DevOps & Security skills

Browse reusable Agent Skills, each with a clear purpose and practical guidance.

golem-rollback

Rolling back a Golem deployment to a previous revision or version. Use when reverting a deployment, restoring a prior environment state, or recovering from a bad deploy.

1.60k repo starsObserved in 1 repos
DevOps & Security

golem-view-agent-logs

Viewing agent logs and output. Use when streaming agent stdout/stderr/log channels or understanding how to observe agent output at runtime.

1.60k repo starsObserved in 1 repos
DevOps & Security

modifying-service-configs

Modifying service configuration types or defaults. Use when changing config structs, adding config fields, or updating default values for any Golem service.

1.60k repo starsObserved in 1 repos
DevOps & Security

github-sync-gate

Enforce this repository's local-review-first GitHub sync policy. Use when Codex is preparing, validating, staging, committing, pushing, or opening a pull request for this repository and must wait for the exact approval phrase before any remote write.

1.59k repo starsObserved in 1 repos
DevOps & Security

Vibe Security Skill

This skill helps Claude write secure web applications. Use when working on any web application to ensure security best practices are followed.

1.58k repo starsObserved in 1 repos
DevOps & Security

steedos-configuration

Steedos Server environment variables and YAML settings. TRIGGER: .env files; env vars (MONGO_URL, ROOT_URL, B6_TRANSPORTER, JWT_SECRET); Docker compose setup, production vs development config, YAML env interpolation; datasources, tenant settings, CFS file storage, SSO/OIDC, email. SKIP: B6_* internals → steedos-builder6-internals; project structure → steedos-project-package.

1.57k repo starsObserved in 1 repos
DevOps & Security

401-403-bypass

401/403 访问拒绝绕过方法论。当遇到管理后台、API 端点返回 401/403 Forbidden 时使用。覆盖路径操纵、HTTP 方法篡改、Header 注入、协议降级、组合攻击

1.57k repo starsObserved in 1 repos
DevOps & Security

ad-domain-attack

Active Directory 域环境攻击全链路。当目标主机在域环境中(systeminfo 显示 Domain 非 WORKGROUP)、发现 88/389/636 端口、或获取到域用户凭据时使用。覆盖域信息收集、用户枚举、Kerberoasting、AS-REP Roasting、委派攻击、ACL 滥用、DCSync、Golden/Silver Ticket

1.57k repo starsObserved in 1 repos
DevOps & Security

ad-persistence

AD 域环境持久化技术。当已获取域管/本地管理员权限、需要建立持久访问以确保重启或密码更改后仍能回到目标环境时使用。覆盖主机级持久化(计划任务/注册表Run/COM劫持/WMI事件订阅/Windows服务/启动文件夹)、域级持久化(Golden Ticket/Silver Ticket/Skeleton Key/DSRM/AdminSDHolder)、DCShadow/GoldenGMSA高级技术、清理命令与检测规避

1.57k repo starsObserved in 1 repos
DevOps & Security

ad-trust-attack

域信任关系攻击。当目标存在多域/多林环境时使用。包含父子域提权(Golden Ticket + ExtraSid)、跨林攻击(SID History/MSSQL Trust Links)、单向信任利用。已获取子域 Domain Admin 或发现信任关系时优先加载。

1.57k repo starsObserved in 1 repos
DevOps & Security