Agent skill

Pulumi

by pproenca in pproenca/dot-skills

Pulumi infrastructure as code performance and reliability guidelines.

MITAuto-check passedDevOps & Cloud

Install Pulumi

skills CLI
$ npx skills add pproenca/dot-skills --skill pulumi -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pproenca/dot-skills pulumi --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.experimental/pulumi .claude/skills/pulumi && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pulumi
GitHub stars
214
Token cost
~1.4k tokens
SKILL.md length
501 words
Files
52 (incl. references, assets)
Skills in repo
182
Repo updated
First seen
Licence
MIT

At a glance

Pulumi infrastructure as code performance and reliability guidelines.

  • Works in 8 steps: State Management and Backend (CRITICAL) → Resource Graph Optimization (CRITICAL) → Component Design (HIGH) → …
  • Tasks involving Pulumi stacks
  • SKILL.md covers When to Apply, Rule Categories by Priority, Quick Reference and How to Use, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pulumi is an agent skill from pproenca/dot-skills. Pulumi infrastructure as code performance and reliability guidelines. This skill should be used when writing, reviewing, or refactoring Pulumi code to ensure optimal deployment performance and infrastructure reliability. Triggers on tasks involving Pulumi stacks, components, state management, secrets configuration, resource lifecycle options, or CI/CD automation.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 54 other files, including reference files and assets (for example `AGENTS.md`, `README.md` and `assets/templates/_template.md`).

It sits in DevOps & Cloud, covering Infrastructure as code and State management. It works with Pulumi. The repository describes itself as: A collection of AI agent skills following the Agent Skills open format. The licence is MIT.

When your agent uses it

  • Tasks involving Pulumi stacks
  • State management
  • Secrets configuration
  • Resource lifecycle options

Example prompts

  • “/pulumi”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. State Management and Backend (CRITICAL)
  2. Resource Graph Optimization (CRITICAL)
  3. Component Design (HIGH)
  4. Secrets and Configuration (HIGH)
  5. Stack Organization (MEDIUM-HIGH)
  6. Resource Options and Lifecycle (MEDIUM)
  7. Testing and Validation (MEDIUM)
  8. Automation and CI/CD (LOW-MEDIUM)

What it can do on your machine

Read from SKILL.md and the folder at commit cf93c57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pulumi loads about 1.4k tokens when it runs, and up to ~24k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 501 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~24k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pproenca/dot-skills at commit cf93c57, republished under its MIT licence (© pproenca). 501 words, ~1,363 tokens.

Download SKILL.mdSave it as .claude/skills/pulumi/SKILL.md (or your agent's skills folder). This skill also uses 51 other files; get the full folder from GitHub.
name
pulumi
description
Pulumi infrastructure as code performance and reliability guidelines. This skill should be used when writing, reviewing, or refactoring Pulumi code to ensure optimal deployment performance and infrastructure reliability. Triggers on tasks involving Pulumi stacks, components, state management, secrets configuration, resource lifecycle options, or CI/CD automation.

Pulumi Best Practices

Comprehensive performance and reliability guide for Pulumi infrastructure as code, designed for AI agents and LLMs. Contains 46 rules across 8 categories, prioritized by impact to guide automated refactoring and code generation.

When to Apply

Reference these guidelines when:

  • Writing new Pulumi infrastructure code
  • Designing component abstractions for reuse
  • Configuring secrets and sensitive values
  • Organizing stacks and cross-stack references
  • Setting up CI/CD pipelines for infrastructure

Rule Categories by Priority

PriorityCategoryImpactPrefix
1State Management and BackendCRITICALpstate-
2Resource Graph OptimizationCRITICALgraph-
3Component DesignHIGHpcomp-
4Secrets and ConfigurationHIGHsecrets-
5Stack OrganizationMEDIUM-HIGHstack-
6Resource Options and LifecycleMEDIUMlifecycle-
7Testing and ValidationMEDIUMtest-
8Automation and CI/CDLOW-MEDIUMauto-

Quick Reference

1. State Management and Backend (CRITICAL)
  • pstate-backend-selection - Use managed backend for production stacks
  • pstate-checkpoint-skipping - Enable checkpoint skipping for large stacks
  • pstate-stack-size - Keep stacks under 500 resources
  • pstate-refresh-targeting - Use targeted refresh instead of full stack
  • pstate-export-import - Use state export/import for migrations
  • pstate-import-existing - Import existing resources before managing
2. Resource Graph Optimization (CRITICAL)
  • graph-parallel-resources - Structure resources for maximum parallelism
  • graph-output-dependencies - Use outputs to express true dependencies
  • graph-explicit-depends - Use dependsOn only for external dependencies
  • graph-avoid-apply-side-effects - Avoid side effects in apply functions
  • graph-conditional-resources - Use conditional logic at resource level
  • graph-stack-references-minimal - Minimize stack reference depth
3. Component Design (HIGH)
  • pcomp-component-resources - Use ComponentResource for reusable abstractions
  • pcomp-parent-child - Pass parent option to child resources
  • pcomp-unique-naming - Use name prefix pattern for unique resource names
  • pcomp-register-outputs - Register component outputs explicitly
  • pcomp-multi-language - Design components for multi-language consumption
  • pcomp-transformations - Use transformations for cross-cutting concerns
4. Secrets and Configuration (HIGH)
  • secrets-use-secret-config - Use secret config for sensitive values
  • secrets-avoid-state-exposure - Prevent secret leakage in state
  • secrets-external-providers - Use external secret managers for production
  • secrets-generate-random - Generate secrets with random provider
  • secrets-provider-rotation - Rotate secrets provider when team members leave
  • secrets-environment-isolation - Isolate secrets by environment
Show full SKILL.md (198 more words)Show less
5. Stack Organization (MEDIUM-HIGH)
  • stack-separation-by-lifecycle - Separate stacks by deployment lifecycle
  • stack-references-parameterized - Parameterize stack references
  • stack-output-minimal - Export only required outputs
  • stack-naming-conventions - Use consistent stack naming convention
6. Resource Options and Lifecycle (MEDIUM)
  • lifecycle-protect-stateful - Protect stateful resources
  • lifecycle-delete-before-replace - Use deleteBeforeReplace for unique constraints
  • lifecycle-retain-on-delete - Use retainOnDelete for shared resources
  • lifecycle-ignore-changes - Use ignoreChanges for externally managed properties
  • lifecycle-replace-on-changes - Use replaceOnChanges for immutable dependencies
  • lifecycle-aliases - Use aliases for safe resource renaming
  • lifecycle-custom-timeouts - Set custom timeouts for long-running resources
7. Testing and Validation (MEDIUM)
  • test-unit-mocking - Use mocks for fast unit tests
  • test-property-policies - Use policy as code for property testing
  • test-integration-ephemeral - Use ephemeral stacks for integration tests
  • test-preview-assertions - Assert on preview results before deployment
  • test-stack-reference-mocking - Mock stack references in unit tests
8. Automation and CI/CD (LOW-MEDIUM)
  • auto-automation-api-workflows - Use Automation API for complex workflows
  • auto-inline-programs - Use inline programs for dynamic infrastructure
  • auto-ci-cd-preview - Run preview in PR checks
  • auto-deployments-api - Use Pulumi Deployments for GitOps
  • auto-review-stacks - Use review stacks for PR environments
  • auto-drift-detection - Enable drift detection for production

How to Use

Read individual reference files for detailed explanations and code examples:

Full Compiled Document

For the complete guide with all rules expanded: AGENTS.md

© pproenca, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 51 other files (references, assets) in skills/.experimental/pulumi of pproenca/dot-skills.

  • SKILL.md
  • AGENTS.md
  • README.md
  • assets/templates/_template.md
  • metadata.json
  • references/_sections.md
  • references/auto-automation-api-workflows.md
  • references/auto-ci-cd-preview.md
  • references/auto-deployments-api.md
  • references/auto-drift-detection.md
  • references/auto-inline-programs.md
  • references/auto-review-stacks.md
  • references/graph-avoid-apply-side-effects.md
  • references/graph-conditional-resources.md
  • references/graph-explicit-depends.md
  • references/graph-output-dependencies.md
  • references/graph-parallel-resources.md
  • references/graph-stack-references-minimal.md
  • … and 34 more

Open the folder on GitHubat commit cf93c57

Compare with similar skills

Pulumi next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pulumi compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pulumi this skillpproenca/dot-skills214—~1.4kAutomated safety check: PassMIT
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Cloudflaredmmulroy/cloudflare-skill728—~1.6kAutomated safety check: PassMIT
Spacectlspacelift-io/spacectl173—~2.3kAutomated safety check: PassMIT
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT
Trace Pulumi Diffmarin-community/marin3.9k—~663Automated safety check: PassApache-2.0

Similar skills

  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    728 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed
  • Spacectl

    spacelift-io/spacectl

    Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.

    173 GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • Trace Pulumi Diff

    marin-community/marin

    Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean…

    3.9k GitHub stars~663 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    134 GitHub stars~649 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from pproenca/dot-skills

All 182 skills in this repo
  • Audio Voice Recovery

    pproenca/dot-skills

    Audio forensics and voice recovery guidelines for CSI-level audio analysis.

    214 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Codemod React Pipeline

    pproenca/dot-skills

    Guided, scripted pipeline for running JSX/TSX/React codemods safely across large legacy codebases.

    214 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Dev Rfc

    pproenca/dot-skills

    Create well-structured RFCs and technical proposals for software projects.

    214 GitHub stars~3.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Dx Harness

    pproenca/dot-skills

    Developer-experience friction auditing and fixing — slow onboarding, repeated manual setup steps, missing bootstrap/reset/seed scripts, undiscoverable conventions.

    214 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Language Spec Author

    pproenca/dot-skills

    Turn a rough idea for a language into a complete, implementable specification — a DSL, query, config/data, template, or protocol language — by interviewing the author dimension by dimension until…

    214 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Python Pep Author

    pproenca/dot-skills

    Drafting Python Enhancement Proposals (PEPs) — proposing a Python language feature, a standard library change, an interoperability standard, or an informational/process document for the Python…

    214 GitHub stars~2.1k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Pulumi

What does Pulumi do?

Pulumi infrastructure as code performance and reliability guidelines. Pulumi is an agent skill from pproenca/dot-skills. Pulumi infrastructure as code performance and reliability guidelines.

When should I use Pulumi?

Pulumi fits situations like: tasks involving Pulumi stacks; state management; secrets configuration; resource lifecycle options.

How do I install Pulumi in Claude Code?

Run `npx skills add pproenca/dot-skills --skill pulumi -a claude-code`. Or copy the skill folder (skills/.experimental/pulumi in pproenca/dot-skills) into .claude/skills/pulumi in your project. Claude Code loads it when a task matches its description.

How do I install Pulumi in Codex?

Run `npx skills add pproenca/dot-skills --skill pulumi -a codex`. Or copy the skill folder (skills/.experimental/pulumi in pproenca/dot-skills) into .agents/skills/pulumi in your project. Codex loads it when a task matches its description.

Can I use Pulumi in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pproenca/dot-skills --skill pulumi -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pulumi, .gemini/skills/pulumi, .github/skills/pulumi and .opencode/skills/pulumi in your project.

What does Pulumi need to run?

SKILL.md names no scripts, command-line tools or credentials: Pulumi is instructions for the agent only.

Does Pulumi access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pulumi safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pulumi use?

Pulumi is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pulumi use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 22k tokens, read only when the agent opens those files.

What are the alternatives to Pulumi?

Skills that share tags, products or a category with Pulumi: Cloudflare (hodgef/apiker, 127 stars), Cloudflare (dmmulroy/cloudflare-skill, 728 stars), Spacectl (spacelift-io/spacectl, 173 stars) and Devops Engineer (Yikai-Liao/symusic, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pulumi?

pproenca (a GitHub user) maintains it in pproenca/dot-skills, which has 214 GitHub stars. The repository holds 182 skills in this directory. The repository was last updated on August 15, 2026.

Source: pproenca/dot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.