agentsclimarketplace

Complete infra

Skill makigjuro/cloudstack-ai-plugins/plugins/cloud-infra/skills/complete-infra

Complete infrastructure task — lint, validate, review, and submit PR. Use when an infrastructure-only branch is ready for submission — runs Terraform/Helm validation and creates the PR, skipping application/frontend checks.From its SKILL.md

Install
npx -y skills add makigjuro/cloudstack-ai-plugins --skill complete-infra

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
  • runs commandsInstructs the agent to run 8 commands, including `BRANCH=$(git branch --show-current)` and 7 more.

SKILL.md

4.4 KB, ~1.1k tokens by cl100k_base, as published. Nobody here has run it

Complete Infrastructure Task

Finalize an infrastructure branch by running infra-specific quality gates and creating a PR. This is the infra equivalent of a full completion workflow — it skips application build/tests and frontend lint.

Prerequisites

  • You must be on a feature branch (not main)
  • All infrastructure changes should be committed
  • Working tree should be clean

Arguments

  • {issue} — GitHub issue number (optional). If not provided, extract from branch name.

Configuration

Read cloudstack.json from the project root at the start of execution. Extract:

  • CHARTS_PATH = infrastructure.chartsPath (default: deploy/charts)
  • TF_PATH = infrastructure.terraformPath (default: infra/terraform/modules)
  • TG_PATH = infrastructure.terragruntPath (default: infra/terragrunt)
  • IAC_WRAPPER = infrastructure.iacWrapper (default: none)

If cloudstack.json does not exist, auto-detect by scanning the project structure. Derive TF_PARENT as the parent directory of TF_PATH.

Scripts

Reusable bash scripts live in scripts/ relative to this skill directory:

ScriptPurpose
scripts/validate-terraform.shValidate changed Terraform modules
scripts/lint-helm.shLint changed Helm charts

These scripts read TF_PATH and CHARTS_PATH from environment variables. Export them before calling:

export TF_PATH="..." CHARTS_PATH="..."

The security scan (Track D below) reuses the script from the trivy-scan skill rather than duplicating it:

bash {plugin-skills-path}/trivy-scan/scripts/scan-trivy.sh

Process

Phase 0: Pre-flight

Run pre-flight checks inline (or source the shared preflight script if available):

BRANCH=$(git branch --show-current)
if [ "$BRANCH" = "main" ] || [ "$BRANCH" = "master" ]; then
  echo "ERROR: Cannot complete task on main branch"
  exit 1
fi
if [ -n "$(git status --porcelain)" ]; then
  echo "ERROR: Working tree is dirty. Commit or stash changes first."
  exit 1
fi
ISSUE=$(echo "$BRANCH" | grep -oE '/[0-9]+' | tr -d '/' || true)
echo "Branch: $BRANCH"
echo "Issue:  ${ISSUE:-<none>}"

Phase 1: Parallel Infrastructure Lint

Launch all lint tracks in parallel using separate Bash tool calls in a single response.

Track A: Terraform format check

terraform fmt -check -recursive {TF_PARENT}

Track B: Terraform validate (changed modules only)

export TF_PATH="{TF_PATH}"
bash {plugin-skills-path}/complete-infra/scripts/validate-terraform.sh

Track C: Helm lint (if charts changed)

export CHARTS_PATH="{CHARTS_PATH}"
bash {plugin-skills-path}/complete-infra/scripts/lint-helm.sh

Track D: Security scan (trivy)

export TF_PARENT="{TF_PARENT}" CHARTS_PATH="{CHARTS_PATH}"
bash {plugin-skills-path}/trivy-scan/scripts/scan-trivy.sh

Honours .trivyignore at {TF_PARENT}/.trivyignore. Every suppression must carry a justifying comment — see the trivy-scan skill for conventions.

If any lint or scan track fails, STOP and report. Treat trivy missing as a FAIL and print the install hint so the user can remediate.

Phase 2: Infrastructure Review (Parallel Agents)

Launch the review agent with worktree isolation:

Agent: infra-reviewer (isolation: worktree) — Dedicated Terraform/Helm/CI review using the infra-reviewer agent definition. Reviews git diff origin/main...HEAD -- {TF_PARENT}/ {CHARTS_PATH}/ .github/workflows/ and returns PASS/FAIL with findings covering security, naming, resource limits, and CI best practices.

Phase 3: Evaluate

If review passes: Proceed to Phase 4.

If issues found:

  1. Display findings
  2. Fix issues (max 3 iterations)
  3. Re-run from Phase 1

Phase 4: Create PR

Run /create-pr {issue}.

Output

## Infrastructure Task Completed

- Branch: {branch}
- Issue: #{issue}
- PR: {pr-url}

### Quality Gates
- Terraform Format: PASS
- Terraform Validate: PASS
- Helm Lint: PASS / SKIP (no chart changes)
- Security Scan (trivy): PASS / WARN (findings in .trivyignore only) / FAIL
- Infra Review: PASS

PR is ready for human review.

What ships with it: 2 files

2.0 KB alongside SKILL.md, 2 of them executable

scripts/

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.