agentsclimarketplace

Infra review

Skill yarlson/yarstack/plugins/yarstack/skills/infra-review

Engineering workflows and standards for Codex and Claude Code: plan, implement, test, review, and deliver repository changes.

Install
npx -y skills add yarlson/yarstack --skill infra-review

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 3 stars3 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Review infrastructure-as-code and rendered deployment configuration without modifying it. Use before plan, apply, or deploy when targeting, replacement, state, availability, cost, ordering, or recovery blast radius may change.

SKILL.md

1.8 KB, as published. Nobody here has run it

Infrastructure Review

Own pre-deployment infrastructure blast-radius analysis using non-mutating evidence.

Workflow

  1. Confirm the comparison target, source-to-rendered path, tooling, and affected environment using safe redacted identifiers.
  2. Rank changed resources by blast radius and inspect full definitions and dependency ordering.
  3. Check targeting, replacement or destruction, state and migration safety, data protection, partial-apply recovery, availability, disruption, capacity, and material cost.
  4. Verify provider or tool semantics from local versions or authoritative sources before claiming replacement or destruction.
  5. Run only trusted repository-supported non-mutating plan, render, diff, or dry-run checks when authorized.
  6. Delegate exploit analysis to security-review, dependency provenance to dependency-review, CI mechanics to ci-review, and cross-cutting runtime readiness to rollout-readiness-review.

Report severity, exact location, redacted environment reference, concrete blast radius, failure path, smallest correction, evidence, and uncertainty. Describe confirmed public exposure, privilege escalation, secret leakage, unprotected destruction, unsafe state migration, or missing recovery as blocking findings; do not claim authority to block an operation.

Never apply, deploy, install, upgrade, delete, destroy, or modify cloud state. Do not expose sensitive plan output or add policy frameworks merely for the review.

Finish with findings or no-findings, scope, destructive effects, cost impact, checks, and confidence limits.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.