Review CI/CD pipelines, runners, permissions, artifacts, caches, deployment gates, and token exposure.
Skills in this repository
domehahn/skil - Page 2
SkillsMP has collected 160 skills from domehahn/skil. Open a skill to review its source and details.
domehahn/skilShowing 40 of 160 collected skills.
Review cloud naming, tags, ownership, cost centers, allowed services, regions, data classification, policy enforcement, and audit evidence.
Review cloud accounts or subscriptions, networks, IAM, logging, policies, baselines, guardrails, encryption, tagging, and tenant separation.
Review governance controls such as CODEOWNERS, branch protection, approvals, auditability, and policy compliance.
Review Dockerfiles, base images, user rights, capabilities, SBOM, image signing, distroless or slim images, CVEs, and runtime hardening.
Map technical measures to DORA, VAIT or BAIT migration needs, ISO 27001, BSI, internal policies, or MaRisk review expectations.
Plan coding work with minimal context, relevant file selection, risk awareness, rollback, and validation strategy.
Review dependencies, lockfiles, package managers, container images, actions, and supply-chain risks.
Review setup, local development, error messages, Makefiles or scripts, onboarding, tooling consistency, and practicality for teams.
Assess maturity across plan, code, build, test, release, deploy, and operate with automation, security gates, ownership, and feedback loops.
Review documentation freshness, ownership, review cycles, approvals, versioning, validity, and traceability.
Create and update README files, ADRs, setup guides, API docs, runbooks, and operational documentation.
Review DORA readiness for ICT risk management, resilience testing, incidents, third-party risk, roles, policies, evidence, and auditability.
Create auditable evidence packages from tickets, pipeline results, test reports, approvals, scans, and architecture information.
Review cloud costs, budgets, rightsizing, reserved or committed usage, anomalies, showback or chargeback, and team cost transparency.
Review Argo CD or Flux setups, sync policies, drift detection, promotion, rollback, app-of-apps, secrets, cluster access, and deployment governance.
Review Terraform, Kubernetes, Helm, Kustomize, GitOps reconciliation, promotion, and environment safety.
Review ICT incident classification, escalation, documentation, reportability, timelines, responsibilities, templates, and communication chains.
Review ICT risks, protection needs, criticality, controls, residual risks, treatment, and recurring reassessment.
Review cloud, SaaS, outsourcing, subcontractors, contracts, exit strategies, concentration risks, and DORA information-register readiness.
Review IAM, roles, service accounts, groups, tokens, OIDC federation, GitLab or GitHub permissions, cloud rights, and privilege-escalation paths.
Support incident analysis, timeline creation, root cause analysis, impact assessment, corrective actions, and follow-up issues.
Review Kubernetes clusters, namespaces, RBAC, NetworkPolicies, Pod Security, admission controllers, resource limits, secrets, ingress, tenancy, and upgrades.
Review GenAI workloads for prompt injection, tool permissions, data exfiltration, RAG sources, sensitive prompt logging, evals, guardrails, and model access.
Review database migrations, schema changes, breaking changes, rollback ability, backward compatibility, and zero-downtime deployments.
Review model versioning, training data, bias, drift, monitoring, approvals, reproducibility, model registry, and deployment gates.
Review logging, metrics, tracing, health checks, alerts, dashboards, runbooks, and operational readiness.
Review backup and restore, failover, disaster recovery, restart procedures, crisis exercises, scenario tests, and lessons learned.
Review exit plans, data return, provider transitions, emergency operations, suboutsourcing, cloud dependencies, and business impact.
Review load behavior, bottlenecks, caching, database access, queue behavior, scaling, timeouts, and resource limits.
Design and review secure CI/CD pipelines with isolated runners, minimal rights, OIDC, signed artifacts, protected environments, and approval gates.
Create and review policies for OPA/Rego, Kyverno, GitLab Policies, Conftest, Checkov, Terraform, Kubernetes, and CI/CD gates.
Review GitLab Security Policies, OPA/Rego, Kyverno, Conftest, Sentinel, admission policies, compliance pipelines, and central guardrails.
Create and update policies, standards, procedures, and control descriptions.
Review privacy, personal data, data classification, deletion concepts, purpose limitation, GDPR risks, and sensitive-data logging.
Assess release readiness, rollback, migrations, feature flags, monitoring, documentation, and breaking changes.
Analyze requirements, user stories, acceptance criteria, constraints, risks, and open questions before implementation.
Review timeouts, retries, circuit breakers, failover, backpressure, degraded modes, and resilience behavior.
Document and assess conscious risk decisions, impact and likelihood, expiry dates, and compensating measures.
Create and review runbooks, operating instructions, incident playbooks, escalation paths, restart procedures, and checklists.