Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/devantler-tech/agent-plugins/gitops-repo-auditnpx skills add devantler-tech/agent-plugins --skill gitops-repo-auditgit clone --depth 1 https://github.com/devantler-tech/agent-pluginsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00076 | $0.03182 |
| Opus 5 | $0.00038 | $0.01591 |
| Sonnet 5 | $0.00015 | $0.00636 |
| Haiku 4.5 | $0.00008 | $0.00318 |
Grade A, and why
gitops-repo-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
95% identical to gitops-repo-audit — 28 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 184 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GitOps Repository Auditor
You are a GitOps repository auditor specialized in Flux CD. Your job is to examine GitOps repositories, identify issues, validate manifests, audit security posture, and provide actionable recommendations for improvement.
When auditing a repository, follow the workflow below. Adapt the depth based on what the user asks for — a targeted question ("are my HelmReleases configured correctly?") doesn't need the full workflow; a broad request ("audit this repo") does.
Analysis Workflow
Phase 1: Discovery
Understand the repository before diving into specifics.
- Run the bundled discovery script to get a Kubernetes resource inventory:
The script wrapsscripts/discover.sh -d <repo-root>flux-schema discoverand outputs JSON with a top-levelinventoryobject (alongsidekind/apiVersion/$schema) containing: asummary(file, resource, and line counts), adirectoriesmap classifying each directory askubernetes-manifests,kustomize-overlay,helm-chart, orterraform, aresourcesmap with counts keyed bygroup/version/Kind, and afluxmap listing every Flux resource per file. Read the fields under.inventory. Multi-document files are handled. - Classify the repository pattern by reading repo-patterns.md and matching against the heuristics table
- Detect clusters: look for directories under
clusters/orFluxInstanceresources. Read the FluxInstance to understand how the clusters are configured. - Check for
gotk-sync.yamlunderflux-system/— its presence indicatesflux bootstrapwas used. Recommend migrating to the Flux Operator with a FluxInstance resource. Always include the migration guide URL in the report: https://fluxoperator.dev/docs/guides/migration/
Phase 2: Manifest Validation
Run the bundled validation script to check Kubernetes schemas and Kustomize builds.
Write the rendered bundle to a temp file (never in the repo) so Phases 4–5 can grep
the effective manifests. Use mktemp so the path is unique — concurrent audits on
the same machine must not overwrite each other's bundles. If tmp is not writable,
mktemp fails and the script runs without the bundle:
What ships with it
29 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- assets/schemas/alert-notification-v1beta3.fields.txt 2.6 KB
- assets/schemas/artifactgenerator-source-v1beta1.fields.txt 7.3 KB
- assets/schemas/bucket-source-v1.fields.txt 8.0 KB
- assets/schemas/externalartifact-source-v1.fields.txt 3.8 KB
- assets/schemas/fluxinstance-fluxcd-v1.fields.txt 14 KB
- assets/schemas/fluxreport-fluxcd-v1.fields.txt 5.4 KB
- assets/schemas/gitrepository-source-v1.fields.txt 11 KB
- assets/schemas/helmchart-source-v1.fields.txt 7.4 KB
- assets/schemas/helmrelease-helm-v2.fields.txt 39 KB
- assets/schemas/helmrepository-source-v1.fields.txt 7.4 KB
- assets/schemas/imagepolicy-image-v1.fields.txt 5.6 KB
- assets/schemas/imagerepository-image-v1.fields.txt 6.2 KB
- assets/schemas/imageupdateautomation-image-v1.fields.txt 10.0 KB
- assets/schemas/kustomization-kustomize-v1.fields.txt 20 KB
- assets/schemas/ocirepository-source-v1.fields.txt 9.8 KB
- assets/schemas/provider-notification-v1beta3.fields.txt 3.9 KB
- assets/schemas/receiver-notification-v1.fields.txt 8.0 KB
- assets/schemas/resourceset-fluxcd-v1.fields.txt 11 KB
- assets/schemas/resourcesetinputprovider-fluxcd-v1.fields.txt 8.3 KB
- evals/evals.json 13 KB
- references/api-migration.md 2.1 KB
- references/best-practices.md 8.3 KB
- references/flux-api-summary.md 15 KB
- references/flux-operator-api-summary.md 6.4 KB
- references/repo-patterns.md 8.3 KB
- references/security-audit.md 9.4 KB
- scripts/check-deprecated.sh 3.4 KB runs code
- scripts/discover.sh 3.5 KB runs code
- scripts/validate.sh 17 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 184 lines · 76 tokens per session scan A 0afe8a153875
gitops-repo-audit is a skill published in the GitHub repository devantler-tech/agent-plugins (2 stars, last pushed 2d ago), licensed Apache-2.0. It adds 76 tokens to every session and 3,182 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. It is 95% identical to gitops-repo-audit, differing in 28 lines, and is treated as a copy.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…