0026 — IaC skills: write-docker-compose, iac-security-review #45

Open
opened 2026-06-28 17:12:55 +00:00 by Claude · 0 comments
Collaborator

Type: HITL
Parent PRD: docs/prd/chunk-3-skills-library.md

What to build

The 2 IaC domain skills scoped for Chunk 3. Both are new. The 5 deferred IaC skills (Ansible, Molecule, Terraform, K8s, Proxmox) are explicitly out of scope. Authored via write-skill (0018), evals via write-eval (0017).

Skills and trigger descriptions:

Flat name Trigger description
write-docker-compose Write Docker Compose, compose stack for X
iac-security-review Security review this IaC, check Terraform/Ansible for issues

Key constraints per skill:

  • write-docker-compose: pinned image versions; secrets via env vars (never hardcoded); healthchecks included on all services
  • iac-security-review: checks — hardcoded secrets, overly permissive access, missing resource limits, unpinned versions, Terraform provisioners (HashiCorp designates these "last resort"; break idempotency), non-idempotent Ansible patterns (shell/command without creates: guards, missing notify, unconditional handlers)

Implementation notes

Follow the per-skill workflow defined in docs/notes/skill-implementation-workflow.md.

Known upstream sources to review:

  • Search GitHub and agentskills.io for open-source Docker Compose and IaC security review skills
  • OWASP IaC security guidance for iac-security-review checklist
  • HashiCorp provisioner documentation (to understand and reference the "last resort" designation)

Acceptance criteria

  • Both SKILL.md files exist at .agents/skills/<skill-name>/SKILL.md; metadata.category: iac; authoring standard met
  • write-docker-compose defaults to pinned versions, env-var secrets, and healthchecks without requiring the user to ask
  • iac-security-review covers all listed check categories; non-idempotent Ansible patterns are explicitly enumerated
  • source: fields populated for any adopted upstream content
  • Each skill has a co-located eval at .agents/evals/iac/<skill-name>/eval.yaml via write-eval
  • install.sh deploys both to ~/.agents/skills/
  • HITL: human runs behavioral test per skill
  • HITL: human reviews each SKILL.md and eval before committing
  • Per-skill process followed for both skills: source discovery → source review → conflict check → synthesis grill → co-write iteratively
  • Trigger description for each skill tested against explicit, implicit, and negative queries before body written
  • eval.yaml for each skill contains all 5 required test types
  • Body ≤500 lines for each skill
  • docs/spec/overview.md updated to reflect both skills deployed

Blocked by

  • 0016 (per-skill workflow)
  • 0017 (write-eval)
  • 0018 (write-skill)
**Type:** HITL **Parent PRD:** `docs/prd/chunk-3-skills-library.md` ## What to build The 2 IaC domain skills scoped for Chunk 3. Both are new. The 5 deferred IaC skills (Ansible, Molecule, Terraform, K8s, Proxmox) are explicitly out of scope. Authored via `write-skill` (0018), evals via `write-eval` (0017). **Skills and trigger descriptions:** | Flat name | Trigger description | |---|---| | `write-docker-compose` | Write Docker Compose, compose stack for X | | `iac-security-review` | Security review this IaC, check Terraform/Ansible for issues | **Key constraints per skill:** - `write-docker-compose`: pinned image versions; secrets via env vars (never hardcoded); healthchecks included on all services - `iac-security-review`: checks — hardcoded secrets, overly permissive access, missing resource limits, unpinned versions, Terraform provisioners (HashiCorp designates these "last resort"; break idempotency), non-idempotent Ansible patterns (shell/command without `creates:` guards, missing `notify`, unconditional handlers) ## Implementation notes Follow the per-skill workflow defined in `docs/notes/skill-implementation-workflow.md`. **Known upstream sources to review:** - Search GitHub and agentskills.io for open-source Docker Compose and IaC security review skills - OWASP IaC security guidance for `iac-security-review` checklist - HashiCorp provisioner documentation (to understand and reference the "last resort" designation) ## Acceptance criteria - [ ] Both SKILL.md files exist at `.agents/skills/<skill-name>/SKILL.md`; `metadata.category: iac`; authoring standard met - [ ] `write-docker-compose` defaults to pinned versions, env-var secrets, and healthchecks without requiring the user to ask - [ ] `iac-security-review` covers all listed check categories; non-idempotent Ansible patterns are explicitly enumerated - [ ] `source:` fields populated for any adopted upstream content - [ ] Each skill has a co-located eval at `.agents/evals/iac/<skill-name>/eval.yaml` via `write-eval` - [ ] `install.sh` deploys both to `~/.agents/skills/` - [ ] **HITL:** human runs behavioral test per skill - [ ] **HITL:** human reviews each SKILL.md and eval before committing - [ ] Per-skill process followed for both skills: source discovery → source review → conflict check → synthesis grill → co-write iteratively - [ ] Trigger description for each skill tested against explicit, implicit, and negative queries before body written - [ ] eval.yaml for each skill contains all 5 required test types - [ ] Body ≤500 lines for each skill - [ ] `docs/spec/overview.md` updated to reflect both skills deployed ## Blocked by - 0016 (per-skill workflow) - 0017 (`write-eval`) - 0018 (`write-skill`)
Claude added this to the Legacy / Triage milestone 2026-06-28 17:12:55 +00:00
Claude added the Kind/Feature
Priority
Medium
3
labels 2026-06-28 17:12:55 +00:00
Claude modified the milestone from Legacy / Triage to Skills & Agents 2026-06-28 19:26:53 +00:00
Sign in to join this conversation.