit as live drift or unresolved attribution. A preview can contain changes from multiple PRs.

Never run pulumi up, pulumi refresh, pulumi destroy, an import, or a state mutation. Call out any NodePool replacement or deletion from the preview.

© marin-community, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/trace-pulumi-diff of marin-community/marin.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 61bb85c

Compare with similar skills

Trace Pulumi Diff next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Trace Pulumi Diff compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Trace Pulumi Diff this skillmarin-community/marin3.9k—~663Automated safety check: PassApache-2.0
Datadog Data Source GeneratorDataDog/terraform-provider-datadog468—~2.7kAutomated safety check: PassMPL-2.0
PR Reviewansible-collections/community.postgresql144—~1.6kAutomated safety check: PassCustom licence
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Cloudflaredmmulroy/cloudflare-skill727—~1.6kAutomated safety check: PassMIT
Reviewwerf/werf4.7k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Datadog Data Source Generator

    DataDog/terraform-provider-datadog

    Official

    Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.

    468 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • PR Review

    ansible-collections/community.postgresql

    Reviews pull requests and code changes in this Ansible collection against project standards and the Ansible Collection Review Checklist.

    144 GitHub stars~1.6k tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    727 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed
  • Review

    werf/werf

    Code review of a pull request, branch, or diff. An agent skill from werf/werf.

    4.7k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Automate GitHub workflows with AI assistance. An agent skill from FNOSP/FlyNarwhal.

    496 GitHub starsUsed in 8 repos~5.4k tokens
    DevOps & CloudAuto-check passed

More from marin-community/marin

All 41 skills in this repo
  • Noslop

    marin-community/marin

    Deslop, simplify, or review low-value tests and prose only when explicitly requested for a branch or diff.

    3.9k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Use Iris

    marin-community/marin

    Use Iris to submit, inspect, debug, monitor, or recover jobs and tasks; diagnose scheduling and federation; deploy controllers; or reserve dev GPUs and TPUs.

    3.9k GitHub stars~745 tokensUpdated today
    Auto-check passed
  • Launch Rl

    marin-community/marin

    Define, validate, submit, or restart a Marin SkyRL experiment through its artifact main.

    3.9k GitHub stars~894 tokensUpdated today
    Auto-check passed
  • Marina Applet

    marin-community/marin

    Build, validate, publish, update, inspect, query, roll back, or archive a dynamic Marina applet.

    3.9k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Query Finelog

    marin-community/marin

    Query Finelog logs and telemetry for Iris tasks, workers, profiles, training, vLLM, and cross-cluster forwarding.

    3.9k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Deploy Hero Change

    marin-community/marin

    Deploy a significant code change (backend, kernel, optimizer, data path) to the live hero run: relaunch it under a new run id from a permanent checkpoint, compare against the old run over a trial…

    3.9k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Trace Pulumi Diff

What does Trace Pulumi Diff do?

Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean…. Trace Pulumi Diff is an agent skill from marin-community/marin. Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean Git checkout.

When should I use Trace Pulumi Diff?

Trace Pulumi Diff fits situations like: A stack has unapplied changes; drift and someone needs to know which PRs explain the preview.

How do I install Trace Pulumi Diff in Claude Code?

Run `npx skills add marin-community/marin --skill trace-pulumi-diff -a claude-code`. Or copy the skill folder (.agents/skills/trace-pulumi-diff in marin-community/marin) into .claude/skills/trace-pulumi-diff in your project. Claude Code loads it when a task matches its description.

How do I install Trace Pulumi Diff in Codex?

Run `npx skills add marin-community/marin --skill trace-pulumi-diff -a codex`. Or copy the skill folder (.agents/skills/trace-pulumi-diff in marin-community/marin) into .agents/skills/trace-pulumi-diff in your project. Codex loads it when a task matches its description.

Can I use Trace Pulumi Diff in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marin-community/marin --skill trace-pulumi-diff -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trace-pulumi-diff, .gemini/skills/trace-pulumi-diff, .github/skills/trace-pulumi-diff and .opencode/skills/trace-pulumi-diff in your project.

What does Trace Pulumi Diff need to run?

Going by SKILL.md and its folder, Trace Pulumi Diff needs the command-line tools its instructions call (pulumi, git, uv, jq and gh).

Does Trace Pulumi Diff access the network?

SKILL.md contains no URLs. Its commands use git, uv and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Trace Pulumi Diff safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Trace Pulumi Diff use?

Trace Pulumi Diff is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Trace Pulumi Diff use?

About 663 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Trace Pulumi Diff?

Skills that share tags, products or a category with Trace Pulumi Diff: Datadog Data Source Generator (DataDog/terraform-provider-datadog, 468 stars), PR Review (ansible-collections/community.postgresql, 144 stars), Cloudflare (hodgef/apiker, 127 stars) and Cloudflare (dmmulroy/cloudflare-skill, 727 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Trace Pulumi Diff?

marin-community (a GitHub organization) maintains it in marin-community/marin, which has 3,920 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 9, 2026.

Source: marin-community/marin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.