SkillAtlasSkill 详情

databricks-bundle-medic

A model-agnostic agent-skills platform.

审核状态:已审核Quality 72Security 70

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月29日

Tons of Skills

A model-agnostic agent-skills platform. The canonical layer is harness-free by construction; Claude Code is currently the verified-native harness. Other harnesses remain engineering candidates until their native-path integration is verified; source research alone is never presented as public support.

Release CLI Plugins Skills GitHub Stars skills.sh Sponsor: Kobiton Buy me a monster

ko-fi

Version semantics: the release badge is this marketplace's display version. npm packages, including the ccpi CLI and publishable plugins, retain their own package versions; they are intentionally not expected to equal the display version. The version-surface checker governs the display surfaces without rewriting package semver.

Install

Inside Claude Code, one command installs the whole marketplace:

/plugin marketplace add jeremylongshore/claude-code-plugins

Or use the CLI:

pnpm add -g @intentsolutionsio/ccpi
ccpi install devops-automation-pack

Browse the marketplace · Explore plugins · Download bundles

Killer Skill of the Week — no-ai-slop by Peter Yang

Strip AI slop from any draft — named-pattern edits that keep the writer's real voice

no-ai-slop does two jobs and refuses to fake a third. In Edit mode it makes the minimum effective edit — cutting throat-clearing, weak verbs, and abstract nouns while deliberately preserving the writer's cadence, bluntness, humor, and honest admissions, so a rough draft still sounds like the same person afterward. In Detect mode it names each AI-slop pattern it finds, quotes the offending line, and gives the fix in a few words — and pointedly does NOT score the draft or guess whether an AI wrote it. That restraint is the whole point: AI detectors guess; named patterns are evidence the reader can check. MIT-licensed, single focused skill, actively maintained by Peter Yang.

"AI detectors guess. Named patterns are evidence the user can check." — Peter Yang

Grade: A | Week of July 22, 2026 (W30) | View on GitHub

Previous picks: tonone, mnemos, databricks-pack, kobiton-automate, skyvern, code-cleanup, web-analytics, token-optimizer, executive-assistant-skills, skill-creator, cursor-pack, crypto-portfolio-tracker. See all at tonsofskills.com.

Scale, labeled

Every number below names the cohort it counts and the command that reproduces it — an unlabeled count is how a corpus ends up with five contradictory answers to "how many skills."

CountCohortReproduce with
442catalog plugins (catalog-entry cohort)node scripts/generate-readme-toc.mjs over marketplace.extended.json
3,067marketplace-visible skills (distinct)node -e "import('./scripts/corpus-resolver.mjs').then(m=>console.log(m.resolveCorpus('marketplace-visible').length))"
347agent definitions in pluginsgit ls-files 'plugins/**' | grep '/agents/.*\.md'
19plugin categoriesls -d plugins/*/

📦 Live npm Downloads

Across 396 published packages in the claude-code-plugins namespace. Updated daily by GitHub Actions.

WindowAll packagesEstablished (>30d)
Last 24 hours962962
Last 7 days2,9202,916
Last 30 days12,86812,779

"Established" excludes packages first published within the last 30 days, so a bulk-publish event doesn't dominate the headline.

Top 10 by last 30 days:

#PackageLast 30d
1@intentsolutionsio/openrouter-pack556
2@intentsolutionsio/groq-pack496
3@intentsolutionsio/databricks-pack274
4@intentsolutionsio/clickhouse-pack273
5@intentsolutionsio/wallet-security-auditor263
6@intentsolutionsio/notion-pack258
7@intentsolutionsio/elevenlabs-pack244
8@intentsolutionsio/freshie-inventory-manager214
9@intentsolutionsio/supabase-pack210
10@intentsolutionsio/agency-os204

Last refreshed 2026-08-19T03:03:05.709Z.

Ways in

Five real questions, five doors — each resolves to a live, generated surface, never a hand-maintained list:

Browse by category

The 19 categories below link into the live marketplace. Plugin counts are the catalog-entry cohort — regenerated from marketplace.extended.json by this generator; the catalog itself lives on tonsofskills.com, never in this file (§ 6A of the platform blueprint).

CategoryPlugins
🤖AI & Machine Learning36
🎭AI Agents & Agency10
🔌API Development26
💼Business Tools6
👥Community21
₿Crypto & Web327
💾Database26
🎨Design2
🔧DevOps & Infrastructure36
📚Examples & Templates5
🧩MCP Servers16
📦Packages5
⚡Performance25
✅Productivity30
🎁SaaS Skill Packs106
🔐Security27
✨Skill Enhancers9
🧪Testing28
📁Analytics1

What the classes mean

Four artifact classes live in this repository, distinguished on sight and never blurred — provenance is a truth requirement here, not a UX nicety:

ClassWhat it isHow the reader can tell
Canonical skillFirst-party, harness-free, the source of truthNo .source.json in its plugin directory
Generated adapterA thin, machine-produced harness projectionLives under a generated path with a "generated — do not edit" header
First-party packageAn Intent Solutions distribution (npm, cowork zip)@intentsolutionsio scope, IS-authored license
Upstream mirrorSomebody else's work, hosted mirror-by-default.source.json present — upstream author, license, and pinned commit recorded

Certification

Not yet certified. The certification program (tiers T0–T4 with retained, hash-matched evidence) is a later epic of the platform blueprint; until its report exists, no artifact on this surface claims a tier. This line is rendered from the absence of certification-report.json — honestly, not cosmetically.

Contribute

Start with the contribution guide, then the intake and review standards every submission passes through:

Governance

Provenance

External plugins are hosted mirror-by-default: the contributor's repository stays the source of truth, every mirrored source is pinned in a content lockfile, and upstream credit — author, license, resolved commit — is recorded in the mirror itself. Improvements flow by upstreaming to the author's repository, never by silently editing the mirror. The full decision record is the external-sync model.

License

MIT for the repository scaffolding and first-party tooling; each plugin carries its own license in its manifest, and mirrored plugins keep their upstream license verbatim.

其他

中风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 可能需要外部 token、网络权限或第三方服务。
  • 未检测到高风险命令。
  • 扫描发现:3 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jeremylongshore/tons-of-skills-marketplace.git
  3. 将 "skills/.curated/databricks-bundle-medic" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jeremylongshore/tons-of-skills-marketplace.git
  3. 将 "skills/.curated/databricks-bundle-medic" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jeremylongshore/tons-of-skills-marketplace.git
  3. 将 "skills/.curated/databricks-bundle-medic" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jeremylongshore/tons-of-skills-marketplace.git
  3. 将 "skills/.curated/databricks-bundle-medic" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jeremylongshore/tons-of-skills-marketplace.git
  3. 将 "skills/.curated/databricks-bundle-medic" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: databricks-bundle-medic
description: |
  Fix the deploy-time foot-guns of Databricks Asset Bundles (DAB) and the
  infrastructure operations around them: the bundle-bind gap for UC catalogs and
  external locations, the "unexpected EOF reading terraform.tfstate" redeploy failure,
  the schema-GRANT-ordering bug that fails the first deploy, customer-managed-key (CMK)
  rotation that requires draining the whole workspace, and the PrivateLink cost leak
  where S3/STS/Kinesis still traverse the NAT. Includes a PreToolUse hook that backs up
  and validates the bundle's terraform state before every deploy, and a PostToolUse
  hook that recognises the transient GRANT-ordering failure and recommends a single
  retry. Use when a databricks bundle deploy fails, before rotating a CMK, when a UC
  resource cannot be bound to a bundle, or when auditing PrivateLink networking cost.
  Trigger with "bundle deploy failed", "unexpected EOF terraform.tfstate", "bundle bind
  external location", "User does not have CREATE TABLE on Schema", "rotate CMK",
  "privatelink still using NAT".
allowed-tools: Read, Write, Edit, Bash(databricks:*), Bash(terraform:*), Bash(jq:*), Bash(python3:*), Bash(bash:*), Glob, mcp__databricks-workspace-mcp__external_locations_list, mcp__databricks-workspace-mcp__storage_credentials_list
version: 2.27.0
author: Jeremy Longshore <jeremy@intentsolutions.io>
license: MIT
compatibility: Designed for Claude Code
tags: [saas, databricks, asset-bundles, deploy, infrastructure]

Databricks Bundle Medic

The deploy + infrastructure spine of the pack. Databricks Asset Bundles (DAB) is immature tooling — the replacement for the deprecated dbx, with a moving bug list across CLI versions — and the infrastructure operations around a deploy (encryption keys, networking, workspace config) bite production platform teams hardest. This skill turns the five worst deploy-time foot-guns into deterministic, reversible operations.

Overview

Five pains, all from the pack's deploy-ops research:

Asset Bundles (DAB). D4 — databricks bundle bind does NOT yet support UC catalogs or external locations (databricks/cli#4842), so existing UC resources cannot come under bundle management without hand-editing terraform.tfstate (hostile) or destroy-and-recreate (impossible with dependent tables). D5 — "unexpected EOF reading terraform.tfstate" on every redeploy after the first (databricks/cli#4986), which bricks the bundle until you switch to DATABRICKS_BUNDLE_ENGINE=direct. D6 — the schema GRANT-ordering bug (databricks/cli#4573): the first deploy to a fresh workspace fails with "User does not have CREATE TABLE on Schema", but the second succeeds because the first applied the grants before dying.

Deploy-time infrastructure. D8 — rotating a workspace's customer-managed key (CMK) requires terminating every cluster, instance pool, and SQL warehouse first: a hard maintenance window. D9 — the PrivateLink trap: enabling PrivateLink for the control plane is mistaken for "all traffic is private," but the data plane's S3 / STS / Kinesis calls still traverse the NAT, billing NAT-processing + cross-AZ transfer until each gets its own VPC endpoint.

The two hooks (this is the pack's only two-hook skill). A PreToolUse hook (hooks/bundle-deploy-guard.py) runs before every databricks bundle deploy: it validates the bundle's local terraform state parses as JSON, caches a timestamped known-good backup as a recovery escape hatch, and warns loudly if the state is corrupt or has shrunk (the D5 signature). A PostToolUse hook (hooks/bundle-grant-retry.py) watches a deploy's output and — ONLY on the exact D6 "does not have … on Schema" signature — adds context recommending one retry, with the reason. Both are advisory: the pre-hook never blocks a deploy, and the post-hook never masks a real error — it surfaces the diagnosis and stops recommending retries if the same failure persists.

Deterministic work lives in scripts/; deep knowledge in references/. The import-uc-resource-to-bundle.py D4 workaround is self-deprecating — it exists only until #4842 closes and says so. Control-plane state comes from the databricks-workspace-mcp server (external_locations_list, storage_credentials_list) or the CLI; advisory-mode fallback accepts pasted input.

Prerequisites

  • Databricks CLI authenticated, plus terraform and jq on PATH — for the bundle, import, and state operations.
  • databricks-workspace-mcp registered (optional) — for external_locations_list and storage_credentials_list. Absent → the CLI (databricks external-locations list) or advisory mode on pasted input.
  • Account-level OAuth M2M (service principal) for CMK rotation — the D8 operations are account-scoped; a workspace PAT is insufficient. AWS/Azure/GCP CLI for the cloud-side key + VPC-endpoint work.
  • The two hooks are plugin-level — installed with the pack. The pre-hook is silent unless a state looks corrupt; the post-hook is silent unless the exact D6 error fires.

Instructions

Pick the flow by symptom. Always name the exact error string / issue id — unexpected EOF reading terraform.tfstate (#4986), does not have CREATE TABLE on Schema (#4573), the bundle bind UC gap (#4842) — an operator greps for those.

Step 1: A bundle deploy that fails on state (D5)

"unexpected EOF reading terraform.tfstate" after the first deploy is #4986. The bundle-deploy-guard PreToolUse hook already cached a known-good backup; restore it, or switch engines:

DATABRICKS_BUNDLE_ENGINE=direct databricks bundle deploy -t "$TARGET"

Engine tradeoffs + the migration steps: ${CLAUDE_SKILL_DIR}/references/bundle-engine-tradeoffs.md.

Step 2: First deploy fails "does not have CREATE TABLE on Schema" (D6)

This is the transient GRANT-ordering bug (#4573). The bundle-grant-retry PostToolUse hook flags it; re-run the SAME deploy exactly once — the failed first pass already applied the grants. If the identical error persists after one retry, it is NOT this transient — treat it as a real missing privilege and stop retrying.

Step 3: A UC resource that will not bind (D4)

databricks bundle bind cannot take a UC catalog or external location yet (#4842). Generate a review-first Terraform import plan (never hand-edit state):

python3 "${CLAUDE_SKILL_DIR}/scripts/import-uc-resource-to-bundle.py" \
  --type external_location --name raw_zone --resource-key raw_zone_loc

The three workarounds, ranked by risk: ${CLAUDE_SKILL_DIR}/references/uc-resource-binding-workarounds.md.

Step 4: Rotate a customer-managed key (D8)

CMK rotation needs the whole workspace drained. Inventory the running compute (via external_locations_list / the CLI), then plan the drain — dry-run by default:

databricks clusters list --output json > /tmp/inv-clusters.json   # + warehouses, pools
python3 "${CLAUDE_SKILL_DIR}/scripts/drain-workspace.py" --inventory inv.json          # dry-run
python3 "${CLAUDE_SKILL_DIR}/scripts/drain-workspace.py" --inventory inv.json --execute --manifest drain.json
# ... rotate the CMK per cloud, then:
python3 "${CLAUDE_SKILL_DIR}/scripts/drain-workspace.py" --resume drain.json

Per-cloud playbooks (AWS/Azure/GCP): ${CLAUDE_SKILL_DIR}/references/cmk-rotation-by-cloud.md.

Step 5: Audit the PrivateLink cost leak (D9)

PrivateLink covers the control plane only. Audit the data-plane VPC for the S3/STS/Kinesis endpoints and emit remediation Terraform for any that are missing:

python3 "${CLAUDE_SKILL_DIR}/scripts/audit-vpc-endpoints.py" \
  --present s3 --vpc-id vpc-abc --region us-east-1 --emit-terraform

The full per-service leak/fix map: ${CLAUDE_SKILL_DIR}/references/cost-leak-map.md.

Output

  • A hook backup + advisory — before each deploy, a validated known-good state backup and, if the state is corrupt/shrunk, the #4986 recovery message.
  • A retry recommendation — on the exact D6 signature, a one-retry recommendation with the reason (never a masked error).
  • A UC import plan — the resources: YAML + Terraform import block/command to adopt an existing UC resource, with the self-deprecation notice.
  • A drain / resume plan — the idempotent list of compute to terminate for CMK rotation and the manifest to resume exactly what was drained.
  • A VPC-endpoint verdict — SAFE or a COST LEAK finding naming the missing S3/STS/Kinesis endpoints, with remediation Terraform.

Error Handling

ErrorCauseSolution
unexpected EOF reading terraform.tfstateTerraform-engine state read bug on redeploy (D5, #4986)Restore the guard's cached backup, or DATABRICKS_BUNDLE_ENGINE=direct.
User does not have CREATE TABLE on Schema '…'DAB GRANT-ordering (D6, #4573)Re-run the deploy once; grants were applied by the failed pass. Persists after one retry → real missing grant.
bundle bind rejects a UC catalog / external locationUnsupported in the CLI (D4, #4842)Use import-uc-resource-to-bundle.py to generate a Terraform import plan; never hand-edit state.
CMK rotation rejected — compute still runningCMK update requires a drained workspace (D8)drain-workspace.py --execute, rotate, then --resume.
High NAT / cross-AZ cost after PrivateLinkS3/STS/Kinesis have no VPC endpoint (D9)audit-vpc-endpoints.py --emit-terraform; add Gateway (S3) + Interface (STS/Kinesis) endpoints.

Examples

Example 1: "My second bundle deploy fails with unexpected EOF reading terraform.tfstate."

D5 (#4986). The bundle-deploy-guard hook already cached a known-good state before the deploy — restore it, then redeploy with DATABRICKS_BUNDLE_ENGINE=direct (the direct engine never reads the state file, so the EOF class cannot fire).

Example 2: "First deploy to a fresh workspace: User does not have CREATE TABLE on Schema."

D6 (#4573). The bundle-grant-retry hook recognises the exact signature and recommends one retry — the failed first deploy applied the schema grants, so the second succeeds.

Example 3: "I need to bring an existing external location under my bundle."

D4 (#4842) — bundle bind can't. import-uc-resource-to-bundle.py --type external_location emits the resources: YAML plus a Terraform import block to adopt it without recreating it or hand-editing state. The script self-deprecates when #4842 closes.

Example 4: "We turned on PrivateLink but the NAT bill went up."

D9. audit-vpc-endpoints.py --present s3 finds STS and Kinesis have no Interface endpoint, so credential-vending and log traffic still cross the NAT — it emits the remediation Terraform for both.

Resources

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!