All skills

Use when the user asks to "find OCI skills", "route Oracle Cloud work", "install the OCI skill pack", "review OCI skill ownership", or "separate Oracle skills".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/oci

This session only. Nothing lands on disk.

best-practicesreferencesoci-well-architected-checklist.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Well-Architected Framework Checklist

Five Pillars Overview

Pillar 1: Security and Compliance

Focus Area Best Practice CLI Verification
User Authentication Enable MFA for all IAM users oci iam user list --query "data[?\"is-mfa-activated\"==\false`]"`
Authorization Use least privilege policies Review policies for all-resources or any-user
Data Encryption Enable encryption at rest oci vault secret list --compartment-id <id>
Network Security Use NSGs over Security Lists oci network nsg list --compartment-id <id>
Audit Logging Enable audit logs for all compartments oci audit event list --compartment-id <id>

Pillar 2: Reliability and Resilience

Focus Area Best Practice CLI Verification
High Availability Deploy across multiple ADs Check instance distribution
Backup Strategy Configure automatic backups oci bv backup list --compartment-id <id>
Disaster Recovery Set up cross-region replication oci os replication list-replication-policies --bucket-name <bucket>
Load Balancing Use regional load balancers oci lb load-balancer list --compartment-id <id>

Pillar 3: Performance and Cost Optimization

Focus Area Best Practice CLI Verification
Right-Sizing Match instance shapes to workload Review CPU/Memory utilization metrics
Reserved Capacity Use committed pricing for predictable workloads oci limits value list
Storage Tiers Use appropriate storage classes Check for overprovisioned volumes
Networking Use Service Gateway for OCI services oci network service-gateway list

Pillar 4: Operational Efficiency

Focus Area Best Practice CLI Verification
Infrastructure as Code Use Terraform for all resources Check for Resource Manager stacks
Monitoring Set up alarms for critical metrics oci monitoring alarm list --compartment-id <id>
Automation Use OCI Events for automation oci events rule list --compartment-id <id>
Tagging Implement mandatory tagging oci iam tag-namespace list --compartment-id <id>

Pillar 5: Distributed Cloud

Focus Area Best Practice CLI Verification
Multi-Region Deploy critical workloads in multiple regions Review region distribution
Hybrid Cloud Use FastConnect for on-premises connectivity oci network fast-connect-provider-service list
Edge Use Content Delivery for global distribution Check CDN configurations

CIS OCI Foundations Benchmark Controls

Identity and Access Management

# 1.1 Ensure MFA is enabled for all users
oci iam user list --all --query "data[?\"is-mfa-activated\"==\`false\`].{Name:name,OCID:id}"

# 1.2 Ensure API keys rotate every 90 days
oci iam user api-key list --user-id <user-ocid> --query "data[?\"time-created\" < '\`date -v-90d +%Y-%m-%dT%H:%M:%S\`']"

# 1.3 Ensure no policies use "any-user"
oci iam policy list --compartment-id <tenancy-ocid> --all --query "data[?contains(statements[],'any-user')]"

Networking

# 2.1 Ensure no security lists allow 0.0.0.0/0 ingress
oci network security-list list --compartment-id <id> --all --query "data[].{Name:\"display-name\",Rules:\"ingress-security-rules\"[?source=='0.0.0.0/0']}"

# 2.2 Ensure VCN flow logs are enabled (flow logs are Logging service logs, source service "flowlogs")
oci logging log list --log-group-id <log-group-id> --source-service flowlogs --all

# 2.3 Ensure Service Gateway is used for OCI services
oci network service-gateway list --compartment-id <id>

Logging and Monitoring

# 3.1 Ensure Audit Log retention is at least 365 days
# Audit logs are retained for 365 days by default and cannot be changed

# 3.2 Ensure Cloud Guard is enabled
oci cloud-guard target list --compartment-id <tenancy-ocid>

# 3.3 Ensure VCN Flow Logs are enabled for all subnets
oci network subnet list --compartment-id <id> --query "data[?!\"vcn-id\"]"

Storage

# 4.1 Ensure Object Storage buckets are not public
oci os bucket list --compartment-id <id> --query "data[?\"public-access-type\"!='NoPublicAccess']"

# 4.2 Ensure boot volumes are encrypted with Customer-Managed Keys
oci bv boot-volume list --compartment-id <id> --query "data[?!\"kms-key-id\"]"

# 4.3 Ensure block volumes are encrypted with Customer-Managed Keys
oci bv volume list --compartment-id <id> --query "data[?!\"kms-key-id\"]"

Quick Compliance Check Script

#!/bin/bash
# OCI Quick Compliance Check
COMPARTMENT_ID="$1"

echo "=== Security Checks ==="
echo "Public buckets:"
oci os bucket list --compartment-id $COMPARTMENT_ID --query "data[?\"public-access-type\"!='NoPublicAccess'].name" --output table

echo "Security lists with 0.0.0.0/0:"
oci network security-list list --compartment-id $COMPARTMENT_ID --all --query "data[].{Name:\"display-name\"}" --output table

echo "=== Reliability Checks ==="
echo "Instances without backups:"
# Compare instance list with backup list

echo "=== Cost Checks ==="
echo "Stopped instances (still incurring boot volume cost):"
oci compute instance list --compartment-id $COMPARTMENT_ID --lifecycle-state STOPPED --query "data[].{Name:\"display-name\",Shape:shape}" --output table

Remediation Priority Matrix

Finding Impact Effort Priority
Public S3 bucket Critical Low P0 - Fix immediately
No MFA enabled High Low P1 - Fix within 24h
Open 22/3389 to 0.0.0.0/0 High Low P1 - Fix within 24h
No encryption at rest High Medium P2 - Fix within 1 week
No backups configured Medium Low P2 - Fix within 1 week
Missing tags Low Low P3 - Fix within 1 month
Over-provisioned instances Low Medium P3 - Fix within 1 month

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub3mo

    An expert-level OCI utility pack that includes advanced scripts for presentation management and database administration. Security concerns include runtime compilation of C shims for system call interception and a powerful SQL script for tenancy-wide security remediation. The skill also ingests untrusted data from document archives and web headers, creating a surface for indirect prompt injection.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago
version
1.0.0
aliases
[
  "oci-skills",
  "oracle-skills",
  "oci-skill-pack"
]
domains
[
  "oci",
  "oracle",
  "skill-pack"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Oracle",
  "skill pack",
  "skill routing",
  "separation of duties",
  "ownership",
  "architecture",
  "operations",
  "manifest"
]

README badge

README badge for acedergren/agentic-tools/oci