Kubeshark Installer
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
Add a semantic audit event to agent-manager-service (the Go control plane).
$ npx skills add wso2/agent-manager --skill add-audit-event -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wso2/agent-manager add-audit-event --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wso2/agent-manager.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/add-audit-event .claude/skills/add-audit-event && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "add-audit-event" agent skill from https://github.com/wso2/agent-manager/tree/main/.claude/skills/add-audit-event into .claude/skills/add-audit-event/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-audit-event", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wso2/agent-manager/tree/main/.claude/skills/add-audit-eventType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wso2/agent-manager --skill add-audit-event -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wso2/agent-manager add-audit-event --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wso2/agent-manager.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/add-audit-event .agents/skills/add-audit-event && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "add-audit-event" agent skill from https://github.com/wso2/agent-manager/tree/main/.claude/skills/add-audit-event into .agents/skills/add-audit-event/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-audit-event", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wso2/agent-manager --skill add-audit-event -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wso2/agent-manager add-audit-event --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wso2/agent-manager.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/add-audit-event .cursor/skills/add-audit-event && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "add-audit-event" agent skill from https://github.com/wso2/agent-manager/tree/main/.claude/skills/add-audit-event into .cursor/skills/add-audit-event/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-audit-event", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wso2/agent-manager.git --path .claude/skills/add-audit-event--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wso2/agent-manager --skill add-audit-event -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wso2/agent-manager add-audit-event --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wso2/agent-manager.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/add-audit-event .gemini/skills/add-audit-event && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "add-audit-event" agent skill from https://github.com/wso2/agent-manager/tree/main/.claude/skills/add-audit-event into .gemini/skills/add-audit-event/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-audit-event", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wso2/agent-manager add-audit-eventInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wso2/agent-manager --skill add-audit-event -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wso2/agent-manager.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/add-audit-event .github/skills/add-audit-event && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "add-audit-event" agent skill from https://github.com/wso2/agent-manager/tree/main/.claude/skills/add-audit-event into .github/skills/add-audit-event/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-audit-event", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wso2/agent-manager --skill add-audit-event -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wso2/agent-manager add-audit-event --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wso2/agent-manager.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/add-audit-event .opencode/skills/add-audit-event && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "add-audit-event" agent skill from https://github.com/wso2/agent-manager/tree/main/.claude/skills/add-audit-event into .opencode/skills/add-audit-event/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-audit-event", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
add-audit-eventAdd a semantic audit event to agent-manager-service (the Go control plane).
Add Audit Event is an agent skill from wso2/agent-manager. Add a semantic audit event to agent-manager-service (the Go control plane). Use when adding or changing an operation that touches credentials, permissions, membership, deployment or deletion — API keys, tokens, secrets, role/group changes, user lifecycle, deploy/promote/delete, gateway trust config — or when the build fails with "cannot derive an action for audited route". Covers action registration, the fail-open vs fail-closed decision, redaction rules, and the test helper that operations refusing to run…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Deployment. The repository describes itself as: WSO2 AI Agent Manager is an open control plane designed for enterprises to deploy, manage, and govern AI agents at scale. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 84899da. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Add Audit Event loads about 2.1k tokens when it runs. Until then it costs about 137 tokens; SKILL.md has 892 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from wso2/agent-manager at commit 84899da, republished under its Apache-2.0 licence (© wso2). 892 words, ~2,133 tokens.
.claude/skills/add-audit-event/SKILL.md (or your agent's skills folder).Read first: agent-manager-service/AGENTS.md → "Audit logging", and agent-manager-service/docs/audit-logging.md for the full design.
Every route registered through RouteRegistrar, and every MCP tool registered through addTool, is already audited. That record names the actor, org, action, resource, outcome and source. Most changes need nothing.
You need this skill only for one of these:
| Situation | What to do |
|---|---|
Build fails: cannot derive an action for audited route (a route with no rbac.Permission) | Step 1 only — add an actionOverrides entry |
| The route's permission does not describe what it does | Step 1 only |
| The operation touches credentials, privileges, membership, deployment or deletion | All steps |
| Everything else | Nothing. Stop here. |
The test is whether the envelope answers the forensic question. POST .../permissions/add → 200 does not say which permission was granted, so it needs a semantic event. PUT .../agents/{name} returning 200 is self-describing, so it does not.
Actions read <resource>:<verb>. Reuse an existing constant if one fits; add to audit/actions_domain.go if not.
The same action must be used by every surface that performs the operation — REST, MCP, internal, background. TestDomainActionsMatchRouteDerivedActions fails the build if a semantic emit and its route disagree, because a split action silently halves every query.
If the route derives the wrong label, add one line to actionOverrides in audit/policy.go, keyed by the exact registrar pattern:
"POST /orgs/{orgName}/identities/roles/{roleID}/permissions/add": "role:grant-permission",All three go in audit/actions_domain.go, in the same place, so they cannot drift apart:
const ActionThingRotate Action = "thing:rotate"
// inside init()
registerCredential(ActionThingRotate, map[string]FieldKind{
"ownerName": KindName,
"keyName": KindName,
})Helpers: registerCredential (credential class, always critical) and registerIdentity (identity class, always critical). Otherwise call Register(action, class, severity) and RegisterDetailSchema(action, fields) directly.
| Class | Use for | Severity |
|---|---|---|
ClassCredential | keys, tokens, secrets, OAuth clients, trusted issuers | Critical |
ClassIdentity | users, groups, roles, permission assignment | Critical |
ClassDeployment | build, deploy, promote, lifecycle state | Notice–Warning |
ClassConfig | everything else that mutates | Info–Warning |
A registered action with no detail schema fails TestRegisteredActionsHaveDetailSchemas. An empty map is a valid answer; skipping the decision is not.
This is the decision that matters. Get it from the consequence, not the convenience.
Fail-closed — audit.Begin / attempt.Complete. Use when a live credential or a privilege change would otherwise exist with no trace of who caused it. The intent record is written before the change; if that write fails, the operation is refused.
attempt, err := audit.Begin(ctx, audit.ActionThingRotate,
audit.Org(ouID),
audit.ResourceNamed(audit.ResourceAPIKey, ownerID, keyName),
audit.Project(projName),
audit.Environment(envID),
audit.Detail("ownerType", audit.APIKeyOwnerAgent),
audit.Detail("keyName", keyName),
)
if err != nil {
return nil, err // do NOT perform the operation
}
resp, err := s.doTheThing(ctx, ...)
attempt.Complete(ctx, err)
return resp, errA record left at outcome: "unknown" means the process died mid-operation. That orphan is deliberate forensic signal, not a defect.
Fail-open — audit.Record. Use for frequent operations that issue no credential: builds, console test keys, gateway configuration, monitor lifecycle. Blocking CI on the audit path costs more than it protects.
err := s.doTheThing(ctx, ...)
audit.Record(ctx, audit.ActionThingUpdate,
audit.Org(ouID),
audit.ResourceNamed("thing", id, name),
audit.Result(err),
)audit.RecordAncillary — for a fact about how a request was handled (an authorization bypass, a rate-limited rejection) rather than what it did. Unlike Record, it does not suppress the coverage-tier record, so you keep both.
Emit from the service, not the controller. Controllers handle HTTP; a fail-closed emit is domain behaviour. The one exception is the identity surface, which has no service layer at all (see the documented exception in agent-manager-service/AGENTS.md → Layering) — do not treat it as precedent for new code.
In a controller, use beginAuditOrFail(w, r, operation, failureMessage, action, opts...): it writes the 503 and logs for you, so the refusal cannot be forgotten or answered with the wrong status.
audit.Detail records string, bool, int, int32, int64, float64, []string and fmt.Stringer. Anything else becomes a [unsupported:<type>] marker instead of being serialised. Pass the field you mean rather than relying on that.audit.SecretRef(key, value) (SHA-256 prefix + last four) or record the key name.audit.AttributeKeySummary(attrs) — it returns sorted key names, a count, and a flag when a key looks credential-shaped. Never the values.KindURL. Pass the URL as-is; the kind is what strips userinfo, query and fragment at redaction, so a token in ?access_token= or an https://user:pass@host/ cannot reach a record. A test fails if a detail whose name ends in uri, url or endpoint is declared as anything else.role:grant-permission records the granted scopes in full; they are identifiers, not credentials._droppedKeys.Services that fail closed refuse to run without a recorder, so a bare context.Background() makes them fail by design (audit: recorder unavailable).
// Exercising the operation: install a discarding recorder.
resp, err := svc.RotateThing(auditableCtx(t), ...)
// Asserting the refusal itself: bare context.
_, err := svc.RotateThing(context.Background(), ...)
require.ErrorIs(t, err, audit.ErrRecorderUnavailable)auditableCtx(t) lives in services/audit_testing_test.go. Do not redeclare it.
To assert on the records themselves, write the test inside the audit package — audit.NewMemorySink() is a test double declared in audit/sink_doubles_test.go and is not importable from services/ or controllers/. See audit/actions_domain_test.go. From another package, assert the behaviour (did the operation proceed or refuse) rather than the record.
actionOverrides makes them agree).audit/actions_domain.go.audit.Detail.auditableCtx(t).make test-unit passes — including TestDomainActionsMatchRouteDerivedActions, TestRegisteredActionsHaveDetailSchemas and TestEveryMutatingRouteIsAudited.docs/audit-logging.md semantic-event table updated if you added an action.golangci-lint run --config .github/linters/.golangci.yaml ./...© wso2, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/add-audit-event of wso2/agent-manager.
Open the folder on GitHubat commit 84899da
Add Audit Event next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Add Audit Event this skillwso2/agent-manager | 108 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Kubeshark Installerkubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Notes | Apache-2.0 | |
| GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb | 6.7k | — | ~4k | Automated safety check: Notes | Apache-2.0 | |
| KubeSphere ServiceMesh Managerkubesphere/kubesphere | 17k | — | ~2.4k | Automated safety check: Pass | Custom licence | |
| Vercelremotion-dev/remotion | 63k | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| AWS Cdk Developmentzxkane/aws-skills | 367 | 2 repos | ~2.5k | Automated safety check: Pass | MIT |
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
GreptimeTeam/greptimedb
Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.
kubesphere/kubesphere
Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.
remotion-dev/remotion
Set up a Codex monitor for Vercel deployments and preview URLs.
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
wso2/agent-manager
Add an API-backed feature to the console (React/TypeScript web UI).
wso2/agent-manager
Add a new evaluator to the amp-evaluation Python library. An agent skill from wso2/agent-manager.
wso2/agent-manager
Write a service-layer unit test in agent-manager-service (the Go control plane).
wso2/agent-manager
Add or change a REST API resource in agent-manager-service (the Go control plane).
Categories
Add a semantic audit event to agent-manager-service (the Go control plane). Add Audit Event is an agent skill from wso2/agent-manager. Add a semantic audit event to agent-manager-service (the Go control plane).
Add Audit Event fits situations like: changing an operation that touches credentials; deletion — API keys; role/group changes; deploy/promote/delete.
Run `npx skills add wso2/agent-manager --skill add-audit-event -a claude-code`. Or copy the skill folder (.claude/skills/add-audit-event in wso2/agent-manager) into .claude/skills/add-audit-event in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wso2/agent-manager --skill add-audit-event -a codex`. Or copy the skill folder (.claude/skills/add-audit-event in wso2/agent-manager) into .agents/skills/add-audit-event in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wso2/agent-manager --skill add-audit-event -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-audit-event, .gemini/skills/add-audit-event, .github/skills/add-audit-event and .opencode/skills/add-audit-event in your project.
Going by SKILL.md and its folder, Add Audit Event needs the command-line tools its instructions call (make).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Add Audit Event is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Add Audit Event: Kubeshark Installer (kubeshark/kubeshark, 12k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), KubeSphere ServiceMesh Manager (kubesphere/kubesphere, 17k stars) and Vercel (remotion-dev/remotion, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wso2 (a GitHub organization) maintains it in wso2/agent-manager, which has 108 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 9, 2026.
Source: wso2/agent-manager on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.