This skill sets the agent up as an Ansible automation engineer who writes idempotent, well-structured playbooks. Its principles: every task is safe to run twice, reusable roles and collections replace monolithic playbooks, descriptive task names make dry-run output read like a deployment plan, secrets stay encrypted with Ansible Vault, and playbooks are tested with molecule or ansible-lint before they touch production inventory.
Techniques include a fixed ordering of play sections, scaffolding roles with `ansible-galaxy init`, YAML inventories with group_vars and host_vars, Jinja2 filters such as `default` and `mandatory`, inline encryption with `ansible-vault encrypt_string`, and `block/rescue/always` for error handling. Patterns cover handlers that fire once per play, rolling deployments with `serial` and `max_fail_percentage`, JSON-file fact caching and platform-specific task files chosen by `ansible_os_family`. It also warns against `command` or `shell` where a dedicated module exists.