Home / devops
DevOps
Eight skills for shipping and operating software: Dockerfile hardening, GitHub Actions workflow authoring and validation, Kubernetes manifest review, Terraform review, crontab diagnosis, .env key diffs, release notes from git history and a semver advisor.
Install
In Claude Code, add the marketplace and install the plugin:
/plugin marketplace add basitalisandhu/claude-skills
/plugin install devops@claude-skills
Or copy the skill files into ~/.claude/skills/ from a clone:
git clone https://github.com/basitalisandhu/claude-skills
cd claude-skills
python3 install.py --user --only devops
Skills
| Skill | What it does | Scripts |
|---|---|---|
| cron-doctor | Diagnose a crontab with a bundled script that validates every schedule, explains it in words, computes the next runs, and flags jobs with no output redirection, unescaped percent signs, PATH assumptions, day-of-month plus day-of-week confusion, DST-sensitive hours, overlapping frequent jobs and duplicates; then fix the entries and add locking and logging. | yes |
| dockerfile-hardening | Lint a Dockerfile with a bundled script for images that run as root, unpinned or latest base images, secrets in ENV or ARG, remote scripts piped to a shell, unclean apt layers, world-writable permissions and missing HEALTHCHECK, then rewrite it as a smaller, pinned, non-root multi-stage build. | yes |
| env-diff | Compare the keys of a .env.example (or any template) against real .env files with a bundled script, listing missing, extra, empty and duplicated keys and template values that look like real credentials, without ever printing a value. | yes |
| github-actions-author | Write or review GitHub Actions workflows with least-privilege permissions, SHA-pinned actions, timeouts, concurrency and caching, and validate them with a bundled linter that catches missing permissions, pull_request_target checkout of fork code, expression injection in run steps, unpinned actions and literal secrets. | yes |
| k8s-manifest-review | Review Kubernetes manifests (Deployments, StatefulSets, DaemonSets, Jobs, CronJobs, Pods, Services, Secrets) with a bundled script for missing resource limits and probes, privileged or root containers, mutable image tags, host namespaces and hostPath mounts, inline secrets and missing seccomp, then produce the corrected YAML. | yes |
| release-notes | Generate release notes from a git commit range with a bundled script that groups commits by Conventional Commits type (breaking, features, fixes, performance, docs, build), links commits and issues, and lists contributors; then edit them into notes a user can read. | yes |
| semver-advisor | Decide the next version number (major, minor or patch, or a pre-release) for a library, service, API, CLI or schema from the actual changes, using a decision table for what counts as breaking in each kind of artefact, and explain the decision with evidence. | no |
| terraform-review | Review Terraform or OpenTofu code against a fixed checklist: state and backend safety, provider and module version pinning, variables with types and validation, secrets handling, public exposure (open security groups, public buckets, 0.0.0.0/0), encryption and logging defaults, lifecycle and destroy protection, and plan hygiene. | no |
Plugin README
Eight skills for shipping and operating software: Dockerfile hardening, GitHub Actions authoring and validation, Kubernetes manifest review, Terraform review, crontab diagnosis, .env key diffs, release notes from git history, and a semver advisor.
Install
/plugin marketplace add basitalisandhu/claude-dev-skills
/plugin install devops@claude-dev-skills
Skills then appear as /devops:<skill>. Scripts need Python 3.11 or newer on PATH as python3; they use the standard library only and make no network calls.
Skills
| Skill | Triggers on | Produces |
|---|---|---|
dockerfile-hardening | review, slim or write a Dockerfile | dockerfile_lint.py findings, pinned non-root multi-stage build |
github-actions-author | add CI, review workflows, unpinned actions | gha_lint.py findings, least-privilege workflow from templates |
k8s-manifest-review | review or harden Kubernetes YAML | k8s_review.py findings, restricted-baseline manifests |
terraform-review | review Terraform, is this plan safe | checklist findings, plan reading, rules to automate |
cron-doctor | cron job did not run, ran twice, wrong time | cron_doctor.py schedule explanations, next runs, fixes |
env-diff | works locally fails in staging, onboarding config | env_diff.py missing, extra and empty keys (no values) |
release-notes | release notes, GitHub release body | release_notes.py grouped Markdown, edited for readers |
semver-advisor | is this breaking, major or minor | version decision with evidence per change |
Tests for every script live in the repository's tests/ directory; run python3 -m pytest -q at the repository root.