Replaces shell script (.git/hooks/pre-commit.legacy) with ecosystem-managed pre-commit framework: - gitleaks/gitleaks: secret scanning - jumanjihouse/pre-commit-hooks: shellcheck wrapper - pre-commit/pre-commit-hooks: JSON/YAML validation, end-of-file-fixer, trailing-whitespace - local hooks: SKILL.md frontmatter validation Uses pinned versions for reproducibility across environments. Includes auto-fixes from hook runs (formatting, trailing whitespace, JSON beautification). Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
3.0 KiB
3.0 KiB
0026 — IaC skills: write-docker-compose, iac-security-review
Type: HITL
Parent PRD: docs/prd/chunk-3-skills-library.md
What to build
The 2 IaC domain skills scoped for Chunk 3. Both are new. The 5 deferred IaC skills (Ansible, Molecule, Terraform, K8s, Proxmox) are explicitly out of scope. Authored via write-skill (0018), evals via write-eval (0017).
Skills and trigger descriptions:
| Flat name | Trigger description |
|---|---|
write-docker-compose |
Write Docker Compose, compose stack for X |
iac-security-review |
Security review this IaC, check Terraform/Ansible for issues |
Key constraints per skill:
write-docker-compose: pinned image versions; secrets via env vars (never hardcoded); healthchecks included on all servicesiac-security-review: checks — hardcoded secrets, overly permissive access, missing resource limits, unpinned versions, Terraform provisioners (HashiCorp designates these "last resort"; break idempotency), non-idempotent Ansible patterns (shell/command withoutcreates:guards, missingnotify, unconditional handlers)
Implementation notes
Follow the per-skill workflow defined in docs/notes/skill-implementation-workflow.md.
Known upstream sources to review:
- Search GitHub and agentskills.io for open-source Docker Compose and IaC security review skills
- OWASP IaC security guidance for
iac-security-reviewchecklist - HashiCorp provisioner documentation (to understand and reference the "last resort" designation)
Acceptance criteria
- Both SKILL.md files exist at
.agents/skills/<skill-name>/SKILL.md;metadata.category: iac; authoring standard met write-docker-composedefaults to pinned versions, env-var secrets, and healthchecks without requiring the user to askiac-security-reviewcovers all listed check categories; non-idempotent Ansible patterns are explicitly enumeratedsource:fields populated for any adopted upstream content- Each skill has a co-located eval at
.agents/evals/iac/<skill-name>/eval.yamlviawrite-eval install.shdeploys both to~/.agents/skills/- HITL: human runs behavioral test per skill
- HITL: human reviews each SKILL.md and eval before committing
- Per-skill process followed for both skills: source discovery (sub-agent) → source review with licence/security check (sub-agent) → conflict check against constitution + factory principles (sub-agent) → synthesis grill → co-write iteratively
- Trigger description for each skill tested against explicit, implicit, and negative queries before body written
when:frontmatter field present in both SKILL.md filessource:andreferences:fields correctly populated or absent- eval.yaml for each skill contains all 5 required test types
- Body ≤500 lines for each skill
docs/spec/overview.mdupdated to reflect both skills deployed
Blocked by
- 0016 (per-skill workflow)
- 0017 (
write-eval) - 0018 (
write-skill)