claudeers.
// DevOps & CI/CD

vanguard-frontier-agentic

Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance-aware engineering - works with Claude Code, Codex, Cursor, Copilot,…

Actively maintained
100/100
last commit 8 days ago
last release 8 days ago
releases 63
open issues 0

Install with your AI

Paste into Claude Code, Cursor, or any agent — it reads the repo and wires the tool into your project.

Install and set up vanguard-frontier-agentic (claude-plugin project) into my current project.
Found on https://claudeers.com/vanguard-frontier-agentic
Repo: https://github.com/VincentChuWaiChow/vanguard-frontier-agentic
Homepage/docs: —
Detected install method: claude-plugin → /plugin install vanguard-frontier-agentic@VincentChuWaiChow/vanguard-frontier-agentic
Category: devops. Platforms: cli, api, web, mobile.
Read the repo's README for exact setup and env vars, then install it and wire it into my project.

Claudeers Health Verdict:
active; community-verified: false. Confirm the source before running anything.
// or install directly (claude-plugin)
/plugin marketplace add VincentChuWaiChow/vanguard-frontier-agentic
/plugin install vanguard-frontier-agentic@VincentChuWaiChow/vanguard-frontier-agentic
// or clone
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic

// compatibility

Platformscli, api, web, mobile
Operating systems
AI compatibilityclaude
LicenseApache-2.0
Pricingopen-source
LanguageRust

Vanguard Frontier Agentic

Vanguard Frontier Agentic

The vanguard frontier of the agentic world — an enterprise-grade ecosystem for AI agents at scale.

Agentic coordination, routing, protocol, and escalation for high-stakes environments. Battle-hardened. Audit-ready by design.

OpenSSF Scorecard OpenSSF Best Practices OpenSSF Baseline

Why Vanguard Frontier  ·  What's Inside  ·  Get Started  ·  Install Reference  ·  Skills  ·  Agents  ·  Issues  ·  FAQ  ·  Feedback  ·  Contributing  ·  Security  ·  Code of Conduct


This is the edge of agentic intelligence — an enterprise-grade ecosystem for running AI agents at scale in environments where a wrong move is a board-level incident. It collects reusable skills, agents, rules, MCP references, and supporting assets for AWS, Azure, OCI, GCP, Alibaba Cloud, Huawei Cloud, Kubernetes, and Terraform — plus cross-functional Legal, HR, Marketing, Salesforce, .NET, Java, Kotlin, PHP, Python, FinOps, Accounting, Finance, Oracle NetSuite ERP, SAP S/4HANA + BTP ERP, Microsoft 365 / Dynamics 365, and Azure-ecosystem Databricks and Snowflake data-platform agentic ecosystems.

This is not just cloud infrastructure tooling. It is agentic coordination: maestro routing, escalation-aware protocol, structured handoff between specialists, and refusal-by-default safety on every irreversible action. Cloud is one domain it operates in. Coordination, governance, and escalation are the product.

📊 Catalog at a glance

CatalogCount
Skills689
Agents666
Providers44
Install roles56
Rules1
MCP references3
  • 🧠 Skills = step-by-step workflows an AI assistant can follow.
  • 🤖 Agents = reusable expert roles for review, architecture, and operations.
  • 📏 Rules = durable instructions for a specific AI harness.
  • 🔌 MCP references = trusted notes for connecting tools to real systems.
  • 🗂️ Catalogs = machine-readable indexes so tools can discover everything.

Works with: Claude Code  ·  Codex  ·  GitHub Copilot  ·  Cursor  ·  Gemini CLI  ·  Kiro  ·  and any other coding agent.

📦 Available on npm: @raishin/vanguard-frontier-agentic is published on the public npm registry.

[!IMPORTANT] 🔁 The GitHub owner changed — the npm package name did not. Both are true at once: this repository moved from Raishin/vanguard-frontier-agentic to VincentChuWaiChow/vanguard-frontier-agentic when the account was renamed, but the npm scope did not move with it.

What changedWhat did NOT change
GitHub owner → VincentChuWaiChownpm package name → still @raishin/vanguard-frontier-agentic

GitHub redirects the old URLs, so existing clones and links keep working, but update your git remote and any pinned marketplace source when convenient.

The npm package is still @raishin/vanguard-frontier-agenticnpm install @raishin/vanguard-frontier-agentic@latest is unchanged, and no republish under a new name is planned. An npm scope is a separate namespace from a GitHub account: renaming the account does not rename the scope, and renaming the scope would break every existing install. Treat @raishin/… in install commands, .npmrc registry config, and packed tarball names as correct, not as a leftover.

⚠️ ALPHA FINOPS BUNDLE: As of v1.8.0, this package includes 4 new experimental FinOps agents and 7 skills for cloud cost optimization, AI economics modeling, Kubernetes rightsizing, and FOCUS-spec normalization. All are marked lifecycle: experimental. See the board readiness memo for known limitations, risk mitigation, and 30-day diligence closure requirements. Use at your own risk in pre-production environments. Production deployment requires signed design-partner SOWs, Big 4 accounting validation, and SOC 2 Type II observation (≥150 days).


🛰️ Why Vanguard Frontier?

"Vanguard frontier" is not branding — it is an operating posture. This ecosystem is built for the front line of agentic deployment, where AI agents touch real production systems, real regulated data, and real legal exposure.

  • 🏛️ Built for Fortune 50 / high-stakes environments. Every agent assumes the blast radius is enterprise-scale: regulated data, audited controls, and decisions that survive legal discovery. Refusal-by-default beats a fast path to a board-level incident.
  • ⚖️ The Legal + HR ecosystem is proof of cross-functional agentic coordination. 28 specialist agents (Legal maestro + 12 specialists, HR maestro + 14 specialists) and 3 cross-functional protocol skills demonstrate that agents can hand off, escalate, and coordinate across organizational boundaries — not just answer in isolation.
  • 🧾 Audit-ready, privacy-preserving, escalation-aware by design. Every review and live-guard agent emits a structured verdict (verdict, evidence_level, blockers, safe_next_actions, open_questions) that maps directly to SOC 2, PCI DSS, NIS2, NIST CSF, and ISO 27001 — no post-processing.
  • 🛡️ Battle-tested against real compliance, governance, and risk workflows. These patterns are exercised against live IAM mutations, KMS destruction, litigation holds, RIF planning, and privacy reviews — the workflows where a generic agent gets an organization sued.

The bar: an auditor, a regulator, or opposing counsel should be able to read the agent's output and trace exactly who decided what, on what evidence, and who approved the risk.


🧱 What's Inside — the three-layer agentic architecture

Vanguard Frontier is not a flat bag of prompts. It is a deliberate three-layer system, and every domain — cloud providers, Kubernetes, marketing, Legal, HR — follows the same shape.

LayerRoleExamples
1. 🧭 Maestro (router)Entry point. Classifies the request, routes to the right specialist, never executes risk itself.legal-maestro-agent, hr-maestro-agent, kubernetes-maestro-agent, provider maestros
2. 🤖 SpecialistsDomain experts with judgment and a hardened permission model. Each loads one companion skill and emits a guarded verdict.13 Legal specialists, 15 HR specialists, cloud advisory + live-guard operators
3. 🔗 Cross-functional protocolShared contracts that let specialists hand off, escalate, and coordinate across organizational boundaries without leaking scope.legal-hr-routing-protocol, legal-hr-case-capsule, legal-hr-risk-taxonomy

How it flows: a request enters at the maestro, which routes to a specialist. When a matter crosses a boundary — an HR investigation that needs privileged Legal review, or a Legal hold that triggers an HR data freeze — the cross-functional protocol carries a structured case capsule between agents, preserving privilege, minimizing data, and recording the escalation path.

This is what "agentic coordination" means here: routing, protocol, and escalation are first-class, not improvised.


🚀 Get Started

Pick the install path for your coding agent. Each dropdown is crystal-clear, step-by-step, and one-click plug-and-play where the harness supports it; the npm/export path works for everything else.

At a glance — which path is yours:

Your harnessFastest pathOne-liner
🤖 Claude CodePlugin marketplace/plugin marketplace add VincentChuWaiChow/vanguard-frontier-agentic
🐙 GitHub Copilot CLIPlugin marketplacecopilot plugin marketplace add VincentChuWaiChow/vanguard-frontier-agentic
🖱️ CursorClone + register plugin dirgit clone … then Settings → Plugins → Add Plugin Directory
⚡ CodexPlugin marketplacecodex plugin marketplace add VincentChuWaiChow/vanguard-frontier-agentic
♊ Gemini / Antigravitynpm exportnpx vfa-export-agents --platform gemini --all --repo .
🔮 KiroAdd Powers per-directoryPowers panel → Add Custom Power → Local Directory
📦 Any othernpm + vfa-export-agents CLInpm install @raishin/vanguard-frontier-agentic@latest

Expand the matching dropdown below for the full step-by-step.

🤖 Claude Code (Anthropic)  —  one-command plugin install
/plugin marketplace add VincentChuWaiChow/vanguard-frontier-agentic
/plugin install vanguard-frontier-agentic@vanguard-frontier-agentic

Or wire it into ~/.claude/settings.json (or your project's .claude/settings.json) for team-wide trust:

{
  "extraKnownMarketplaces": {
    "vanguard-frontier-agentic": {
      "source": { "source": "github", "repo": "VincentChuWaiChow/vanguard-frontier-agentic" }
    }
  },
  "enabledPlugins": {
    "vanguard-frontier-agentic@vanguard-frontier-agentic": true
  }
}

Pin to a tag for reproducible installs: pick any released tag for stable versions, or use @latest for the current release.

🐙 GitHub Copilot CLI  —  one-command marketplace install
# Add the marketplace, then install
copilot plugin marketplace add VincentChuWaiChow/vanguard-frontier-agentic
/plugin install vanguard-frontier-agentic

Or in .github/copilot/settings.json for repo-wide trust:

{
  "extraKnownMarketplaces": [
    "https://raw.githubusercontent.com/VincentChuWaiChow/vanguard-frontier-agentic/master/.github/plugin/marketplace.json"
  ]
}
  • Marketplace manifest: .github/plugin/marketplace.json declares this repo as a single-plugin marketplace
  • Source path: ./ (the repo root is the plugin root)
  • Bundled: 666 Copilot agent adapters under agents/<provider>/<agent>/harnesses/copilot.agent.md
  • Docs: github.com/github/copilot-cli (/plugin marketplace add)
🖱️ Cursor  —  plugin manifest at repo root
# Clone the repo, then register it as a plugin directory in Cursor:
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic

In Cursor: Settings → Plugins → Add Plugin Directory → pick the cloned repo path. Or via the Cursor Extension API:

vscode.cursor.plugins.registerPath("/absolute/path/to/vanguard-frontier-agentic");
🔮 Kiro (Powers + agents)  —  42 ready-to-add Powers

Kiro Powers UI is per-Power directory add — there is no single-command marketplace flow. This repo ships 42 Powers under powers/, one per provider, so Kiro users can add only what they need.

# 1. Clone this repo
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic
cd vanguard-frontier-agentic

# 2. In Kiro:
#    Open the Powers panel → "Add Custom Power" → "Local Directory"
#    Paste the absolute path to the Power(s) you need, one at a time:
#       /absolute/path/to/vanguard-frontier-agentic/powers/vanguard-aws
#       /absolute/path/to/vanguard-frontier-agentic/powers/vanguard-kubernetes
#       /absolute/path/to/vanguard-frontier-agentic/powers/vanguard-terraform
  • Powers available: vanguard-accounting, vanguard-alibaba, vanguard-argocd, vanguard-aws, vanguard-azure, vanguard-backstage, vanguard-cert-manager, vanguard-cilium, vanguard-contabo, vanguard-databricks, vanguard-dotnet, vanguard-falco, vanguard-finance, vanguard-fluxcd, vanguard-frontend, vanguard-gcp, vanguard-generic, vanguard-hetzner, vanguard-hr, vanguard-huawei, vanguard-ionos, vanguard-istio, vanguard-java, vanguard-kotlin, vanguard-kubernetes, vanguard-kyverno, vanguard-legal, vanguard-marketing, vanguard-microsoft, vanguard-multi-cloud, vanguard-netsuite, vanguard-nvidia, vanguard-oci, vanguard-opentelemetry, vanguard-ovhcloud, vanguard-php, vanguard-prometheus, vanguard-python, vanguard-salesforce, vanguard-sap, vanguard-scaleway, vanguard-sigstore, vanguard-snowflake, vanguard-terraform
  • Each Power ships: routing pattern (maestro entry), live-mutation discipline, provider invariants (account-ID/region, MLPS 2.0, EU sovereignty, etc.)
  • Frontmatter: strict-5 fields (name, displayName, description, keywords, author) per Kiro spec
  • For Kiro agent adapter files (.kiro/agents/*.md, .kiro/agents/*.json): use the npm-export path below
  • Docs: github.com/kirodotdev/powers
♊ Gemini CLI & Google Antigravity  —  skills framework via npm export

Antigravity reads skills from .agent/skills/<name>/SKILL.md (workspace) or ~/.gemini/antigravity/skills/<name>/ (global). There is no first-party marketplace install command — use the npm export to write skills + adapters into the right paths:

# Install the package
npm install @raishin/vanguard-frontier-agentic@latest

# Export agents + companion skills for Gemini Antigravity
npx vfa-export-agents --platform gemini --all --repo .

Or for a single provider:

npx vfa-export-agents --platform gemini --provider aws --repo .
⚡ Codex (OpenAI)  —  one-command marketplace install
# Add the marketplace, then enable the bundled plugin
codex plugin marketplace add VincentChuWaiChow/vanguard-frontier-agentic
/plugin install vanguard-frontier-agentic@vanguard-frontier-agentic

codex plugin marketplace add writes the marketplace into your ~/.codex/config.toml. The resulting block looks like this (the screenshot pattern):

[marketplaces.vanguard-frontier-agentic]
last_updated = "2026-05-11T06:46:00Z"
last_revision = "<sha>"
source_type = "git"
source = "https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git"

[plugins."vanguard-frontier-agentic@vanguard-frontier-agentic"]
enabled = true
📦 Any other harness  —  npm package + vfa-export-agents CLI

Prerequisite: Node.js 18+

# 1️⃣ Install the package
npm install @raishin/vanguard-frontier-agentic@latest

# 2️⃣ Export agents for your role into your repo (claude-code shown — swap platform)
npx vfa-export-agents --platform claude-code --role cloud-security-engineer --repo .

# 3️⃣ Open your coding agent and reference the exported agent
#    "Use kubernetes-rbac-review-agent to audit this RBAC change."

Supports --platform: claude-code, codex, copilot, cursor, gemini, kiro, kiro-ide, kiro-cli. Supports --role, --agents, --all, --provider filters. See the Install Reference for the full argument matrix.


Install paths

There are now eight supported install paths — Claude Code plugin marketplace, GitHub Copilot CLI marketplace, Cursor plugin, Codex plugin marketplace, Kiro Powers, Gemini Antigravity skills, npm package + vfa-export-agents CLI, and the third-party skills CLI — each with different versioning, trust, and scope characteristics. See docs/integrations/skills-cli.md for the full trust matrix, verified flag syntax, pinning guidance, and pre-install inspection steps.

npm install @raishin/vanguard-frontier-agentic@latest

🖥️ Terminal UI (vfa-tui)

⚠️ Alpha — the TUI is functional but under active development.

An enterprise-grade terminal interface for interactive catalog browsing, validation gate execution, and export command building — built in Rust for speed and security by construction. Distributed as the vfa-tui crate.

Install (recommended — from crates.io):

cargo install vfa-tui

Or download a prebuilt binary (Linux / macOS / Windows, x86-64 + arm64) — each release attaches the binaries alongside their SBOM and checksums.sha256 — from the latest vfa-tui release.

Build from source (alternative):

cd tools/vfa-tui && cargo build --release

Run (from the repo root — auto-detects workspace):

vfa-tui                                      # installed via cargo or prebuilt binary
./tools/vfa-tui/target/release/vfa-tui       # from a source build

Key features:

  • 🗂️ Catalog browsing with fuzzy search across all agents, skills, and providers
  • ✅ Validation gate execution with real-time progress and structured output
  • 📦 Export command builder with platform/role/provider selection
  • 🔐 Security by construction — no shell injection, no credential handling, no network access

Full documentation


🧠 Skills

689 skills across AWS, Azure, OCI, GCP, Alibaba Cloud, Huawei Cloud, Kubernetes, CNCF ecosystem, Terraform, marketing governance, and more.

DomainCountWhat they cover
🟧 AWS47IAM, EKS, ECS, Lambda, RDS, S3, Cost, DevOps, Bedrock, Security, WAF reviews, Live Guards
🟥 OCI41ADB, OKE, IAM, Vault, Resource Manager, Cost, Networking, WAF reviews, Live Guards
🟩 GCP51GKE, BigQuery, Vertex AI, Cloud Run, AlloyDB, Firebase, Gemini API, WAF reviews, Live Guards
🟦 Azure36AKS, App Service, ARM/Bicep, Key Vault, PIM, Cost, Entra ID, CosmosDB, WAF reviews, Live Guards
🟠 Alibaba Cloud43ACK, ECS, PolarDB, MaxCompute, RAM, OSS, MLPS 2.0, WAF reviews, Live Guards
🔴 Huawei Cloud43CCE, GaussDB, ModelArts, DEW, SecMaster, OBS, MLPS 2.0, WAF reviews, Live Guards
☸️ Kubernetes10RBAC review, workload identity, PSA, live RBAC/admission/mesh/network/ArgoCD guards, maestro
🛡️ Kyverno1ClusterPolicy/Policy, PolicyException, failureAction, background scan
🔄 Argo CD2AppProject blast-radius, sync impersonation, RollingSync, sync-window
🕸️ Istio1Ambient mesh, ztunnel L4 vs waypoint L7, PeerAuthentication, mTLS posture
🐝 Cilium1CiliumNetworkPolicy, ClusterMesh trust, 169.254.169.254 egress, WireGuard encryption
📡 OpenTelemetry1Collector pipeline, memory_limiter, receiver exposure, exporter cardinality, credential handling
🟩 Terraform1IaC review and plan safety
📣 Marketing14Consent, pixel-leakage, martech access, GPC, email auth, ads.txt, targeting fairness, EU AI Act, audience uploads, list retention, influencer, dark patterns, analytics, maestro
☁️ Salesforce25Org assessment, metadata review, permissions audit, Flow automation, Apex/LWC code review, release readiness, integration, marketing consent, Agentforce risk review, zero-trust maturity, DevSecOps pipeline, SOQL generation, Apex generation and test generation, operational T1/T2 runtime skills
Ⓜ️ Microsoft 365 / D36538Maestro routing (microsoft/m365/d365/Power Platform/Copilot), Entra Zero Trust & Conditional Access, Microsoft 365 Copilot readiness, Purview data security & compliance, Defender XDR SecOps, Intune endpoints, Teams collaboration, Exchange/SharePoint information governance, tenant governance, backup/BCDR & data resilience, licensing/EA optimization, Dataverse/DLP security, Power Platform ALM, Power Automate risk review, Copilot Studio governance, Fabric/Power BI governance, Fabric data engineering, Fabric analytics engineering, D365 Success by Design, SoD, data migration/cutover, finance close-to-report, supply chain, field service, customer service, sales ops, Customer Insights – Journeys, F&O developer/extensions, dual-write integration, Project Operations, Commerce, value realization, live-guard identity posture + Dataverse security role (read-only-runtime, Phase A), live-guard Dataverse record field update + sensitivity label apply (mutating-runtime, Phase B)
🧱 Databricks (Azure)3Azure Databricks Unity Catalog governance (least-privilege grants, admin separation) + lakehouse engineering (medallion, managed-identity storage, cluster policies) — static review; + Unity Catalog schema-scoped grant guard (mutating-runtime live-guard, Phase B)
❄️ Snowflake (Azure)3Snowflake-on-Azure RBAC governance (SoD, ACCOUNTADMIN restriction, network policies) + data-platform engineering (Private Link, masking/row-access governance) — static review; + RBAC grant guard (mutating-runtime live-guard, Phase B)

🛡️ Live Guard skills — stop before you break prod

Live-guard skills enforce approval gates and rollback posture for irreversible operations:

🟧 AWS (5):

  • aws-live-deployment-guarded-operator — approval-gated generic live deployment actions with account/region confirmation
  • aws-live-iac-change-guard — CloudFormation/SAM/CDK/Terraform change set + drift + rollback posture enforcement
  • aws-live-pipeline-approval-operator — CodePipeline approval gating with exact stage and approver scope
  • aws-live-serverless-release-guard — Lambda alias/canary/linear rollout with alarm + rollback required
  • aws-live-ecs-rollout-guard — ECS/Fargate deployment circuit breaker, health check evidence, rollback path

🟩 GCP (6):

  • gcp-live-gke-rollout-guard — GKE deployment and node pool mutations, control-plane version gating
  • gcp-live-iam-policy-change-guard — IAM binding mutations, org policy changes, SA key creation — org-wide blast radius
  • gcp-live-kms-key-destruction-guard — Cloud KMS key version destruction — CMEK data permanently unrecoverable
  • gcp-live-cost-budget-action-guard — budget thresholds, CUD commitments, quota increases — financial authority gate
  • gcp-live-bigquery-dataset-deletion-guard — dataset deletion, table truncation, authorized view changes — irreversible data loss
  • gcp-live-cloud-run-traffic-migration-guard — Cloud Run revision traffic shifts, min-instances changes — production traffic blast radius

🟠 Alibaba Cloud (6):

  • alibaba-live-ack-rollout-guard — ACK deployment mutations, node pool scaling, cluster version upgrades
  • alibaba-live-ram-policy-change-guard — RAM policy/role mutations — account-wide blast radius, privilege escalation risk
  • alibaba-live-kms-key-mutation-guard — KMS key deletion/disable — encrypted data permanently inaccessible
  • alibaba-live-cost-budget-action-guard — budget threshold changes, Savings Plan purchases, RI commitments — financial authority gate
  • alibaba-live-oss-bucket-policy-guard — OSS bucket ACL/policy changes — public exposure or China data-residency violation
  • alibaba-live-rds-polardb-mutation-guard — RDS/PolarDB instance deletion, spec downgrade, backup policy removal — data loss risk

🔴 Huawei Cloud (6):

  • huawei-live-cce-rollout-guard — CCE deployment mutations, node pool upgrades, cluster version changes
  • huawei-live-iam-policy-change-guard — IAM policy/SCP mutations — account-wide blast radius, privilege escalation
  • huawei-live-kms-key-destruction-guard — DEW/KMS key deletion — CSMS secrets and DBSS-encrypted data permanently lost
  • huawei-live-cost-budget-action-guard — budget threshold changes, RI purchases, CUD commitments — financial authority gate
  • huawei-live-obs-bucket-policy-guard — OBS bucket ACL/policy changes — public exposure or data residency violation
  • huawei-live-gaussdb-mutation-guard — GaussDB/RDS instance deletion, spec downgrade, backup policy changes — data loss

🟦 Azure (7):

  • azure-live-aks-rollout-guard — PDB audit, rollout pause/undo, post-rollout health
  • azure-live-arm-deployment-stack-guard — what-if evidence, denySettings, PIM-gated delete
  • azure-live-app-service-slot-swap-guard — sticky-setting audit, traffic shifting, swap-back path
  • azure-live-keyvault-rotation-purge-guard — rotation policy, soft-delete/purge-protection, PIM gate
  • azure-live-pim-jit-activation-guard — eligible assignment audit, MFA gate, JIT revocation
  • azure-live-cost-budget-action-guard — budget mutation, GPU SKU policy, quota read-only
  • azure-live-entra-role-assignment-guard — permanent role assignment scope/principal audit, PIM-preference enforcement, Guest principal blocking

🟥 OCI (7):

  • oci-live-autonomous-db-lifecycle-guard — ADB scale/stop/clone/terminate with tag enforcement
  • oci-live-oke-rollout-guard — DevOps pipeline approval, PDB audit, rollout pause/undo
  • oci-live-resource-manager-stack-guard — plan-before-apply, drift detection, job-lock enforcement
  • oci-live-vault-key-destruction-guard — rotation vs. destruction separation, 7–30 day deletion window
  • oci-live-iam-policy-compartment-guard — MFA break-glass, dual-approval for tenancy-root changes
  • oci-live-cost-budget-runaway-guard — 3-tier budget management, GPU shape gate, ONS alert routing
  • oci-live-network-security-rule-guard — Security List/NSG rule capture, 0.0.0.0/0 detection, DB-subnet criticality, Path Analyzer gate

☸️ Kubernetes (5):

  • kubernetes-live-rbac-mutation-guard — escalate/bind/impersonate verb detection, wildcard blocking, pre-mutation state capture, rollback via YAML backup
  • kubernetes-live-admission-policy-guard — Kyverno/VAP mutation blast-radius, failureAction enforcement, PolicyException scope validation
  • kubernetes-live-mesh-policy-guard — Istio AuthorizationPolicy/PeerAuthentication traffic impact, PERMISSIVE→STRICT migration gating
  • kubernetes-live-network-policy-guard — CiliumNetworkPolicy/NetworkPolicy connectivity impact, metadata service egress blocking
  • kubernetes-live-argocd-sync-guard — AppProject blast-radius, sync impersonation identity review, sync-window change gating

Sample skills

Rule of thumb: if the asset teaches how to do a repeatable task, it is a skill.


🤖 Agents

666 agents matching the skill catalog — agents ship harness adapters and a hardened permission model.

ProviderCountSpecialisations
🟩 GCP51advisory, live-guard operators, maestro router
🟧 AWS47advisory, execution, live-guard operators
🟠 Alibaba Cloud43advisory, live-guard operators, maestro router
🔴 Huawei Cloud43advisory, live-guard operators, maestro router
🟥 OCI39advisory, live-guard operators
🟦 Azure36advisory, live-guard operators
☸️ Kubernetes15RBAC review, workload identity, PSA, 5 live-guard operators, maestro router
☁️ OVHcloud6advisory, live KMS guard, maestro router
🌐 IONOS Cloud6advisory, live DB lifecycle guard, maestro router
🇫🇷 Scaleway6advisory, live Kapsule rollout guard, maestro router
🇩🇪 Hetzner Cloud6advisory, live firewall + server lifecycle guards, maestro router
💰 Contabo6advisory, live instance + storage guards, maestro router
🛡️ Kyverno1Admission policy review
🔄 Argo CD2GitOps review, live sync guard
🕸️ Istio1Ambient mesh review
🐝 Cilium1Network policy review
📡 OpenTelemetry1Collector config review
💡 Backstage1IDP scaffolder review
🔐 cert-manager1PKI certificate lifecycle review
🦅 Falco1runtime threat detection review
🔁 Flux CD1GitOps Kustomization/HelmRelease review
📊 Prometheus1alerting and cardinality review
🔏 Sigstore1supply-chain security review
🟩 Terraform2IaC review, maestro
💸 FinOps4cross-cloud price advisor + experimental cost/economics agents
🐘 PHP5maestro + 4 static-review specialists: application security (session fixation, deserialization, file-upload), runtime EOL/OPcache/FPM hardening, Composer supply-chain audit, WordPress REST API/block-editor security — static-review only
🟣 .NET10C#/runtime, ASP.NET Core API & identity, EF Core data access, testing, NuGet supply chain, performance/AOT, OpenTelemetry, Aspire — static-review specialists + maestro router
☕ Java15JDK lifecycle & upgrade, concurrency/virtual threads, JVM performance & GC, container/K8s sizing, framework readiness (Spring Boot/Quarkus/Micronaut), Spring Security, deserialization/parser security, JPA/Hibernate performance, transaction & consistency, migration safety, Kafka reliability, resilience patterns, test architecture, app-server license exit — static-review specialists + maestro router
🟧 Kotlin16language/null-safety correctness, coroutines/Flow reliability, library API/ABI governance, Ktor + Kotlin-Spring backend readiness, kotlinx.serialization wire contracts, Java-to-Kotlin modernization, Android (architecture, Compose UI + accessibility, MASVS security/privacy, runtime performance), Kotlin Multiplatform (portfolio + interop), Gradle build engineering, dependency/release supply-chain integrity, test architecture — static-review specialists + maestro router
🐍 Python3520 static-review specialists (application security, asyncio reliability, packaging/supply-chain, numerical correctness, typing contracts, web-service readiness, data-access/transactions, distributed-task reliability, testing quality, estate modernization, performance/memory, free-threading/no-GIL, native-extension interop, container/serverless, data-pipeline reliability, ML/AI production, observability, tooling/build, automation governance) routed by python-maestro-agent; plus a 15-agent live control plane (python-live-*, read-only-runtime + mutating-runtime) routed by python-live-governance-maestro-agent — mutating operators are live-guard gated (external signed approval bound to target, JIT credentials, pre-approved rollback, immutable audit event, fail-closed for R3+); ships definitions/contracts/evals, not a running control plane
🟤 NVIDIA12CUDA/GPU infrastructure, TensorRT/TensorRT-LLM, Triton serving, NeMo/NIM generative AI, agentic-AI platform, NGC supply chain, AI networking fabric, day-2 operations, GPU Operator on Kubernetes, model promotion gatekeeper — advisory + live-runtime gate + maestro router
📣 Marketing1413 governance review agents + maestro router
⚖️ Legal13contract review, employment law risk, privacy & data protection, regulatory compliance, IP & open source, litigation & discovery hold, ethics & investigations, vendor/procurement risk, policy governance, public disclosure, counsel review, knowledge management
👥 HR15employee relations, workplace investigations, performance management, compensation & equity, benefits & payroll, recruiting & selection, workforce planning & RIF, leave & accommodation, learning policy, culture & DEI, people analytics, HRIS process controls, termination readiness, risk triage
🧪 QA10Playwright E2E review + execution, flakiness triage, coverage quality, CI test pipeline review, PLC control-logic safety, RPA workflow resilience — static-review + opt-in execution
☁️ Salesforce3020 Wave 1 domain specialists (admin, dev, security, integration, Sales/Service/Marketing/Industry clouds, Agentforce, analytics, compliance) + 10 Wave 3 infrastructure security + DevSecOps agents — maestro router + live-guard authority gate
🔷 SAP40maestro + 39 specialists: S/4HANA transformation architecture, BTP account/entitlement governance, ABAP Cloud/RAP & CAP code review, Fiori/UI5 UX, finance FI-CO controls, supply chain IBP resilience, manufacturing execution risk, SuccessFactors HR process risk, MDG master data quality, custom-code remediation, Cloud ALM SRE, transport/release governance, read-only landscape + identity discovery; + 4 guarded-mutating-runtime live-guard operators (BTP entitlement, integration flow, role assignment, transport import) — advisory + live-guard-gated execution + maestro router
Ⓜ️ Microsoft 365 / D365405 maestro routers (microsoft, m365, d365, Power Platform, Copilot governance) + 31 static-review specialists + 2 read-only-runtime live-guards (Phase A: identity posture, Dataverse security role) + 2 mutating-runtime live-guards (Phase B: Dataverse record field update, sensitivity label apply) across M365 (Entra identity/Zero Trust, Copilot readiness, Purview data security & compliance, Defender XDR SecOps, Intune endpoints, Teams collaboration, Exchange/SharePoint information governance, tenant governance, backup/BCDR & data resilience, licensing/EA optimization), Power Platform (Dataverse security, ALM pipelines, automation risk, Copilot Studio governance), Fabric/Power BI (governance, data engineering, analytics engineering), D365 (Success by Design, SoD, data migration/cutover, finance, supply chain, field service, customer service, sales, Customer Insights – Journeys, F&O developer/extensions, dual-write integration, Project Operations, Commerce, value realization), and live-guard runtime (Phase A: identity posture, Dataverse security role; Phase B: Dataverse record field update guard, sensitivity label apply guard)
🧱 Databricks (Azure)32 static-review specialists (Phase A): Unity Catalog governance (metastore→catalog→schema→table, least-privilege grants, account/workspace/metastore admin separation, run-as-service-principal) + lakehouse engineering (medallion architecture, ADLS Gen2 via Access Connector managed identity, cluster policies, AKV-backed secret scopes, VNet/Private Link); + 1 mutating-runtime live-guard (Phase B): Unity Catalog schema-scoped grant guard (single GRANT to one principal, REVOKE rollback, written approval token + PREFLIGHT required)
❄️ Snowflake (Azure)32 static-review specialists (Phase A): RBAC governance (ACCOUNTADMIN/SECURITYADMIN/SYSADMIN separation, custom least-privilege roles, SoD, network policies, Entra OAuth/SSO/SCIM) + data-platform engineering (warehouses, Azure Private Link, storage integration to ADLS Gen2/Blob, dynamic masking/row-access/tagging, ACCESS_HISTORY); + 1 mutating-runtime live-guard (Phase B): Snowflake RBAC grant guard (single GRANT to one grantee, REVOKE rollback, written approval token + PREFLIGHT required, ACCOUNTADMIN/SECURITYADMIN/SYSADMIN escalation denied)
🔗 Cross-functional skills3legal-hr-routing-protocol, legal-hr-case-capsule, legal-hr-risk-taxonomy (protocol skills, not agents)

Beyond cloud and platform agents, Vanguard Frontier ships a 28-agent cross-functional Legal + HR ecosystem plus 3 cross-functional protocol skills — proof that agentic coordination works across organizational boundaries, not just inside one cloud account.

Every Legal and HR agent is escalation-aware (knows when a matter must go to privileged counsel or a human owner), privacy-preserving (minimizes personal and sensitive data in every handoff), and audit-ready (emits the same structured verdict shape as the cloud live-guard agents). These agents advise on process and risk posture — they do not replace licensed legal counsel or qualified HR professionals, and they say so.

🐘 The PHP application review board

PHP is a widely used open-source, general-purpose scripting language built for the web — it powers a large share of the internet, including WordPress, and ships its own dependency manager, Composer. The board is a php-maestro router plus four static-review specialists covering application security (session fixation, insecure deserialization, and file-upload exploits), runtime end-of-life/OPcache/PHP-FPM configuration hardening, Composer supply-chain dependency audit, and WordPress REST API / block-editor security — every agent reads source, sanitized configuration, and dependency manifests only and never executes payloads, installs packages, or mutates a live runtime. These agents declare their own provider: php catalog value with a mix of ID prefixes (php-, composer-, wordpress-) reflecting the specific ecosystem tool each one reviews.

🟣 The .NET application review board

.NET is a free, cross-platform, open-source developer platform — runtime, libraries, and languages (C# is the most popular) — with ASP.NET Core as its lean, modular framework for modern cloud-based web services and EF Core as its lightweight, extensible data-access layer. The board is a dotnet-maestro router plus nine static-review specialists covering C#/runtime correctness, ASP.NET Core API architecture, identity and authorization, EF Core data access, test quality, CI/NuGet supply chain, performance/AOT/trimming, in-app OpenTelemetry wiring, and .NET Aspire cloud-native readiness — every agent reads source and sanitized configuration only and never builds, runs, migrates, or contacts a live system. These agents use provider: generic with a dotnet- ID prefix because .NET is a language/runtime, not a cloud provider — mirroring the existing non-cloud boards.

☕ The Java application review board

Java and the JVM run a large share of the enterprise back end — Spring Boot, Jakarta EE, Quarkus, and Micronaut services over Hibernate/JPA, Kafka, and relational databases, on JDKs whose support and licensing boundaries move. The board is a java-maestro router plus fourteen static-review specialists, each owning one distinct, evidence-gated decision: JDK-estate lifecycle and upgrade risk, virtual-thread adoption correctness, JVM performance and GC, containerized-JVM sizing, Spring/Quarkus/Micronaut production readiness, Spring Security authorization and Actuator exposure, untrusted-deserialization/parser RCE surface, JPA/Hibernate fetch performance, transaction and cross-resource consistency (dual-write → outbox), schema-migration deploy safety, Kafka delivery semantics, resilience-pattern composition, JVM test architecture, and the application-server license-exit portfolio decision. Every agent reads source and sanitized configuration only and never builds, runs, invokes a JDK, opens a database or broker connection, or contacts a live system. Two hardened refusal contracts anchor the board's honesty: the JDK agent never states a vendor lifecycle date from memory (it cites a verified, refreshable reference or returns unknown), and the performance and application-server-exit agents refuse to issue a GC recommendation or a payback number without supplied evidence — no hardcoded pricing or tenant data. These agents use provider: java with a java- ID prefix, mirroring the other non-cloud topical boards.

🟧 The Kotlin application review board

view the full README on GitHub.

// faq

What is vanguard-frontier-agentic?

Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance-aware engineering - works with Claude Code, Codex, Cursor, Copilot, and more.. It is open-source on GitHub.

Is vanguard-frontier-agentic free to use?

vanguard-frontier-agentic is open-source under the Apache-2.0 license, so it is free to use.

What category does vanguard-frontier-agentic belong to?

vanguard-frontier-agentic is listed under devops in the Claudeers registry of Claude-compatible tools.

5 views
21 stars
unclaimed
updated 14 days ago

// embed badge

vanguard-frontier-agentic on Claudeers
[![Claudeers](https://claudeers.com/api/badge/vanguard-frontier-agentic.svg)](https://claudeers.com/vanguard-frontier-agentic)

// retro hit counter

vanguard-frontier-agentic hit counter
[![Hits](https://claudeers.com/api/counter/vanguard-frontier-agentic.svg)](https://claudeers.com/vanguard-frontier-agentic)

// reviews

// guestbook

0/500

// related in DevOps & CI/CD

🔓

⭐AI-driven public opinion & trend monitor with multi-platform aggregation, RSS, and smart alerts.🎯 告别信息过载,你的 AI 舆情监控助手与热点筛选工具!聚合多平台热点 + RSS 订阅,支持关键词精准筛选。AI…

// devopssansan0/Python61,486GPL-3.0[ claude ]
🔓

Use Claude Code as the foundation for coding infrastructure, allowing you to decide how to interact with the model while enjoying updates from Anthropic.

// devopsmusistudio/TypeScript36,683MIT[ claude ]
🔓

Professional Antigravity Account Manager & Switcher. One-click seamless account switching for Antigravity Tools. Built with Tauri v2 + React (Rust).专业的 Antig…

// devopslbjlaq/Rust30,371NOASSERTION[ claude ]
→ see how vanguard-frontier-agentic connects across the ecosystem