All skills
acedergren avatar

/oci-security-control-plane

@d0e87b8

Use when the user asks to "choose OCI security control", "route OCI security issue", "compare Cloud Guard vs Security Zones", "decide ZPR vs NSG", or "use Bastion vs public SSH".

  • 1 file
  • 4.2 KB
  • Updated 4 months ago
  • GitHub

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/oci-security-control-plane

This session only. Nothing lands on disk.

SKILL.md

≈52 tokens always: the name and description. ≈916 when used: this file.

OCI Security Control Plane Router

Use this thin router to decide which OCI security control owns a problem. Keep detailed procedures in the specialist skills and load only the one needed for the user's control area.

When to Use

Load this skill for: the user asks to "choose OCI security control", "route OCI security issue", "compare Cloud Guard vs Security Zones", "decide ZPR vs NSG", "use Bastion vs public SSH", or "harden an OCI environment".

Use it before narrow skills when the control owner is unclear or the user lists several security controls together.

Do NOT load this skill when

Do not load this skill for a direct, already-known specialist task such as "write ZPL policy", "create Managed SSH", "store OCI secrets", "debug OCI 403", or "choose NSG vs security list". Load the owning skill directly.

NEVER Do This

NEVER duplicate specialist procedures in this router. Route to the owner skill and keep high-drift facts there.

NEVER enable broad responders, guardrails, or production ZPR attributes without a lower-environment test. Security controls can block traffic, API calls, deployments, or emergency access.

NEVER pick a control before identifying the failure plane. Decide whether the problem is API authorization, network reachability, packet authorization, secret handling, operator access, posture detection, preventive guardrails, audit evidence, or Terraform automation.

NEVER use public SSH as the default private-instance access answer. Route private operator access to oci/managed-bastion-access, VPN/FastConnect, or another approved private path.

Control Routing

Problem or hot word Load
Zero Trust Packet Routing, ZPR, security attributes, ZPL policy, protected resources oci/zpr-security
OCI Bastion, Managed SSH, port forwarding, dynamic SOCKS5, client CIDR allowlist oci/managed-bastion-access
IAM policy, identity domains, IDCS, dynamic groups, 403/404, principal type oci/iam-identity-management
Vault, KMS, secret rotation, replication, secret retrieval 403 oci/secrets-management
Cloud Guard, detector/responder recipes, Security Zones, landing-zone guardrails oci/landing-zones
NSGs, security lists, route tables, DRG, Service Gateway, DNS, private endpoints oci/networking-management
Audit, Logging, Service Connector, alarms, evidence collection oci/monitoring-operations
Terraform security automation, Resource Manager, state, imports, drift oci/infrastructure-as-code
Compute access posture, public IPs, instance principals, plugin state oci/compute-management

Decision Rules

  1. API denied or ambiguous 404: start with oci/iam-identity-management.
  2. Packet path blocked without ZPR: start with oci/networking-management.
  3. Packet path blocked after security attributes or ZPL change: start with oci/zpr-security.
  4. Human/operator access to private targets: start with oci/managed-bastion-access.
  5. Secret lifecycle or retrieval: start with oci/secrets-management.
  6. Preventive tenancy guardrails: start with oci/landing-zones.
  7. Detection, response, audit, and evidence: start with oci/monitoring-operations.
  8. Any of the above encoded in Terraform: also load oci/infrastructure-as-code.

Reference Files

This router intentionally has no deep reference file. Load the owning specialist skill and its focused references instead.

Arguments

$ARGUMENTS: Optional user-provided control, symptom, resource, compartment, network path, principal, Terraform path, or risk objective. When empty, classify the failure plane first, then load the owner skill.

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago
version
2.0.0
aliases
[
  "oci-security-router",
  "oracle-cloud-security"
]
domains
[
  "oci",
  "security"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "security control plane",
  "Cloud Guard",
  "Security Zones",
  "Zero Trust Packet Routing",
  "ZPR",
  "Bastion",
  "Vault",
  "KMS",
  "IAM",
  "Audit",
  "Logging",
  "NSG",
  "security list"
]

README badge

README badge for acedergren/agentic-tools/oci-security-control-plane