Provider Bug Review
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes).
$ npx skills add runwhen-contrib/runwhen-local --skill extend-discovery-type -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install runwhen-contrib/runwhen-local extend-discovery-type --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/runwhen-contrib/runwhen-local.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/extend-discovery-type .claude/skills/extend-discovery-type && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "extend-discovery-type" agent skill from https://github.com/runwhen-contrib/runwhen-local/tree/main/.cursor/skills/extend-discovery-type into .claude/skills/extend-discovery-type/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-discovery-type", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/runwhen-contrib/runwhen-local/tree/main/.cursor/skills/extend-discovery-typeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add runwhen-contrib/runwhen-local --skill extend-discovery-type -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install runwhen-contrib/runwhen-local extend-discovery-type --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/runwhen-contrib/runwhen-local.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.cursor/skills/extend-discovery-type .agents/skills/extend-discovery-type && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "extend-discovery-type" agent skill from https://github.com/runwhen-contrib/runwhen-local/tree/main/.cursor/skills/extend-discovery-type into .agents/skills/extend-discovery-type/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-discovery-type", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add runwhen-contrib/runwhen-local --skill extend-discovery-type -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install runwhen-contrib/runwhen-local extend-discovery-type --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/runwhen-contrib/runwhen-local.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.cursor/skills/extend-discovery-type .cursor/skills/extend-discovery-type && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "extend-discovery-type" agent skill from https://github.com/runwhen-contrib/runwhen-local/tree/main/.cursor/skills/extend-discovery-type into .cursor/skills/extend-discovery-type/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-discovery-type", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/runwhen-contrib/runwhen-local.git --path .cursor/skills/extend-discovery-type--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add runwhen-contrib/runwhen-local --skill extend-discovery-type -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install runwhen-contrib/runwhen-local extend-discovery-type --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/runwhen-contrib/runwhen-local.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.cursor/skills/extend-discovery-type .gemini/skills/extend-discovery-type && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "extend-discovery-type" agent skill from https://github.com/runwhen-contrib/runwhen-local/tree/main/.cursor/skills/extend-discovery-type into .gemini/skills/extend-discovery-type/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-discovery-type", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install runwhen-contrib/runwhen-local extend-discovery-typeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add runwhen-contrib/runwhen-local --skill extend-discovery-type -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/runwhen-contrib/runwhen-local.git skills-src && mkdir -p .github/skills && cp -r skills-src/.cursor/skills/extend-discovery-type .github/skills/extend-discovery-type && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "extend-discovery-type" agent skill from https://github.com/runwhen-contrib/runwhen-local/tree/main/.cursor/skills/extend-discovery-type into .github/skills/extend-discovery-type/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-discovery-type", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add runwhen-contrib/runwhen-local --skill extend-discovery-type -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install runwhen-contrib/runwhen-local extend-discovery-type --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/runwhen-contrib/runwhen-local.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.cursor/skills/extend-discovery-type .opencode/skills/extend-discovery-type && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "extend-discovery-type" agent skill from https://github.com/runwhen-contrib/runwhen-local/tree/main/.cursor/skills/extend-discovery-type into .opencode/skills/extend-discovery-type/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-discovery-type", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
extend-discovery-typeAdd or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes).
Extend Discovery Type is an agent skill from runwhen-contrib/runwhen-local. Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes). Use when asked to support a new cloud resource type, add a typed SDK collector, fix a resource type mapping, or extend what an indexer discovers. Enforces the registry sync, collector registration, normalizer, tests, docs, and generation-rule contract.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes, Google Cloud, Microsoft Azure and Amazon Web Services. The repository describes itself as: RunWhen Local provides a tailored troubleshooting cheat sheet for Kubernetes environments. The licence is Apache-2.0.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ecf77b7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pythondockerbashpoetryFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Extend Discovery Type loads about 1.7k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 623 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from runwhen-contrib/runwhen-local at commit ecf77b7, republished under its Apache-2.0 licence (© runwhen-contrib). 623 words, ~1,712 tokens.
.claude/skills/extend-discovery-type/SKILL.md (or your agent's skills folder).Use this when an existing indexer should discover a new resource type or
return richer data for one it already covers. To stand up a brand-new platform,
use the add-discovery-type skill instead.
The native SDK indexers (azureapi, gcpapi, future awsapi) all share the
same shape: a generated registry maps CloudQuery table names to native
cloud API types, a generic collector provides broad parity, and a small set
of typed collectors provide rich payloads for high-value types. Read the
canonical worked examples before editing:
docs/architecture/azure-indexer-internals.mddocs/architecture/gcp-indexer-internals.mdsrc/indexers/*_resource_type_registry.yaml).
Edit the overrides file and re-run the sync script.resource_type contract used in generation rules. New types must resolve by
their canonical CloudQuery table name (or a registered alias).Copy this checklist and track it:
- [ ] 1. Identify the target indexer + canonical CloudQuery table name
- [ ] 2. Edit the overrides YAML (type mapping / alias / typed_collector flag)
- [ ] 3. Regenerate the registry via the sync script (never hand-edit the YAML)
- [ ] 4. (typed only) Implement collector + register in _TYPED_COLLECTORS
- [ ] 5. (if needed) Extend the normalizer for the new payload shape
- [ ] 6. Add/extend the SDK dependency (pyproject + locked) if required
- [ ] 7. Update tests (registry + normalizer + selective)
- [ ] 8. Update docs (indexed-resources + indexer internals)
- [ ] 9. Verify the generation-rule contract still holds
- [ ] 10. Run the unit testsDetermine which backend (azureapi / gcpapi / aws / Kubernetes) owns the
type and the canonical CloudQuery table name (e.g. gcp_compute_instances,
azure_compute_disks). This name is the registry key and the generation-rule
resource_type.
Per platform:
| Platform | Overrides file |
|---|---|
| Azure | scripts/azure/azure_resource_type_overrides.yaml |
| GCP | scripts/gcp/gcp_resource_type_overrides.yaml |
Edit only what the heuristic gets wrong:
arm_type_overrides (Azure) or
cai_type_overrides (GCP). Set it to null if the table has no native API
equivalent (so the generic pass skips it).aliases so older/alternate names still resolve.typed_collectors.service_api_hosts.# GCP (round-trips existing table list, picks up override changes):
python scripts/gcp/sync_gcp_resource_type_registry.py
# Azure:
python scripts/azure/sync_azure_resource_type_registry.pyThe script reports added / removed / changed. Inspect the diff in the
generated YAML; it should reflect only your intended change.
Skip this for types that are fine coming from the generic pass (Azure
resources.list() envelope, GCP Cloud Asset Inventory full payload).
GCP (src/indexers/gcpapi_resource_types.py):
def _collect_<type>(credentials, project_id):
from google.cloud import <client_module> # lazy import
client = <Client>(credentials=credentials)
return list(client.list_<entity>(project=project_id))Register it keyed by canonical table name:
_TYPED_COLLECTORS: dict[str, GcpCollector] = {
"gcp_compute_instances": _collect_compute_instances,
"gcp_<service>_<entity>": _collect_<type>,
}Azure (src/indexers/azureapi_resource_types.py): implement both
_collect_<type>_all(credential, subscription_id) and
_collect_<type>_in_rg(credential, subscription_id, rg_name), then register in
_TYPED_COLLECTORS keyed by canonical table name (pass None for the second
slot only if no per-RG SDK call exists).
A typed type is automatically excluded from the generic pass, so the resource is written exactly once.
Normalizers (*_normalizers.py) convert raw SDK/API objects into the
CloudQuery-shaped dict the platform handler expects. Reuse the existing
normalize_* helpers when possible. Only add code for genuinely new fields, and
always map cloud labels/tags into the canonical tags field.
If the typed collector needs an SDK that isn't already a dependency, add it to
src/pyproject.toml and regenerate the lock inside the pinned Python container:
docker run --rm -v "$PWD/src:/app" -w /app python:3.14-slim \
bash -lc "pip install poetry && poetry lock"Lazy-import SDK clients inside the collector so importing the indexer module never hard-requires the SDK.
test_<platform>_resource_type_registry.py: assert the new type resolves and,
if typed, appears in the typed-collector set.test_<platform>api_normalizers.py: a round-trip through the platform handler
for the new payload shape.test_<platform>api_selective.py: if dispatch/selection logic changed.docs/authoring/indexed-resources/<platform>.md: list the new matchable type
and note whether it's typed (rich) or generic.Generation rules reference the type by its CloudQuery table name as
resource_type. Confirm:
find/find_spec by that exact
table name (and any aliases you added).resource_name, scope qualifiers, tags). See the
template-tags-hierarchy rule for the tag/hierarchy contract.If a contrib generation rule should start matching the new type, update or note it; do not silently change matching behavior for existing rules.
cd src && python -m unittest discover -s indexers -p 'test_*.py'© runwhen-contrib, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .cursor/skills/extend-discovery-type of runwhen-contrib/runwhen-local.
Open the folder on GitHubat commit ecf77b7
Extend Discovery Type next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Extend Discovery Type this skillrunwhen-contrib/runwhen-local | 163 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Provider Bug Reviewmondoohq/mql | 411 | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Kcli Cluster Deploymentkarmab/kcli | 653 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Kclikarmab/kcli | 653 | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | |
| Azure Arcvinayaklatthe/microsoft-security-skills | 175 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Provider API Call Dedupmondoohq/mql | 411 | — | ~7.7k | Automated safety check: Pass | Custom licence |
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
karmab/kcli
Comprehensive guide for kcli usage. An agent skill from karmab/kcli.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
mondoohq/mql
A skill your agent uses when a provider scan is slow, times out, or trips rate limits (429, throttling, Retry-After), when the same request URL appears many times in a debug log, when an asset's…
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
runwhen-contrib/runwhen-local
Stand up a brand-new RunWhen Local discovery platform / indexer from scratch (a new cloud or resource source) following the native SDK pattern used by azureapi and gcpapi.
runwhen-contrib/runwhen-local
Write generation rules using bundled references in this repo (airgap).
Categories
Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes). Extend Discovery Type is an agent skill from runwhen-contrib/runwhen-local. Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes).
Extend Discovery Type fits situations like: asked to support a new cloud resource type; add a typed SDK collector; fix a resource type mapping; extend what an indexer discovers.
Run `npx skills add runwhen-contrib/runwhen-local --skill extend-discovery-type -a claude-code`. Or copy the skill folder (.cursor/skills/extend-discovery-type in runwhen-contrib/runwhen-local) into .claude/skills/extend-discovery-type in your project. Claude Code loads it when a task matches its description.
Run `npx skills add runwhen-contrib/runwhen-local --skill extend-discovery-type -a codex`. Or copy the skill folder (.cursor/skills/extend-discovery-type in runwhen-contrib/runwhen-local) into .agents/skills/extend-discovery-type in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add runwhen-contrib/runwhen-local --skill extend-discovery-type -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/extend-discovery-type, .gemini/skills/extend-discovery-type, .github/skills/extend-discovery-type and .opencode/skills/extend-discovery-type in your project.
Going by SKILL.md and its folder, Extend Discovery Type needs the command-line tools its instructions call (python, docker, bash and poetry). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Extend Discovery Type is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Extend Discovery Type: Provider Bug Review (mondoohq/mql, 411 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars), Kcli (karmab/kcli, 653 stars) and Azure Arc (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
runwhen-contrib (a GitHub organization) maintains it in runwhen-contrib/runwhen-local, which has 163 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.
Source: runwhen-contrib/runwhen-local on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.