14 issues created covering AGENTS.md refactor prerequisite, skill implementation workflow grill, bootstrap skills (write-eval, write-skill), remaining factory skills, and one issue per skill category group through to chunk closure. All HITL; acceptance criteria for 0017-0028 to be refined after 0016 grill session. Doc updates: CONTEXT.md PRD/issue scope clarified (HOW distribution across architecture-review and issue design notes); ROADMAP.md housekeeping updated with bootstrap order and issue range; spec/overview.md recent changes entry added; PRD updated (skills-index: delete → update). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2.4 KiB
2.4 KiB
0026 — IaC skills: write-docker-compose, iac-security-review
Type: HITL
Parent PRD: docs/prd/chunk-3-skills-library.md
What to build
The 2 IaC domain skills scoped for Chunk 3. Both are new. The 5 deferred IaC skills (Ansible, Molecule, Terraform, K8s, Proxmox) are explicitly out of scope. Authored via write-skill (0018), evals via write-eval (0017).
Skills and trigger descriptions:
| Flat name | Trigger description |
|---|---|
write-docker-compose |
Write Docker Compose, compose stack for X |
iac-security-review |
Security review this IaC, check Terraform/Ansible for issues |
Key constraints per skill:
write-docker-compose: pinned image versions; secrets via env vars (never hardcoded); healthchecks included on all servicesiac-security-review: checks — hardcoded secrets, overly permissive access, missing resource limits, unpinned versions, Terraform provisioners (HashiCorp designates these "last resort"; break idempotency), non-idempotent Ansible patterns (shell/command withoutcreates:guards, missingnotify, unconditional handlers)
Implementation notes
Follow the per-skill workflow defined in docs/notes/skill-implementation-workflow.md (produced by issue 0016).
Known upstream sources to review:
- Search GitHub and agentskills.io for open-source Docker Compose and IaC security review skills
- OWASP IaC security guidance for
iac-security-reviewchecklist - HashiCorp provisioner documentation (to understand and reference the "last resort" designation)
Acceptance criteria
- Both SKILL.md files exist at
.agents/skills/<skill-name>/SKILL.md;metadata.category: iac; authoring standard met write-docker-composedefaults to pinned versions, env-var secrets, and healthchecks without requiring the user to askiac-security-reviewcovers all listed check categories; non-idempotent Ansible patterns are explicitly enumeratedsource:fields populated for any adopted upstream content- Each skill has a co-located eval at
.agents/evals/iac/<skill-name>/eval.yamlviawrite-eval install.shdeploys both to~/.agents/skills/- HITL: human runs behavioral test per skill
- HITL: human reviews each SKILL.md and eval before committing
- (Further criteria to be refined after issue 0016 grill session)
Blocked by
- 0016 (per-skill workflow)
- 0017 (
write-eval) - 0018 (
write-skill)