Agent skill

Spacectl

by spacelift-io in spacelift-io/spacectl

Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.

MITAuto-check passedDevOps & Cloud

Install Spacectl

skills CLI
$ npx skills add spacelift-io/spacectl --skill spacectl -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install spacelift-io/spacectl spacectl --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/spacelift-io/spacectl.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spacectl .claude/skills/spacectl && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spacectl
GitHub stars
173
Token cost
~2.3k tokens
SKILL.md length
171 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.

  • Tasks that involve Infrastructure as code
  • SKILL.md covers Quick start, Commands, Output formats and Smart stack selection, plus 2 more sections
  • Calls jq

What it does

Spacectl is an agent skill from spacelift-io/spacectl. Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Pulumi and Terraform. The repository describes itself as: Spacelift client and CLI. The licence is MIT.

When your agent uses it

  • Tasks that involve Infrastructure as code

Example prompts

  • “/spacectl”

Requirements

  • Pre-approved tools (allowed-tools): Bash(spacectl:*)

What it can do on your machine

Read from SKILL.md and the folder at commit cca3a87. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(spacectl:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spacectl loads about 2.3k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 171 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from spacelift-io/spacectl at commit cca3a87, republished under its MIT licence (© spacelift-io). 171 words, ~2,280 tokens.

Download SKILL.mdSave it as .claude/skills/spacectl/SKILL.md (or your agent's skills folder).
name
spacectl
description
Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.
allowed-tools
Bash(spacectl:*)

Spacelift CLI (spacectl)

Quick start

bash
# check current profile and auth
spacectl profile current
spacectl whoami
# list stacks
spacectl stack list
# deploy a stack
spacectl stack deploy --id my-stack --tail
# preview changes from local workspace
spacectl stack local-preview --id my-stack

Commands

Authentication

Always operate on the current profile. Use select to switch, login (no alias) to re-authenticate. Login opens a browser for SSO.

bash
spacectl profile current
spacectl whoami
spacectl profile list
spacectl profile select <account-alias>
# re-authenticate current profile (opens browser)
spacectl profile login
spacectl profile export-token
Stack — Inspection
bash
spacectl stack list
spacectl stack list -o json
spacectl stack list --search "production" --limit 10
spacectl stack list --show-labels
spacectl stack show --id my-stack
spacectl stack show --id my-stack -o json
spacectl stack outputs --id my-stack
spacectl stack outputs --id my-stack --output-id specific_output
spacectl stack resources list --id my-stack
spacectl stack run list --id my-stack
spacectl stack run list --id my-stack --preview-runs --max-results 20
spacectl stack dependencies on --id my-stack
spacectl stack dependencies off --id my-stack
Stack — Run Management

Run states: QUEUED -> PREPARING -> PLANNING -> UNCONFIRMED -> APPLYING -> FINISHED (or FAILED/DISCARDED/CANCELED).

bash
# deploy (tracked run)
spacectl stack deploy --id my-stack --tail
spacectl stack deploy --id my-stack --sha abc123 --tail
spacectl stack deploy --id my-stack --auto-confirm
spacectl stack deploy --id my-stack --runtime-config runtime.yaml --tail
# preview (proposed run, plan only)
spacectl stack preview --id my-stack --tail
spacectl stack preview --id my-stack --sha abc123
# run lifecycle
spacectl stack confirm --id my-stack --run 01JRUN123 --tail
spacectl stack discard --id my-stack --run 01JRUN123
spacectl stack cancel --id my-stack --run 01JRUN123
spacectl stack retry --id my-stack --run 01JRUN123 --tail
spacectl stack replan --id my-stack --run 01JRUN123 --tail
spacectl stack replan --id my-stack --run 01JRUN123 --resources "aws_instance.foo"
spacectl stack prioritize --id my-stack --run 01JRUN123
spacectl stack deprioritize --id my-stack --run 01JRUN123
# approval
spacectl stack approve --id my-stack --run 01JRUN123 --note "LGTM"
spacectl stack reject --id my-stack --run 01JRUN123 --note "needs fix"
# approve current stack blocker (no specific run)
spacectl stack approve --id my-stack
# logs and changes
spacectl stack logs --id my-stack --run 01JRUN123
spacectl stack logs --id my-stack --run-latest
spacectl stack changes --id my-stack --run 01JRUN123
# task (arbitrary command in stack environment)
spacectl stack task --id my-stack "terraform state list" --tail
spacectl stack task --id my-stack --noinit "echo hello" --tail
Stack — Local Preview

Packages local files (respects .gitignore and .terraformignore), uploads to Spacelift, triggers a preview run.

bash
# auto-detects stack from git repo
spacectl stack local-preview
# explicit stack
spacectl stack local-preview --id my-stack
# env var overrides
spacectl stack local-preview --id my-stack --env-var-override "FOO=bar"
spacectl stack local-preview --id my-stack --tf-env-var-override "var_name=value"
# target specific resources
spacectl stack local-preview --id my-stack --target "aws_instance.foo" --target "aws_s3_bucket.bar"
# package only project root (not entire repo)
spacectl stack local-preview --id my-stack --project-root-only
# debug — create archive without uploading
spacectl stack local-preview --id my-stack --no-upload
# prioritize the preview run
spacectl stack local-preview --id my-stack --prioritize-run
# suppress log tailing
spacectl stack local-preview --id my-stack --no-tail
Stack — Management
bash
spacectl stack open --id my-stack
spacectl stack open --id my-stack --run 01JRUN123
spacectl stack lock --id my-stack --note "deploying manually"
spacectl stack unlock --id my-stack
spacectl stack enable --id my-stack
spacectl stack disable --id my-stack
spacectl stack set-current-commit --id my-stack --sha abc123
spacectl stack sync-commit --id my-stack
spacectl stack delete --id my-stack --skip-confirmation
spacectl stack delete --id my-stack --destroy-resources --skip-confirmation
Stack — Environment Variables
bash
spacectl stack environment list --id my-stack
spacectl stack environment list --id my-stack -o json
spacectl stack environment setvar --id my-stack MY_VAR "my-value"
# write-only: not readable outside runs
spacectl stack environment setvar --id my-stack SECRET_VAR "s3cret" --write-only
spacectl stack environment mount --id my-stack config.tfvars ./local-file.tfvars
spacectl stack environment mount --id my-stack config.tfvars --write-only < file.tfvars
spacectl stack environment delete --id my-stack MY_VAR
Modules
bash
spacectl module list
spacectl module list -o json --search "vpc"
spacectl module list-versions --id my-module
spacectl module create-version --id my-module --version "1.2.3" --sha abc123
spacectl module delete-version --id my-module --version-id 01JVER123
spacectl module local-preview --id my-module
spacectl module local-preview --id my-module --tests
Policies
bash
spacectl policy list
spacectl policy list --search "plan" --limit 5
spacectl policy show --id my-policy
spacectl policy samples --id my-policy
spacectl policy sample --id my-policy --key "sample-key"
spacectl policy simulate --id my-policy --input '{"key": "value"}'
spacectl policy simulate --id my-policy --input input.json
Blueprints
bash
spacectl blueprint list
spacectl blueprint show --id my-blueprint
spacectl blueprint deploy --b-id my-blueprint
Worker Pools
bash
spacectl workerpool list
spacectl workerpool list -o json
spacectl workerpool worker list --pool-id 01JPOOL123
spacectl workerpool worker drain --id 01JWORKER123 --pool-id 01JPOOL123
spacectl workerpool worker drain --id 01JWORKER123 --pool-id 01JPOOL123 --wait-until-drained
spacectl workerpool worker undrain --id 01JWORKER123 --pool-id 01JPOOL123
spacectl workerpool worker cycle --pool-id 01JPOOL123
Providers
bash
spacectl provider add-gpg-key --name "release-key" --generate
spacectl provider add-gpg-key --name "release-key" --import --path key.gpg
spacectl provider list-gpg-keys
spacectl provider revoke-gpg-key --id 01JKEY123
spacectl provider create-version --type my-provider --gpg-key-id 01JKEY123
spacectl provider list-versions --type my-provider
spacectl provider publish-version --version-id 01JVER123
spacectl provider revoke-version --version-id 01JVER123
spacectl provider delete-version --version-id 01JVER123
Infra Assistant sessions

Sessions belong to the user who created them: the profile must be logged in as that user (spacectl profile login, web browser option). API key profiles can't read sessions: get reports the session as not found.

bash
spacectl ai sessions list
spacectl ai sessions list --search "vpc" --limit 20 -o json
# print a session's markdown transcript to stdout
spacectl ai sessions get 01JSESSION123
# only messages 10-19 (offset is the index of the first message)
spacectl ai sessions get 01JSESSION123 --offset 10 --limit 10
Other
bash
# audit trail
spacectl audit-trail list
spacectl audit-trail list --search "stack" --limit 20 -o json
# external dependencies
spacectl run-external-dependency mark-completed --id dep-123 --status finished
spacectl run-external-dependency mark-completed --id dep-123 --status failed
# usage data
spacectl profile usage-csv --since 2025-01-01 --until 2025-03-31
spacectl profile usage-csv --aspect run-minutes --group-by run-state --file usage.csv
# version
spacectl version

Output formats

All list/show commands support --output (-o) with values table (default) or json. Use --no-color to disable ANSI colors (auto-disabled when piped).

bash
spacectl stack list -o json
spacectl stack show --id my-stack -o json
spacectl stack outputs --id my-stack -o json
spacectl workerpool list -o json | jq '.[].name'

Smart stack selection

When --id is omitted, spacectl auto-detects the stack from the current git repository and subdirectory. If multiple stacks match, an interactive prompt appears. Set SPACECTL_SKIP_STACK_PROMPT=true to auto-select.

bash
# from inside a git repo linked to a Spacelift stack
spacectl stack show
spacectl stack deploy --tail
spacectl stack local-preview

Example: full deploy flow

bash
spacectl stack deploy --id my-stack --tail
# wait for UNCONFIRMED, review the plan output, then:
spacectl stack confirm --id my-stack --run 01JRUN123 --tail
# or discard if something looks wrong:
spacectl stack discard --id my-stack --run 01JRUN123

Example: auto-confirm deploy

bash
spacectl stack deploy --id my-stack --auto-confirm

© spacelift-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/spacectl of spacelift-io/spacectl.

Open the folder on GitHubat commit cca3a87

Compare with similar skills

Spacectl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spacectl compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spacectl this skillspacelift-io/spacectl173—~2.3kAutomated safety check: PassMIT
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Cloudflaredmmulroy/cloudflare-skill727—~1.6kAutomated safety check: PassMIT
Audit Infrastructure As Codecyberful/cyberful135—~649Automated safety check: PassAGPL-3.0
AWS Sst Developmentzxkane/aws-skills367—~2.7kAutomated safety check: WarnMIT
Deploying Applicationsancoleman/ai-design-components526—~3.1kAutomated safety check: PassMIT

Similar skills

  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    727 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • AWS Sst Development

    zxkane/aws-skills

    SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

    367 GitHub stars~2.7k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: warnings
  • Deploying Applications

    ancoleman/ai-design-components

    Deployment patterns from Kubernetes to serverless and edge functions.

    526 GitHub stars~3.1k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed
  • Writing Infrastructure Code

    ancoleman/ai-design-components

    Managing cloud infrastructure using declarative and imperative IaC tools.

    526 GitHub stars~3.9k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed

Works with

Categories

Questions about Spacectl

What does Spacectl do?

Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI. Spacectl is an agent skill from spacelift-io/spacectl. Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.

When should I use Spacectl?

Spacectl fits situations like: tasks that involve Infrastructure as code.

How do I install Spacectl in Claude Code?

Run `npx skills add spacelift-io/spacectl --skill spacectl -a claude-code`. Or copy the skill folder (skills/spacectl in spacelift-io/spacectl) into .claude/skills/spacectl in your project. Claude Code loads it when a task matches its description.

How do I install Spacectl in Codex?

Run `npx skills add spacelift-io/spacectl --skill spacectl -a codex`. Or copy the skill folder (skills/spacectl in spacelift-io/spacectl) into .agents/skills/spacectl in your project. Codex loads it when a task matches its description.

Can I use Spacectl in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spacelift-io/spacectl --skill spacectl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spacectl, .gemini/skills/spacectl, .github/skills/spacectl and .opencode/skills/spacectl in your project.

What does Spacectl need to run?

Going by SKILL.md and its folder, Spacectl needs the command-line tools its instructions call (jq). Its frontmatter pre-approves these tools: Bash(spacectl:*).

Does Spacectl access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spacectl safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Spacectl use?

Spacectl is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spacectl use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spacectl?

Skills that share tags, products or a category with Spacectl: Cloudflare (hodgef/apiker, 127 stars), Cloudflare (dmmulroy/cloudflare-skill, 727 stars), Audit Infrastructure As Code (cyberful/cyberful, 135 stars) and AWS Sst Development (zxkane/aws-skills, 367 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spacectl?

spacelift-io (a GitHub organization) maintains it in spacelift-io/spacectl, which has 173 GitHub stars. The repository was last updated on October 7, 2026.

Source: spacelift-io/spacectl on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.