DevOps & Security skills

Browse reusable Agent Skills, each with a clear purpose and practical guidance.

om-auto-sec-report-pr

Paranoid OWASP-oriented security analysis for a SINGLE unit of work — one PR, one spec under `.ai/specs/`, or one branch diff. Hunts non-obvious attack vectors beyond OWASP Top 10, flags same-pattern hotspots elsewhere, and emits "Next steps — go deeper" follow-ups. Writes markdown + HTML under `.ai/analysis/`; runs standalone or as a sub-unit of `om-auto-sec-report`.

1.50k repo starsObserved in 1 repos
DevOps & Security

om-dev-container-maintenance

Maintain the VS Code Dev Container setup for Open Mercato. MUST use for ANY change to `.devcontainer/` files. Also use when the container fails to build/start, services inside misbehave, or "works locally but not in dev container". Triggers on "dev container", "devcontainer", ".devcontainer".

1.50k repo starsObserved in 1 repos
DevOps & Security

om-prepare-test-env

Repo-local extension of the shared om-prepare-test-env skill. Adds this standalone Open Mercato app's environment specifics — the mercato CLI ephemeral runner commands, state-file semantics, readiness-probe contract, and the rule that generated entrypoint scripts stay machine-local — on top of the shared skill's workflow. Local rules win on repo specifics only; this file never relaxes the shared skill's safety rules.

1.50k repo starsObserved in 1 repos
DevOps & Security

spin-laravel-development

Develops, tests, and deploys Laravel applications using Spin and serversideup/php Docker images. Covers Docker Compose configuration, development environment setup, container commands, running Laravel tests (PHPUnit and Pest), SPIN_ENV selection and CI parity, parallel Compose environments, Laravel service configuration (databases, queues, Horizon, Reverb), server provisioning, and deployment workflows. Use when working with Spin, Docker Compose files, serversideup/php images, spin commands, running artisan test, configuring Laravel services in Docker, or deploying Laravel apps to production servers.

1.49k repo starsObserved in 1 repos
DevOps & Security

incident-investigation

Use this skill to diagnose and resolve production incidents in VoxBento.

1.48k repo starsObserved in 1 repos
DevOps & Security

post-dev-workflow

MANDATORY post-development workflow orchestrating validation, synchronization, and testing phases. Automatically invoked by AI agents after code changes. BLOCKING - work is incomplete without this.

1.48k repo starsObserved in 1 repos
DevOps & Security

livecodes/gh-action

Use the "Preview in LiveCodes" GitHub Action to generate preview playground links for pull request code changes. Automates playground creation and PR comments.

1.47k repo starsObserved in 1 repos
DevOps & Security

livecodes/self-hosting

Deploy LiveCodes to static servers, GitHub Pages, or Docker. Configure SDK appUrl, BASE_URL for subdirectories, and handle share/broadcast services. Load this skill when self-hosting LiveCodes or using a custom app URL.

1.47k repo starsObserved in 1 repos
DevOps & Security

release-workspace

Run the multi-crate workspace release process for metrics-rs/metrics: audit unreleased changes, plan version bumps and changelog entries, then execute per-crate (cargo-release publish + per-PR comments + S-awaiting-release label removal) with explicit gates between crates. Invoke with /release-workspace when the user asks to prepare/run a release, says "what's ready to release?", or wants to drain the S-awaiting-release queue.

1.46k repo starsObserved in 1 repos
DevOps & Security

platform-trust

Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction. Use for anything touching licenses, dependencies, tokens, or product surfaces.

1.46k repo starsObserved in 1 repos
DevOps & Security