BagelHole/DevOps-Security-Agent-Skills

Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container hardening, SOC2/ISO27001, and incident response—plus ready-to-run scripts, templates, and playbooks for SRE, platform, and security teams.

1.1kStars on the repository
163Mods indexed here, across every type
3mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

user-management

121

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Manage users, groups, and permissions on Linux systems. Configure sudo and access controls. Use when managing system access.

not rated 1.1k +31 3mo ago D 26 tokens original MIT

windows-server

122

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Administer Windows Server systems. Manage IIS, Active Directory, and PowerShell automation. Use when administering Windows infrastructure.

not rated 1.1k +31 3mo ago A SkillSpector: pass 26 tokens original MIT

backup-recovery

123

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Implement backup and recovery strategies. Configure rsync, Restic, and cloud backups. Use when designing data protection solutions.

not rated 1.1k +31 3mo ago D 28 tokens original MIT

block-storage

124

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Manage block storage volumes and LVM. Configure cloud block storage and local disks. Use when managing disk storage.

not rated 1.1k +31 3mo ago B SkillSpector: warn 25 tokens original MIT

nfs-storage

125

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Configure NFS servers and clients. Implement network file sharing for Linux systems. Use when setting up shared storage.

not rated 1.1k +31 3mo ago A SkillSpector: warn 26 tokens original MIT

object-storage

126

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex needs its repo

Configure object storage with S3, GCS, and MinIO. Implement lifecycle policies and access controls. Use when managing object storage.

not rated 1.1k +31 3mo ago A SkillSpector: warn 30 tokens original MIT

ai-agent-security

127

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex needs its repo

Secure AI agents against prompt injection, tool abuse, and data exfiltration with defense-in-depth controls. Use when building, deploying, or hardening agentic AI systems that invoke tools, access data, or interact with production infrastructure.

not rated 1.1k +31 3mo ago D 51 tokens original MIT

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex needs its repo

Secure AI coding agents (Claude Code, Cursor, Codex, Copilot) with permission boundaries, secret protection, code review gates, and safe sandbox configurations for team environments.

not rated 1.1k +31 3mo ago C 43 tokens original MIT

ai-red-teaming

129

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Run structured AI red team exercises for jailbreak resistance, data exfiltration risk, harmful output controls, and agent tool abuse resilience.

not rated 1.1k +31 3mo ago C 31 tokens original MIT

ai-security-hardening

130

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Harden AI/LLM deployments against prompt injection, data exfiltration, model theft, and supply chain attacks. Covers input validation, output filtering, access control, model API security, and compliance controls for production AI systems.

not rated 1.1k +31 3mo ago A SkillSpector: pass 51 tokens original MIT

llm-app-security

131

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Secure LLM-powered applications with input validation, output controls, tenant isolation, and abuse prevention.

not rated 1.1k +31 3mo ago B SkillSpector: warn 24 tokens original MIT

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Secure the AI model supply chain with artifact signing, provenance attestation, SBOM workflows, dependency controls, and trusted model promotion.

not rated 1.1k +31 3mo ago A SkillSpector: pass 32 tokens original MIT

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Defend AI systems against prompt injection and indirect prompt attacks using input controls, tool permissions, output validation, and isolation boundaries.

not rated 1.1k +31 3mo ago D 30 tokens original MIT

cis-benchmarks

134

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Audit and remediate CIS benchmark violations. Use automated tools to assess compliance and implement hardening recommendations. Use when meeting compliance requirements or implementing security baselines.

not rated 1.1k +31 3mo ago A SkillSpector: warn 36 tokens original MIT

container-hardening

135

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Secure Docker images and container runtime configurations. Implement non-root users, read-only filesystems, and security contexts. Use when building secure container images or hardening container deployments.

not rated 1.1k +31 3mo ago B 38 tokens original MIT

kubernetes-hardening

136

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Implement Kubernetes security contexts, Pod Security Standards, and network policies. Secure cluster components and workloads. Use when hardening Kubernetes deployments or meeting security compliance.

not rated 1.1k +31 3mo ago A SkillSpector: pass 35 tokens original MIT

linux-hardening

137

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Apply CIS benchmarks and secure Linux servers. Configure SSH, manage users, implement firewall rules, and enable security features. Use when hardening Linux systems for production or meeting security compliance requirements.

not rated 1.1k +31 3mo ago B Socket: passSnyk: warn 41 tokens original MIT

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification. Use when shipping OpenClaw with Docker, Kubernetes, or automated release pipelines.

not rated 1.1k +31 3mo ago A SkillSpector: pass 51 tokens original MIT

windows-hardening

139

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Harden Windows servers per security baselines and CIS benchmarks. Configure Group Policy, Windows Defender, and security features. Use when securing Windows Server environments.

not rated 1.1k +31 3mo ago A SkillSpector: pass 34 tokens original MIT

firewall-config

140

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Configure iptables, nftables, and cloud firewalls. Implement network segmentation and traffic filtering. Use when securing network perimeters or implementing security zones.

not rated 1.1k +31 3mo ago A SkillSpector: warn 34 tokens original MIT

ssl-tls-management

141

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Manage SSL/TLS certificates with Let's Encrypt and internal PKI. Configure secure HTTPS, certificate renewal, and cipher suites. Use when implementing secure communications.

not rated 1.1k +31 3mo ago B SkillSpector: warn 35 tokens original MIT

vpn-setup

142

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Configure WireGuard, OpenVPN, and cloud VPNs. Implement secure remote access and site-to-site connectivity. Use when setting up secure network tunnels.

not rated 1.1k +31 3mo ago D 34 tokens original MIT

waf-setup

143

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex needs its repo

Deploy and tune Web Application Firewalls. Configure rules for OWASP Top 10 protection. Use when protecting web applications from common attacks.

not rated 1.1k +31 3mo ago A SkillSpector: warn 32 tokens original MIT

zero-trust

144

BagelHole/DevOps-Security-Agent-Skills

Skill Claude CodeCodex

Implement zero-trust network architecture. Configure identity-based access, micro-segmentation, and continuous verification. Use when implementing modern security architectures.

not rated 1.1k +31 3mo ago A SkillSpector: warn 32 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: