Agent skill

Ansible Playbook Updater

by vinta in vinta/hal-9000

Keeps Ansible install tasks in line with upstream docs by fixing version, install-method and link drift one tool at a time, with a commit for each.

MITAuto-check passedDevOps & Cloud

Install Ansible Playbook Updater

skills CLI
$ npx skills add vinta/hal-9000 --skill update-playbooks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinta/hal-9000 update-playbooks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/update-playbooks .claude/skills/update-playbooks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-playbooks
GitHub stars
138
Token cost
~1.4k tokens
SKILL.md length
740 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Keeps Ansible install tasks in line with upstream docs by fixing version, install-method and link drift one tool at a time, with a commit for each.

  • Works in 6 steps: Scan → Read the upstream docs → Edit → …
  • Bumping a pinned tool version in an install role
  • SKILL.md covers 1. Scan, 2. Read the upstream docs, 3. Edit and 4. Match the collection pin to…, plus 2 more sections
  • Calls make, gh and curl

What it does

Each install task in playbooks/roles carries a comment URL pointing at upstream docs, and the skill reads that page for three kinds of drift: the pinned version trails the newest release within its release line, upstream now recommends a different install method, or the link has moved. Bumps stay inside the release line, and a newer line is only reported in the final summary for you to decide.

The steps are scan, read and edit. A grep lists every task with its role, doc URL and pinned version. For each URL the agent fetches the page once, taking the newest tag from the GitHub API for GitHub links and WebFetch otherwise, the install commands currently recommended for macOS, and where the URL ends up after redirects. It then replaces the old version everywhere in the role and repoints moved links. A separate pin for the community.general collection is checked against the Homebrew-installed Ansible. Allowed edits are limited to the roles and the collections requirements file.

When your agent uses it

  • Bumping a pinned tool version in an install role
  • Adopting a newly recommended installation method from upstream docs
  • Repointing documentation links that have moved
  • Aligning the community.general collection pin with the installed Ansible

Example prompts

  • “Check every install role against its upstream docs and bump any stale pins in the same release line.”
  • “The kubectl docs moved; update the link in its role and confirm the install command is still current.”

Requirements

  • A repository with install tasks under playbooks/roles
  • The gh CLI and network access to fetch upstream docs
  • Pre-approved tools (allowed-tools): Edit(./playbooks/roles/**), Edit(./playbooks/collections/requirements.yml), WebFetch, Bash(gh api:*), Bash(curl:*), Bash(make lint:*), Bash(ansible-galaxy collection list:*)

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scan
  2. Read the upstream docs
  3. Edit
  4. Match the collection pin to brew's ansible
  5. Verify and commit
  6. Offer method switches

What it can do on your machine

Read from SKILL.md and the folder at commit 46dc048. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Edit(./playbooks/roles/**)
    • Edit(./playbooks/collections/requirements.yml)
    • WebFetch
    • Bash(gh api:*)
    • Bash(curl:*)
    • Bash(make lint:*)
    • Bash(ansible-galaxy collection list:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • gh
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ansible Playbook Updater loads about 1.4k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 740 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinta/hal-9000 at commit 46dc048, republished under its MIT licence (© vinta). 740 words, ~1,363 tokens.

Download SKILL.mdSave it as .claude/skills/update-playbooks/SKILL.md (or your agent's skills folder).
name
update-playbooks
description
(project) Use when updating install tasks in playbooks/roles/ against upstream docs — bumping a pinned version, adopting a newly recommended install method, repointing a doc link that moved, or realigning the community.general pin with the brew-installed ansible
allowed-tools
Edit(./playbooks/roles/**), Edit(./playbooks/collections/requirements.yml), WebFetch, Bash(gh api:*), Bash(curl:*), Bash(make lint:*), Bash(ansible-galaxy collection list:*)
user-invocable
true
model
sonnet
effort
high
metadata.internal
true

Update Playbooks

Close the drift between each install task in playbooks/roles/*/tasks/main.yml and the upstream docs it cites, then commit per tool.

Drift takes three forms, and all three are read off the same page — the # comment URL above the task:

  • Version drift — the pin trails the newest release of its release line.
  • Method drift — upstream now recommends a different way to install.
  • Link drift — the doc URL itself moved.

A release line is the version prefix a project treats as a stable series: Node 24.x, Python 3.14.x, kubectl 1.35.x. Every bump stays inside the line (24.15.0 -> 24.18.0 is in-line for Node because Node's line is the major). When a newer line exists (Node 26, Python 3.15, kubectl 1.36), keep the pin on its current line and report the newer line in the final summary so the user can decide.

One pin lives outside the roles and answers to a different source of truth — playbooks/collections/requirements.yml, covered in §4.

1. Scan

bash
grep -rn -E '^# https?://|^- name:' playbooks/roles/*/tasks/main.yml

Adjacent line numbers pair each URL with the task it documents. Done when every install task is listed with its role, its doc URL, and any version pinned in its name, command body, or download URL.

2. Read the upstream docs

Fetch each doc URL once and take all three answers off that one page:

  • newest tag inside the release line — gh api repos/OWNER/REPO/releases --jq '.[].tag_name' for a github.com/OWNER/REPO link, WebFetch otherwise.
  • the install commands the page currently recommends for macOS — quote them verbatim, including which method the page calls recommended when it ranks them.
  • where the URL lands — curl -sIL -o /dev/null -w '%{http_code} %{url_effective}\n' URL.

Done when every task has today's version, install commands, and final URL confirmed from its page. Anything recalled from training data is stale by definition.

3. Edit

Apply version and link drift, matching the surrounding task style:

  • Version — replace the old version at every occurrence in the role: the task name:, each command line, and any URL. Done when grepping the file for the old version returns nothing.
  • Link — repoint the # comment at the URL that resolved.

Keep each task's install method, and note each tool whose page recommends a different macOS method for §6. A page that ranks nothing recommends every method it lists, so note a tool only when its task's method is no longer among them.

Show full SKILL.md (355 more words)Show less

4. Match the collection pin to brew's ansible

playbooks/collections/requirements.yml pins community.general, the collection supplying the homebrew, homebrew_tap, and homebrew_cask modules the roles install through. Upstream releases do not drive this pin — the brew-installed ansible does. Brew bundles its own copy of the collection, ~/.ansible/collections takes precedence over it, and the pin is what fills ~/.ansible/collections. So a pin that disagrees with brew means ansible-lint validates different module code than ansible-playbook executes, silently.

bash
ansible-galaxy collection list community.general

When they differ, set the pin to brew's version. Never the reverse, and never to the newest release on Galaxy — a pin ahead of brew shadows the bundled collection just as badly as one behind it. Editing the pin is where this skill stops: installing it is make install's job, so note in the final summary that the bump takes effect on the next make install.

5. Verify and commit

Run make lint. Then create one commit per tool with the commit skill, passing what moved, e.g. bump kubectl to v1.35.7 or install foundryup from getfoundry.sh. A collection pin bump is its own commit, separate from any role.

6. Offer method switches

Once §5's commits are made, ask the user with AskUserQuestion whether to switch each tool noted in §3, one question per tool, up to four per call. Each question offers keeping the current method and switching to the page's recommended one, quoting the recommended commands in that option's preview; when the switch would cost something the task has, such as a version pin Homebrew cannot hold or a script's self-update, say so in the option's description.

For each yes, adopt the upstream commands; a script install points its creates: guard at the binary the script produces. A Homebrew install uses the homebrew module at state: latest, which also replaces any separate upgrade task, as fnm and bun show; a formula from the project's own tap takes a homebrew_tap task above it. Then run make lint and commit each switched tool as in §5.

Close with a summary: what changed per tool, which tools were already current, which method switches the user declined, and any newer release lines waiting on the user.

© vinta, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/update-playbooks of vinta/hal-9000.

Open the folder on GitHubat commit 46dc048

Compare with similar skills

Ansible Playbook Updater next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ansible Playbook Updater compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ansible Playbook Updater this skillvinta/hal-9000138—~1.4kAutomated safety check: PassMIT
Depot GitHub RunnersPostHog/posthog40k—~2.8kAutomated safety check: PassCustom licence
PR Reviewansible-collections/community.postgresql144—~1.6kAutomated safety check: PassCustom licence
Releaseansible-collections/community.postgresql144—~1.7kAutomated safety check: PassCustom licence
Azure Pipelines Log Downloaderansible/ansible71k—~825Automated safety check: PassGPL-3.0
Wdio Testingansible/vscode-ansible488—~2.2kAutomated safety check: PassMIT

Similar skills

  • Depot GitHub Runners

    PostHog/posthog

    Official

    Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners.

    40k GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • PR Review

    ansible-collections/community.postgresql

    Reviews pull requests and code changes in this Ansible collection against project standards and the Ansible Collection Review Checklist.

    144 GitHub stars~1.6k tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Release

    ansible-collections/community.postgresql

    Guides the release of an Ansible collection following the upstream process (without release branches).

    144 GitHub stars~1.7k tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Downloads Azure Pipelines CI logs for an Ansible pull request or build so the agent can analyze test failures, after asking you first.

    71k GitHub stars~825 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Wdio Testing

    ansible/vscode-ansible

    Write, run, and debug WebDriverIO (WDIO) UI tests for the Ansible VS Code extension.

    488 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Datadog Data Source Generator

    DataDog/terraform-provider-datadog

    Official

    Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.

    468 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from vinta/hal-9000

All 15 skills in this repo
  • Finds which plugins in the repository changed, bumps only the ones not already bumped since origin/main, and checks that each plugin's two manifests stay in sync.

    138 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Audits your Claude Code settings and environment variables against the current official docs and returns a ranked list of changes tied to how you actually work.

    138 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Logical Git Commits

    vinta/hal-9000

    Commits everything in the working tree as one logical change per commit, splitting files by hunk, with bodies that say what was wrong before and never an invented reason.

    138 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • PR

    vinta/hal-9000

    A skill your agent uses when the user explicitly asks to push the current branch and open a PR, rewrite an open PR's body from its commits, or wait for CI and merge it

    138 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Rewrites docs, READMEs, issues, comments or UI text in plain Global English that translates well and still sounds native, keeping every fact intact.

    138 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Best Practices

    vinta/hal-9000

    A skill your agent uses when about to choose, configure, or refine a tool, library, config format, API pattern, or project setup, or before proposing a design of your own — research current…

    138 GitHub stars~553 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Ansible Playbook Updater

What does Ansible Playbook Updater do?

Keeps Ansible install tasks in line with upstream docs by fixing version, install-method and link drift one tool at a time, with a commit for each. Each install task in playbooks/roles carries a comment URL pointing at upstream docs, and the skill reads that page for three kinds of drift: the pinned version trails the newest release within its release line, upstream now recommends a different install method, or the link has moved. Bumps stay inside the release line, and a newer line is only reported in the final summary for you to decide.

When should I use Ansible Playbook Updater?

Ansible Playbook Updater fits situations like: bumping a pinned tool version in an install role; adopting a newly recommended installation method from upstream docs; repointing documentation links that have moved; aligning the community.general collection pin with the installed Ansible.

How do I install Ansible Playbook Updater in Claude Code?

Run `npx skills add vinta/hal-9000 --skill update-playbooks -a claude-code`. Or copy the skill folder (.claude/skills/update-playbooks in vinta/hal-9000) into .claude/skills/update-playbooks in your project. Claude Code loads it when a task matches its description.

How do I install Ansible Playbook Updater in Codex?

Run `npx skills add vinta/hal-9000 --skill update-playbooks -a codex`. Or copy the skill folder (.claude/skills/update-playbooks in vinta/hal-9000) into .agents/skills/update-playbooks in your project. Codex loads it when a task matches its description.

Can I use Ansible Playbook Updater in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinta/hal-9000 --skill update-playbooks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-playbooks, .gemini/skills/update-playbooks, .github/skills/update-playbooks and .opencode/skills/update-playbooks in your project.

What does Ansible Playbook Updater need to run?

Going by SKILL.md and its folder, Ansible Playbook Updater needs the command-line tools its instructions call (make, gh and curl). Our summary lists: A repository with install tasks under playbooks/roles; The gh CLI and network access to fetch upstream docs. Its frontmatter pre-approves these tools: Edit(./playbooks/roles/**), Edit(./playbooks/collections/requirements.yml), WebFetch, Bash(gh api:*), Bash(curl:*), Bash(make lint:*), Bash(ansible-galaxy collection list:*).

Does Ansible Playbook Updater access the network?

SKILL.md contains no URLs. Its commands use gh and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ansible Playbook Updater safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ansible Playbook Updater use?

Ansible Playbook Updater is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ansible Playbook Updater use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ansible Playbook Updater?

Skills that share tags, products or a category with Ansible Playbook Updater: Depot GitHub Runners (PostHog/posthog, 40k stars), PR Review (ansible-collections/community.postgresql, 144 stars), Release (ansible-collections/community.postgresql, 144 stars) and Azure Pipelines Log Downloader (ansible/ansible, 71k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ansible Playbook Updater?

vinta (a GitHub user) maintains it in vinta/hal-9000, which has 138 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 8, 2026.

Source: vinta/hal-9000 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.