All skills
simota avatar

/scaffold

@e307415
by shingo imotasimota/agent-skills85 stars
15

Provisioning infrastructure via cloud IaC (Terraform/OpenTofu/CloudFormation/Pulumi) and local dev environments (Docker Compose, env vars). Use for IaC design or multi-cloud provisioning.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/scaffold

This session only. Nothing lands on disk.

referencesecurity-and-cost.md

≈702 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security And Environment Patterns

Purpose: Use this file when the task involves secrets, IAM, network controls, .env templates, or environment validation.

Contents:

  1. Secrets strategy
  2. IAM least privilege
  3. Network guardrails
  4. Pre-commit hooks
  5. .env.example
  6. Zod validation

Secrets Strategy

Approach Use when Notes
.env (gitignored) Local development only never commit
Cloud Secrets Manager Staging and production preferred for secrets
Parameter Store Non-sensitive runtime config lighter-weight option
Vault Enterprise / multi-cloud centralized secret lifecycle

Terraform pattern:

data "aws_secretsmanager_secret_version" "db_password" {
  secret_id = "/${var.project_name}/${var.environment}/db-password"
}

resource "aws_db_instance" "main" {
  password = data.aws_secretsmanager_secret_version.db_password.secret_string
}

IAM Least Privilege

  • Scope actions and resources narrowly.
  • Prefer roles or workload identity over long-lived keys.
  • Separate service accounts/roles per workload.
  • Enforce MFA or equivalent admin controls where applicable.

Network Guardrails

  • Prefer security-group-to-security-group rules over wide CIDR rules.
  • Default outbound should be explicit where the platform allows it.
  • Treat 0.0.0.0/0 as an exception requiring justification and policy review.

Example:

ingress {
  from_port       = var.app_port
  to_port         = var.app_port
  protocol        = "tcp"
  security_groups = [aws_security_group.alb.id]
}

Pre-Commit Hooks

repos:
  - repo: https://github.com/antonbabenko/pre-commit-terraform
    rev: v1.86.0
    hooks:
      - id: terraform_fmt
      - id: terraform_validate
      - id: terraform_tflint

  - repo: https://github.com/bridgecrewio/checkov
    rev: 3.1.0
    hooks:
      - id: checkov

  - repo: https://github.com/gitleaks/gitleaks
    rev: v8.18.0
    hooks:
      - id: gitleaks

.env.example

NODE_ENV=development
PORT=3000
APP_URL=http://localhost:3000
DATABASE_URL=postgresql://user:password@localhost:5432/app_dev
REDIS_URL=redis://localhost:6379
JWT_SECRET=REPLACE_WITH_SECURE_SECRET
SESSION_SECRET=REPLACE_WITH_SECURE_SECRET
FEATURE_NEW_UI=false
LOG_LEVEL=debug

Zod Validation

export const envSchema = z.object({
  NODE_ENV: z.enum(['development', 'staging', 'production']).default('development'),
  PORT: z.coerce.number().default(3000),
  APP_URL: z.string().url(),
  DATABASE_URL: z.string().url(),
  REDIS_URL: z.string().url().optional(),
  JWT_SECRET: z.string().min(32),
  SESSION_SECRET: z.string().min(32),
  FEATURE_NEW_UI: z.coerce.boolean().default(false),
  LOG_LEVEL: z.enum(['error', 'warn', 'info', 'debug']).default('info'),
});

Source: SKILL.md on GitHub

1 warning13d5 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a comprehensive infrastructure provisioning assistant that follows security best practices for IaC. It has an inherent attack surface for indirect prompt injection as it processes external requirements to generate code, and it involves the dynamic generation of infrastructure scripts.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

  • Runlayer6mo

    5/14 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e307415. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/scaffold