agentsclimarketplace

Review conf

Skill 3A2DEV/ansible-designer/skills/review-conf

Claude code ansible skill

Install
npx -y skills add 3A2DEV/ansible-designer --skill review-conf

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 5 stars5 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Review an ansible.cfg and produce a structured severity report grouped by CRITICAL, WARNING, and INFO. Triggered by /review-conf. Checks for deprecated settings, insecure values, missing critical sections, and vault misconfiguration. NEVER modifies files.

SKILL.md

5.5 KB, as published. Nobody here has run it

review-conf

Review an ansible.cfg and produce a structured severity report. This command never modifies files.


Required Inputs

  1. path to ansible.cfg — Resolved from discovery if not provided (checks ANSIBLE_CONFIG env, ./ansible.cfg, ~/.ansible.cfg, /etc/ansible/ansible.cfg in that order)

Behavior

Step 1 — Discovery

Run discovery per references/discovery.md. Locate the ansible.cfg. Report which file will be reviewed.

Step 2 — Load and Parse

Read and parse the ansible.cfg as an INI file. Identify all sections and key-value pairs.

Step 3 — Generate Severity Report

## ansible.cfg Review: <path>
Reviewed: <timestamp>
Sections found: <list>

---

### CRITICAL
[Critical issues]

### WARNING
[Warnings]

### INFO
[Informational notes]

---
Summary: <X> critical, <Y> warnings, <Z> info

Checks to Perform

CRITICAL

CheckConditionMessage
vault_password_file world-readablevault_password_file path exists and is readable by others (check permissions)[defaults] vault_password_file '<path>' may be world-readable — run: chmod 600 <path>
Inline vault passwordvault_identity_list contains an inline password (not a file path)[defaults] vault_identity_list contains what appears to be an inline password — use a file path instead
Deprecated accelerate[accelerate] section present (removed in ansible-core 2.12)[accelerate] Section removed in ansible-core 2.12 — remove this section entirely
forks extremely highforks > 200[defaults] forks=<N> is dangerously high — each fork uses ~100MB RAM, risking OOM on controller
log_path world-writablelog_path is set to a world-writable directory (e.g., /tmp/ansible.log without restriction)[defaults] log_path '<path>' is in a world-writable directory — logs may contain sensitive data

WARNING

CheckConditionMessage
host_key_checking=False without commenthost_key_checking = False with no inline comment justifying it[defaults] host_key_checking=False without justification comment — add a comment explaining the context (dev/CI/ephemeral runners)
Missing [privilege_escalation]become = True set in [defaults] but no [privilege_escalation] section[defaults] become=True is set but [privilege_escalation] section is absent — add the section for explicit configuration
Callbacks include awx_display manuallycallbacks_enabled contains awx_display[defaults] Do not add awx_display to callbacks_enabled — AWX injects it automatically and adding it causes duplicate output
fact_caching_connection has credentialsfact_caching_connection contains a password in the URL (redis://:password@...)[defaults] fact_caching_connection contains credentials in plaintext — use an environment variable or vault-encrypted value
stdout_callback=debugstdout_callback = debug[defaults] stdout_callback=debug produces very verbose output — use yaml or minimal for normal operation
retry_files_enabled=Trueretry_files_enabled = True (the default)[defaults] retry_files_enabled is True (default) — consider setting to False to reduce filesystem noise
Deprecated squash_actionssquash_actions key present[defaults] squash_actions was removed in ansible-core 2.8 — remove this setting
Deprecated any_errors_fatal at cfg levelany_errors_fatal in ansible.cfg (not a valid ansible.cfg setting)[defaults] any_errors_fatal belongs in playbooks, not ansible.cfg
Missing collections_pathlocal collections exist but no collection path is configured[defaults] ./collections/ directory exists but collections_path is not configured — add collections_path = ./collections
pipelining disabledpipelining = False or not set[ssh_connection] pipelining is disabled — enable it for significant performance improvement (requires Defaults:!requiretty in /etc/sudoers)

INFO

CheckConditionMessage
gathering=implicitgathering = implicit (not smart)[defaults] gathering=implicit re-gathers facts on every play — consider smart to use cached facts
forks at defaultforks not set or = 5[defaults] forks defaults to 5 — increase for large inventories (e.g., forks=20)
No fact caching configuredfact_caching not set[defaults] Fact caching not configured — consider jsonfile or redis for faster reruns
log_path not setlog_path absent[defaults] log_path not set — consider enabling for audit trail (rotate with logrotate)
No vault configNeither vault_password_file nor vault_identity_list is set[defaults] No vault configuration — add vault_password_file or vault_identity_list if using ansible-vault
control_persist not setcontrol_persist absent[ssh_connection] control_persist not set — add control_persist=60s for connection reuse

Constraints

  • Never modify files. This command is read-only.
  • Parse ansible.cfg as an INI file — do not attempt YAML parsing.
  • Report the section and key name for every finding.
  • Conclude with: "Use /ansible-designer:update-conf to apply fixes."

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.