Back to Discover

blackrim-nimbus-skills

skill

jsgerman-oss

Claude Code plugin marketplace — 19 cloud-provider toolkits with schemas, validator, and rule registry.

View on GitHub
8 starsMITSynced Aug 2, 2026

Install to Claude Code

/plugin marketplace add jsgerman-oss/blackrim-nimbus-skills

README

blackrim-nimbus-skills

A Claude Code plugin marketplace for cloud-development workflows. Production-grade defaults, validated by schema, across 19 cloud providers.

License: MIT Node ≥ 18 Plugins: 19 Validator rules: 28 Claude Code compatible Validate PRs welcome

Quick start · The matrix · Pick a provider · Plugin anatomy · Validator · Contributing


What this is

A curated marketplace of 19 Claude Code plugins, one per cloud, each shipping:

ComponentCountWhat it does
Domain skills6Auto-fire by description match; cover compute → IaC for that cloud
SME sub-agents2<provider>-architect (well-architected review) + -security-reviewer (audit)
Slash commands1+/<provider>-scaffold-iac and platform-specific scaffolds

Every plugin is schema-validated, follows a canonical structure enforced by CI, and bakes in production-grade defaults: encryption-at-rest, least-privilege identity, private-by-default networking, observability before launch, cost flagged at decision time.

Why use this? You want Claude Code to be opinionated and right about cloud choices, not generic. The skills are scoped tightly enough to fire only when relevant, deep enough to actually help, and consistent enough across providers that switching clouds doesn't break your muscle memory.

🚀 Quick start

From any Claude Code session:

/plugin marketplace add /absolute/path/to/blackrim-nimbus-skills
/plugin install cloud-aws@blackrim-cloud-toolkits

That's it. The next time you ask Claude something compute-shaped on AWS — "should this be a Lambda or an ECS task?" — the aws-compute skill auto-fires with a decision tree, defaults, and anti-patterns.

Install multiple plugins side-by-side:

/plugin install cloud-aws@blackrim-cloud-toolkits
/plugin install cloud-cloudflare@blackrim-cloud-toolkits
/plugin install cloud-supabase@blackrim-cloud-toolkits

Try the sub-agents

Use the aws-architect agent to review my CDK stack against the Well-Architected pillars.
Use the cf-security-reviewer agent to audit my wrangler.toml + Workers code for exposure.

Try the slash commands

/aws-scaffold-iac a multi-AZ web service with a Postgres backend and CloudFront in front

🗺️ The matrix

Hyperscalers

PluginBest forCoverage
cloud-awsGreenfield US/EU startup, AWS-nativeLambda, ECS, EKS, EC2, S3, RDS / Aurora, DynamoDB, VPC, ALB / CloudFront, IAM, KMS, Secrets Manager, GuardDuty, CloudWatch / X-Ray, CDK / Terraform / SAM.
cloud-gcpGKE / Vertex AI / BigQuery / data-heavy stacksCloud Run, GKE, Cloud Functions Gen 2, Compute Engine, GCS, Cloud SQL / AlloyDB / Spanner / Firestore / BigQuery, Cloud LB / Cloud CDN / Cloud Armor, Cloud IAM + Workload Identity, KMS, Cloud Monitoring / Logging / Trace, Terraform / Config Connector.
cloud-azureEnterprise, FedRAMP, financial servicesFunctions, AKS, Container Apps, App Service, VMs, Blob / Azure SQL / Cosmos DB, VNet / Application Gateway / Front Door / APIM, Entra ID + Managed Identity, Key Vault, Defender for Cloud, Azure Monitor + App Insights, Bicep / Terraform.
cloud-ociOracle workloads + Autonomous DatabaseCompute, OKE, Functions, Object Storage, Autonomous Database, MySQL HeatWave, VCN / Load Balancer / WAF, OCI IAM + Resource Principal, Vault KMS, Cloud Guard, Security Zones, Monitoring + APM, Terraform / Resource Manager.
cloud-ibmFIPS 140-2 L4 (Hyper Protect), regulated workloadsVPC VSIs, Code Engine, IKS / ROKS, COS, Cloudant, Db2 on Cloud, Hyper Protect, IBM Cloud IAM + Trusted Profiles, Key Protect + HPCS, Activity Tracker, Sysdig + LogDNA, Terraform / Schematics.
cloud-alibabaAPAC + China-region presence (MLPS, ICP)ECS, ACK, Function Compute, OSS, RDS / PolarDB, VPC, SLB / ALB / NLB, CDN / DCDN, RAM + STS, KMS, Anti-DDoS + WAF + Security Center, CloudMonitor + SLS, Terraform / ROS. China + International account separation.
cloud-tencentChina-region with EdgeOne CDNCVM, TKE, SCF, COS, CDB / TDSQL, VPC / CLB, CDN + EdgeOne, CAM, KMS, CloudAudit, Cloud Monitor + CLS, Terraform / TIC.

Edge · Zero Trust · Frontend

PluginBest forCoverage
cloud-cloudflareEdge-first, low egress, ZTNA, Workers stackWorkers, Durable Objects, Pages Functions, Workers AI, Workflows, R2, D1, KV, Queues, Hyperdrive, Vectorize, DNS / CDN / LB, Argo, Tunnel, Access (ZTNA), Gateway, WAF, Bot Management, DDoS, Page Shield, Analytics Engine, Logpush, Wrangler + Terraform v5.
cloud-vercelNext.js / SvelteKit / Astro productionProduction / Preview / Branch deploys, Edge Functions, Edge Middleware, Serverless Functions, ISR, Image Optimization, Cron, Vercel KV / Postgres / Blob, Edge Config, Deployment Protection, WAF + Attack Challenge, Web Analytics, Speed Insights, Logs Drains, Spend Management.
cloud-netlifyJAMstack with build pipelines + Deploy PreviewsBuild pipelines, Deploy Previews, Edge Functions (Deno), Background + Scheduled Functions, Blobs, Forms, Identity, Visitor Access, security headers via _headers, Logs Drains, build minutes / bandwidth pricing.

Modern PaaS · Dev-first · BaaS

PluginBest forCoverage
cloud-flyGlobal Docker fleet, multi-region defaultFly Machines (Firecracker VMs), Apps, scale-to-zero, anycast routing, 6PN private mesh, Flycast, Volumes (AZ-local), Fly Postgres, Redis (Upstash), Tigris (S3-compat), LiteFS, flyctl + GitHub Actions.
cloud-renderHeroku replacement with SOC 2 postureWeb Services, Private Services, Background Workers, Cron Jobs, Static Sites, Managed Postgres (HA + PITR), Managed Redis, Persistent Disks, Blueprints (render.yaml), PR Previews.
cloud-railwayFast-onboarding PaaS with usage billingServices, Volumes, Database Plugins (Postgres / MySQL / Mongo / Redis), Reference Variables, Service Tokens, Templates, preview environments.
cloud-supabasePostgres + Auth + Storage as managed BaaSPostgres + RLS-first security, Auth (email / OAuth / magic link / MFA + passkeys), Storage with RLS, Realtime (WAL + Broadcast + Presence), Edge Functions (Deno), pgvector, Supabase CLI + branching + GitHub Actions.

VPS · Regional · Cost-leader

PluginBest forCoverage
cloud-digitaloceanPredictable pricing, App Platform onboardingDroplets, App Platform, DOKS, Spaces, Volumes, Managed Databases, VPC, Load Balancer, Reserved IPs, Cloud Firewall, doctl + Terraform + App Spec YAML.
cloud-hetznerEU data residency, budget servers + dedicatedHetzner Cloud servers (CX / CPX / CCX / CAX ARM), Robot dedicated, Volumes, Storage Box, Private Networks, Load Balancer, Cloud Firewalls, hcloud-cli + Terraform + Ansible. Honest about no native managed DB.
cloud-linodeAkamai-backed VPS with global presenceCompute Instances, LKE, Object Storage, Volumes, Managed Databases, NodeBalancer, VLAN + VPC, Cloud Firewall, linode-cli + Terraform + Ansible.
cloud-vultrHigh-frequency / AMD / Bare Metal / GPUCloud Compute (Regular / High Performance / High Frequency / AMD / Intel), Bare Metal, Cloud GPU, VKE, Object Storage, Managed Databases, VPC 2.0, Load Balancers, Reserved IPs, Firewall Groups, vultr-cli + Terraform + Packer.
cloud-scalewayEU-strong, Serverless Containers + KapsuleInstances, Elastic Metal, Serverless Containers / Jobs / Functions, Kapsule (Kubernetes — Kosmos for hybrid), Object Storage, Managed Databases, Serverless SQL, Scaleway IAM + Secret Manager + Key Manager, Cockpit (managed Grafana), scw + Terraform.

🎯 Pick a provider

If you're…Reach for
A greenfield startup, AWS-native, want one IaCcloud-aws + CDK or Terraform
GKE / Vertex-heavy ML stackcloud-gcp
Enterprise / regulated (FedRAMP, financial, FIPS 140-2 L4)cloud-azure or cloud-ibm (Hyper Protect)
Edge-first, low egress, Workers-friendlycloud-cloudflare
Next.js / SvelteKit / Astro frontendcloud-vercel or cloud-netlify
Postgres + Auth + Storage as a managed BaaScloud-supabase
Global Docker fleet, multi-region by defaultcloud-fly
Heroku-replacement, fast onboardingcloud-render or cloud-railway
Budget-conscious / EU data residencycloud-hetzner or cloud-scaleway
APAC / China-region presencecloud-alibaba or cloud-tencent
Oracle workloads + Autonomous Databasecloud-oci

🧩 Plugin anatomy

Every plugin follows the same shape. Predictable layout, predictable surface area.

cloud-<provider>/
├── .claude-plugin/
│   └── plugin.json                              # manifest (name, prefix, keywords, ...)
├── README.md                                    # has a managed "What's inside" region
├── skills/
│   ├── <prefix>-compute/SKILL.md                # runtime selection + sizing
│   ├── <prefix>-storage-and-databases/SKILL.md  # data tier decisions
│   ├── <prefix>-networking-and-edge/SKILL.md    # VPC / LB / DNS / WAF / CDN
│   ├── <prefix>-identity-and-security/SKILL.md  # IAM, KMS, secrets, audit
│   ├── <prefix>-observability-and-cost/SKILL.md # metrics, logs, traces, FinOps
│   └── <prefix>-iac-and-deployment/SKILL.md     # IaC tool selection + CI/CD
├── agents/
│   ├── <prefix>-architect.md                    # well-architected reviewer
│   └── <prefix>-security-reviewer.md            # security audit
└── commands/
    └── <prefix>-scaffold-iac.md                 # IaC project scaffold

Note on <prefix> — usually matches the provider name (aws-, gcp-), but some diverge: Cloudflare uses cf-, DigitalOcean uses do-. The plugin's prefix is declared in plugin.json.

For platforms whose shape diverges from generic IaaS (Cloudflare's Zero Trust, Vercel's edge runtime, Supabase's Postgres+Auth model, Fly's Firecracker fleet), the six-slot template flexes — e.g. cf-workers-and-compute, supabase-auth, vercel-frontend-platform.

📖 Skill anatomy

Each SKILL.md follows a consistent shape so Claude knows what to expect and contributors know what to write:

---
name: <skill-slug>
description: <when to use this skill — fires on description match>
---

# <Skill Title>

## When to use
- Concrete triggering conditions

## Decision tree / Defaults
Per-service production-grade defaults or a decision tree.

## Anti-patterns
| Anti-pattern | What goes wrong |
| --- | --- |
| ... | ... |

## Security defaults
## Observability defaults
## Cost considerations
## IaC hints

## Verification checklist
- [ ] Items that gate "done"

The Verification checklist is the load-bearing section — it's what gates "is this work actually finished?" The validator enforces it; downstream tooling can parse it via npm run checklist <plugin>.

🧪 What's in the validator

Every plugin and every file is checked by a declarative rule registry at bin/lib/rules.js. Run npm run rules to print the live list (29 rules across 5 scopes).

ScopeWhat it checks
marketplaceJSON schema, plugin references resolve, marketplace.json + the pack's providers.json in sync
pluginplugin.json schema, name matches dir, ≥5 skills, has both agents, has command, README managed-region in sync
skillFrontmatter parses, name matches slug, description ≥20 chars, ## Verification checklist with - [ ] items
agentFrontmatter parses, role-correct tools (architect adds WebFetch, security-reviewer adds Bash), model: sonnet, canonical body sections present
commandFrontmatter parses, filename starts with prefix, description + argument-hint present

Architect agents must contain: ## Inputs you expect, ## Review process, ## Output format, ## Rules of engagement. Security-reviewer agents must contain: ## Inputs, ## Review scope — what you check, ## Output, ## Rules of engagement.

CI runs npm run check + npm run regen + asserts no diff on every push and PR. Drift is caught before it lands.

🛠️ Development

Requires Node ≥ 18.

# Setup
git clone https://github.com/jsgerman-oss/blackrim-nimbus-skills.git
cd blackrim-nimbus-skills
npm install

# Validate
npm run check                                # run all 29 rules
npm run check -- --rule plugin-schema        # one rule
npm run check -- --skip skill-checklist-min-items  # skip one
npm run check -- --json                      # machine-readable output

# Inspect
npm run rules                                # list all rules (text)
npm run rules -- --md                        # markdown table
npm run rules -- --json                      # JSON
npm run checklist cloud-aws                  # all checklists in a plugin
npm run checklist cloud-aws aws-compute --json   # JSON for one skill

# Regenerate derived files (run after adding skills/agents/commands or a provider)
npm run regen                                # marketplace.json + plugin READMEs + pack provider index
npm run regen:marketplace                    # marketplace.json only
npm run regen:plugin-readmes                 # plugin README "What's inside" regions only
npm run regen:pack-providers                 # pack/nimbus/providers.json only

Adding a new plugin

  1. Create the directory: mkdir -p cloud-<provider>/{.claude-plugin,skills,agents,commands}
  2. Write plugin.json (don't forget prefix).
  3. Write 5+ skills, two agents (<prefix>-architect.md, <prefix>-security-reviewer.md), one command.
  4. npm run regen to update marketplace.json and your README's managed region.
  5. npm run check to validate.
  6. Open a PR.

See CONTRIBUTING.md for the full file-shape conventions.

🎨 Design principles

  1. Defaults are production-grade, not demo-grade. Encryption-at-rest on by default. Private subnets unless public is explicitly required. Least-privilege identity scoped to specific resources, never *.
  2. Cost is a first-class concern. Every skill flags cost-amplifying choices (NAT, cross-AZ, idle baselines, infinite log retention) at decision time, not in post-mortem.
  3. Observability before launch. No workload ships without metrics, logs, traces, and at least one alarm wired to a real notification channel.
  4. IaC over console. Console steps appear only as bootstrap (account hardening). Everything else is code.
  5. Well-architected as a checklist, not a vibe. The architect agent maps findings to specific pillar best practices and rates severity.
  6. Honest about limits. When a provider lacks a feature — fine-grained tokens, managed databases, anycast LB, fully-managed Postgres — the skill says so out loud rather than papering over it.
  7. Schema-validated. Conventions are enforced by code (bin/lib/rules.js), not by reviewer attention.

💡 Worked example

Suppose you're building a multi-region API on Fly.io with Supabase as the data tier. You'd install:

/plugin install cloud-fly@blackrim-cloud-toolkits
/plugin install cloud-supabase@blackrim-cloud-toolkits

Then in your session, the skills fire automatically as you discuss your design:

  • "Should I run this in 2 or 6 regions on Fly?"fly-machines-and-apps skill fires; decision tree on placement vs LiteFS replication.
  • "How do I scope RLS so user A can't read user B's rows?"supabase-postgres-and-rls skill fires; RLS policy templates.
  • "Audit my supabase RLS setup before launch." → invoke the supabase-security-reviewer agent.
  • "Scaffold the fly.toml for this service."/fly-scaffold-app slash command.

The cross-plugin story is consistent: every plugin's architect agent uses the same six-step review process; every security-reviewer uses the same four canonical sections; every skill ends with a parseable checklist.

🤝 Contributing

Contributions are welcome — new providers, deeper skills, refined defaults. See CONTRIBUTING.md for:

  • File-shape conventions (the canonical 6-skill + 2-agent + 1-command layout)
  • Skill anatomy and the verification-checklist contract
  • The 28-rule validator and how to add a new rule
  • PR checklist

Before opening a PR, run:

npm run check && npm run regen

…and ensure your diff is clean.

📜 License

MIT — Copyright © 2026 Blackrim.dev.

Pull requests, issues, and feature requests are welcome. The full validator output, schema definitions, and rule registry are all open to inspection so you can verify the production-grade-defaults claim isn't marketing.


Built with Claude Code · Validated by bin/check-plugins · 19 providers, one consistent shape

Rendered live from jsgerman-oss/blackrim-nimbus-skills's GitHub README — not stored, always reflects the source repo.

19 Plugins

NameDescriptionCategorySource
cloud-awsAWS development toolkit — domain skills, SME sub-agents, slash commands for IaC scaffolding, health checks, and architecture review../cloud-aws
cloud-gcpGoogle Cloud development toolkit — domain skills, SME sub-agents, slash commands for IaC scaffolding, health checks, and architecture review../cloud-gcp
cloud-azureMicrosoft Azure development toolkit — domain skills, SME sub-agents, slash commands for IaC scaffolding, health checks, and architecture review../cloud-azure
cloud-ociOracle Cloud Infrastructure development toolkit — Compute, OKE, Object Storage, Autonomous Database, OCI IAM, networking, and observability skills../cloud-oci
cloud-cloudflareCloudflare development toolkit — Workers, R2, D1, Pages, Zero Trust, and edge networking skills, with SME sub-agents and slash commands../cloud-cloudflare
cloud-digitaloceanDigitalOcean development toolkit — Droplets, App Platform, DOKS, Spaces, Managed Databases, and networking skills, with SME sub-agents and slash commands../cloud-digitalocean
cloud-hetznerHetzner Cloud development toolkit — Hetzner Cloud servers, volumes, networks, load balancers, firewalls, and Robot dedicated infrastructure../cloud-hetzner
cloud-flyFly.io development toolkit — Machines, Apps, Volumes, Postgres, Redis, networking, anycast, scale-to-zero, and global multi-region deployments../cloud-fly
cloud-vercelVercel development toolkit — Next.js deployments, Edge Functions, Edge Middleware, Image Optimization, KV / Postgres / Blob, ISR, and monorepos../cloud-vercel
cloud-supabaseSupabase development toolkit — Postgres, Auth, Row Level Security, Storage, Realtime, Edge Functions, Vector / pgvector, migrations, and self-hosting../cloud-supabase
cloud-renderRender development toolkit — Web Services, Background Workers, Cron Jobs, Static Sites, Managed Postgres / Redis, Disks, and Blueprints (IaC)../cloud-render
cloud-railwayRailway development toolkit — Services, Volumes, Plugins, Environments, Templates, Cron Jobs, observability, and PR preview deployments../cloud-railway
cloud-linodeLinode (Akamai Cloud Computing) toolkit — Compute Instances, LKE Kubernetes, Object Storage, Managed Databases, NodeBalancer, VLAN, and Cloud Firewalls../cloud-linode
cloud-vultrVultr development toolkit — Cloud Compute, Bare Metal, VKE Kubernetes, Object Storage, Managed Databases, Load Balancers, and VPC 2.0../cloud-vultr
cloud-scalewayScaleway development toolkit — domain skills, SME sub-agents, slash commands for IaC scaffolding and architecture review. EU data residency, Kapsule, Serverless Containers, Object Storage, and IAM../cloud-scaleway
cloud-netlifyNetlify development toolkit — Builds, Edge Functions, Functions (background / scheduled), Blobs, Forms, Identity, redirects, and Deploy Previews../cloud-netlify
cloud-ibmIBM Cloud development toolkit — VPC, Code Engine, IKS / Red Hat OpenShift on IBM Cloud, Cloud Object Storage, Cloudant, IAM, and watsonx services../cloud-ibm
cloud-alibabaAlibaba Cloud development toolkit — ECS, ACK Kubernetes, Function Compute, OSS, RDS / PolarDB, VPC, RAM, ApsaraDB, and CDN. APAC and China-region patterns../cloud-alibaba
cloud-tencentTencent Cloud development toolkit — CVM, TKE Kubernetes, SCF (serverless), COS object storage, TencentDB, VPC, CAM IAM, and CDN. APAC and China-region patterns../cloud-tencent

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.