复制安装命令
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
A model-agnostic agent-skills platform.
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
来源文件:README.md
A model-agnostic agent-skills platform. The canonical layer is harness-free by construction; Claude Code is currently the verified-native harness. Other harnesses remain engineering candidates until their native-path integration is verified; source research alone is never presented as public support.
Version semantics: the release badge is this marketplace's display version. npm packages, including the
ccpiCLI and publishable plugins, retain their own package versions; they are intentionally not expected to equal the display version. The version-surface checker governs the display surfaces without rewriting package semver.
Inside Claude Code, one command installs the whole marketplace:
/plugin marketplace add jeremylongshore/claude-code-plugins
Or use the CLI:
pnpm add -g @intentsolutionsio/ccpi
ccpi install devops-automation-pack
Browse the marketplace · Explore plugins · Download bundles
Killer Skill of the Week — no-ai-slop by Peter Yang
Strip AI slop from any draft — named-pattern edits that keep the writer's real voice
no-ai-slop does two jobs and refuses to fake a third. In Edit mode it makes the minimum effective edit — cutting throat-clearing, weak verbs, and abstract nouns while deliberately preserving the writer's cadence, bluntness, humor, and honest admissions, so a rough draft still sounds like the same person afterward. In Detect mode it names each AI-slop pattern it finds, quotes the offending line, and gives the fix in a few words — and pointedly does NOT score the draft or guess whether an AI wrote it. That restraint is the whole point: AI detectors guess; named patterns are evidence the reader can check. MIT-licensed, single focused skill, actively maintained by Peter Yang.
"AI detectors guess. Named patterns are evidence the user can check." — Peter Yang
Grade: A | Week of July 22, 2026 (W30) | View on GitHub
Previous picks: tonone, mnemos, databricks-pack, kobiton-automate, skyvern, code-cleanup, web-analytics, token-optimizer, executive-assistant-skills, skill-creator, cursor-pack, crypto-portfolio-tracker. See all at tonsofskills.com.
Every number below names the cohort it counts and the command that reproduces it — an unlabeled count is how a corpus ends up with five contradictory answers to "how many skills."
| Count | Cohort | Reproduce with |
|---|---|---|
| 442 | catalog plugins (catalog-entry cohort) | node scripts/generate-readme-toc.mjs over marketplace.extended.json |
| 3,067 | marketplace-visible skills (distinct) | node -e "import('./scripts/corpus-resolver.mjs').then(m=>console.log(m.resolveCorpus('marketplace-visible').length))" |
| 347 | agent definitions in plugins | git ls-files 'plugins/**' | grep '/agents/.*\.md' |
| 19 | plugin categories | ls -d plugins/*/ |
Across 396 published packages in the claude-code-plugins namespace. Updated daily by GitHub Actions.
| Window | All packages | Established (>30d) |
|---|---|---|
| Last 24 hours | 962 | 962 |
| Last 7 days | 2,920 | 2,916 |
| Last 30 days | 12,868 | 12,779 |
"Established" excludes packages first published within the last 30 days, so a bulk-publish event doesn't dominate the headline.
Top 10 by last 30 days:
Last refreshed 2026-08-19T03:03:05.709Z.
Five real questions, five doors — each resolves to a live, generated surface, never a hand-maintained list:
The 19 categories below link into the live marketplace. Plugin counts are the catalog-entry cohort — regenerated from marketplace.extended.json by this generator; the catalog itself lives on tonsofskills.com, never in this file (§ 6A of the platform blueprint).
| Category | Plugins | |
|---|---|---|
| 🤖 | AI & Machine Learning | 36 |
| 🎭 | AI Agents & Agency | 10 |
| 🔌 | API Development | 26 |
| 💼 | Business Tools | 6 |
| 👥 | Community | 21 |
| ₿ | Crypto & Web3 | 27 |
| 💾 | Database | 26 |
| 🎨 | Design | 2 |
| 🔧 | DevOps & Infrastructure | 36 |
| 📚 | Examples & Templates | 5 |
| 🧩 | MCP Servers | 16 |
| 📦 | Packages | 5 |
| ⚡ | Performance | 25 |
| ✅ | Productivity | 30 |
| 🎁 | SaaS Skill Packs | 106 |
| 🔐 | Security | 27 |
| ✨ | Skill Enhancers | 9 |
| 🧪 | Testing | 28 |
| 📁 | Analytics | 1 |
Four artifact classes live in this repository, distinguished on sight and never blurred — provenance is a truth requirement here, not a UX nicety:
| Class | What it is | How the reader can tell |
|---|---|---|
| Canonical skill | First-party, harness-free, the source of truth | No .source.json in its plugin directory |
| Generated adapter | A thin, machine-produced harness projection | Lives under a generated path with a "generated — do not edit" header |
| First-party package | An Intent Solutions distribution (npm, cowork zip) | @intentsolutionsio scope, IS-authored license |
| Upstream mirror | Somebody else's work, hosted mirror-by-default | .source.json present — upstream author, license, and pinned commit recorded |
Not yet certified. The certification program (tiers T0–T4 with retained, hash-matched evidence) is a later epic of the platform blueprint; until its report exists, no artifact on this surface claims a tier. This line is rendered from the absence of certification-report.json — honestly, not cosmetically.
Start with the contribution guide, then the intake and review standards every submission passes through:
External plugins are hosted mirror-by-default: the contributor's repository stays the source of truth, every mirrored source is pinned in a content lockfile, and upstream credit — author, license, resolved commit — is recorded in the mirror itself. Improvements flow by upstreaming to the author's repository, never by silently editing the mirror. The full decision record is the external-sync model.
MIT for the repository scaffolding and first-party tooling; each plugin carries its own license in its manifest, and mirrored plugins keep their upstream license verbatim.
name: databricks-bundle-medic
description: |
Fix the deploy-time foot-guns of Databricks Asset Bundles (DAB) and the
infrastructure operations around them: the bundle-bind gap for UC catalogs and
external locations, the "unexpected EOF reading terraform.tfstate" redeploy failure,
the schema-GRANT-ordering bug that fails the first deploy, customer-managed-key (CMK)
rotation that requires draining the whole workspace, and the PrivateLink cost leak
where S3/STS/Kinesis still traverse the NAT. Includes a PreToolUse hook that backs up
and validates the bundle's terraform state before every deploy, and a PostToolUse
hook that recognises the transient GRANT-ordering failure and recommends a single
retry. Use when a databricks bundle deploy fails, before rotating a CMK, when a UC
resource cannot be bound to a bundle, or when auditing PrivateLink networking cost.
Trigger with "bundle deploy failed", "unexpected EOF terraform.tfstate", "bundle bind
external location", "User does not have CREATE TABLE on Schema", "rotate CMK",
"privatelink still using NAT".
allowed-tools: Read, Write, Edit, Bash(databricks:*), Bash(terraform:*), Bash(jq:*), Bash(python3:*), Bash(bash:*), Glob, mcp__databricks-workspace-mcp__external_locations_list, mcp__databricks-workspace-mcp__storage_credentials_list
version: 2.27.0
author: Jeremy Longshore <jeremy@intentsolutions.io>
license: MIT
compatibility: Designed for Claude Code
tags: [saas, databricks, asset-bundles, deploy, infrastructure]The deploy + infrastructure spine of the pack. Databricks Asset Bundles (DAB) is
immature tooling — the replacement for the deprecated dbx, with a moving bug list
across CLI versions — and the infrastructure operations around a deploy (encryption
keys, networking, workspace config) bite production platform teams hardest. This skill
turns the five worst deploy-time foot-guns into deterministic, reversible operations.
Five pains, all from the pack's deploy-ops research:
Asset Bundles (DAB). D4 — databricks bundle bind does NOT yet support UC catalogs
or external locations (databricks/cli#4842), so existing UC resources cannot come under
bundle management without hand-editing terraform.tfstate (hostile) or
destroy-and-recreate (impossible with dependent tables). D5 — "unexpected EOF reading
terraform.tfstate" on every redeploy after the first (databricks/cli#4986), which bricks
the bundle until you switch to DATABRICKS_BUNDLE_ENGINE=direct. D6 — the schema
GRANT-ordering bug (databricks/cli#4573): the first deploy to a fresh workspace fails
with "User does not have CREATE TABLE on Schema", but the second succeeds because the
first applied the grants before dying.
Deploy-time infrastructure. D8 — rotating a workspace's customer-managed key (CMK) requires terminating every cluster, instance pool, and SQL warehouse first: a hard maintenance window. D9 — the PrivateLink trap: enabling PrivateLink for the control plane is mistaken for "all traffic is private," but the data plane's S3 / STS / Kinesis calls still traverse the NAT, billing NAT-processing + cross-AZ transfer until each gets its own VPC endpoint.
The two hooks (this is the pack's only two-hook skill). A PreToolUse hook
(hooks/bundle-deploy-guard.py) runs before every databricks bundle deploy: it
validates the bundle's local terraform state parses as JSON, caches a timestamped
known-good backup as a recovery escape hatch, and warns loudly if the state is corrupt
or has shrunk (the D5 signature). A PostToolUse hook (hooks/bundle-grant-retry.py)
watches a deploy's output and — ONLY on the exact D6 "does not have … on Schema"
signature — adds context recommending one retry, with the reason. Both are advisory:
the pre-hook never blocks a deploy, and the post-hook never masks a real error — it
surfaces the diagnosis and stops recommending retries if the same failure persists.
Deterministic work lives in scripts/; deep knowledge in references/. The
import-uc-resource-to-bundle.py D4 workaround is self-deprecating — it exists only
until #4842 closes and says so. Control-plane state comes from the
databricks-workspace-mcp server (external_locations_list, storage_credentials_list)
or the CLI; advisory-mode fallback accepts pasted input.
terraform and jq on PATH — for the bundle,
import, and state operations.databricks-workspace-mcp registered (optional) — for external_locations_list
and storage_credentials_list. Absent → the CLI (databricks external-locations list) or advisory mode on pasted input.Pick the flow by symptom. Always name the exact error string / issue id —
unexpected EOF reading terraform.tfstate (#4986), does not have CREATE TABLE on Schema (#4573), the bundle bind UC gap (#4842) — an operator greps for those.
"unexpected EOF reading terraform.tfstate" after the first deploy is #4986. The
bundle-deploy-guard PreToolUse hook already cached a known-good backup; restore it,
or switch engines:
DATABRICKS_BUNDLE_ENGINE=direct databricks bundle deploy -t "$TARGET"
Engine tradeoffs + the migration steps:
${CLAUDE_SKILL_DIR}/references/bundle-engine-tradeoffs.md.
This is the transient GRANT-ordering bug (#4573). The bundle-grant-retry PostToolUse
hook flags it; re-run the SAME deploy exactly once — the failed first pass already
applied the grants. If the identical error persists after one retry, it is NOT this
transient — treat it as a real missing privilege and stop retrying.
databricks bundle bind cannot take a UC catalog or external location yet (#4842).
Generate a review-first Terraform import plan (never hand-edit state):
python3 "${CLAUDE_SKILL_DIR}/scripts/import-uc-resource-to-bundle.py" \
--type external_location --name raw_zone --resource-key raw_zone_loc
The three workarounds, ranked by risk:
${CLAUDE_SKILL_DIR}/references/uc-resource-binding-workarounds.md.
CMK rotation needs the whole workspace drained. Inventory the running compute (via
external_locations_list / the CLI), then plan the drain — dry-run by default:
databricks clusters list --output json > /tmp/inv-clusters.json # + warehouses, pools
python3 "${CLAUDE_SKILL_DIR}/scripts/drain-workspace.py" --inventory inv.json # dry-run
python3 "${CLAUDE_SKILL_DIR}/scripts/drain-workspace.py" --inventory inv.json --execute --manifest drain.json
# ... rotate the CMK per cloud, then:
python3 "${CLAUDE_SKILL_DIR}/scripts/drain-workspace.py" --resume drain.json
Per-cloud playbooks (AWS/Azure/GCP):
${CLAUDE_SKILL_DIR}/references/cmk-rotation-by-cloud.md.
PrivateLink covers the control plane only. Audit the data-plane VPC for the S3/STS/Kinesis endpoints and emit remediation Terraform for any that are missing:
python3 "${CLAUDE_SKILL_DIR}/scripts/audit-vpc-endpoints.py" \
--present s3 --vpc-id vpc-abc --region us-east-1 --emit-terraform
The full per-service leak/fix map:
${CLAUDE_SKILL_DIR}/references/cost-leak-map.md.
resources: YAML + Terraform import block/command to
adopt an existing UC resource, with the self-deprecation notice.| Error | Cause | Solution |
|---|---|---|
unexpected EOF reading terraform.tfstate | Terraform-engine state read bug on redeploy (D5, #4986) | Restore the guard's cached backup, or DATABRICKS_BUNDLE_ENGINE=direct. |
User does not have CREATE TABLE on Schema '…' | DAB GRANT-ordering (D6, #4573) | Re-run the deploy once; grants were applied by the failed pass. Persists after one retry → real missing grant. |
bundle bind rejects a UC catalog / external location | Unsupported in the CLI (D4, #4842) | Use import-uc-resource-to-bundle.py to generate a Terraform import plan; never hand-edit state. |
| CMK rotation rejected — compute still running | CMK update requires a drained workspace (D8) | drain-workspace.py --execute, rotate, then --resume. |
| High NAT / cross-AZ cost after PrivateLink | S3/STS/Kinesis have no VPC endpoint (D9) | audit-vpc-endpoints.py --emit-terraform; add Gateway (S3) + Interface (STS/Kinesis) endpoints. |
bundle deploy fails with unexpected EOF reading terraform.tfstate."D5 (#4986). The bundle-deploy-guard hook already cached a known-good state before the
deploy — restore it, then redeploy with DATABRICKS_BUNDLE_ENGINE=direct (the direct
engine never reads the state file, so the EOF class cannot fire).
D6 (#4573). The bundle-grant-retry hook recognises the exact signature and recommends
one retry — the failed first deploy applied the schema grants, so the second succeeds.
D4 (#4842) — bundle bind can't. import-uc-resource-to-bundle.py --type external_location emits the resources: YAML plus a Terraform import block to adopt
it without recreating it or hand-editing state. The script self-deprecates when #4842 closes.
D9. audit-vpc-endpoints.py --present s3 finds STS and Kinesis have no Interface
endpoint, so credential-vending and log traffic still cross the NAT — it emits the
remediation Terraform for both.
${CLAUDE_SKILL_DIR}/references/uc-resource-binding-workarounds.md — the D4 bundle bind gap + 3 ranked workarounds (#4842).${CLAUDE_SKILL_DIR}/references/bundle-engine-tradeoffs.md — Terraform vs direct engine, the D5 EOF bug (#4986).${CLAUDE_SKILL_DIR}/references/cmk-rotation-by-cloud.md — AWS/Azure/GCP CMK rotation playbooks + the drain requirement (D8).${CLAUDE_SKILL_DIR}/references/cost-leak-map.md — the PrivateLink S3/STS/Kinesis NAT cost leak + fix map (D9).${CLAUDE_SKILL_DIR}/scripts/import-uc-resource-to-bundle.py — self-deprecating UC-resource import-plan generator (D4).${CLAUDE_SKILL_DIR}/scripts/drain-workspace.py — idempotent drain + resume for CMK rotation (D8).${CLAUDE_SKILL_DIR}/scripts/audit-vpc-endpoints.py — VPC-endpoint audit + remediation Terraform (D9).${CLAUDE_SKILL_DIR}/hooks/bundle-deploy-guard.py — PreToolUse state backup + validation (D5).${CLAUDE_SKILL_DIR}/hooks/bundle-grant-retry.py — PostToolUse D6 retry recommendation (D6).
评论 (0)
暂无评论,成为第一个评论者吧!