By tonone-ai
Audit infrastructure-as-code files and cloud configurations for security vulnerabilities, reliability gaps, and cost inefficiencies across Terraform, Pulumi, Kubernetes, CloudFormation, AWS, and GCP.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub tonone-ai/tonone --plugin forge-auditInfrastructure engineer — cloud services, networking, IaC, cost optimization
Pre-deployment checks, configuration validation, and deployment readiness assessment
Infrastructure maintenance with security audits and update management
Research-backed, opinionated guidance for building cloud infrastructure that doesn't rot — multi-account governance, naming conventions, IaC organization, security, deployment pipelines, and operational hygiene, distilled from production experience across multiple cloud migrations
Perform an AWS Well-Architected Framework review of a workload's IaC and architecture, generating findings and GitHub issues for improvements.
Find security misconfigurations
Design and build networking infrastructure — VPCs, subnets, DNS, load balancers, firewall rules. Use when asked to "set up networking", "VPC design", "configure DNS", "load balancer setup", "network architecture", or "firewall rules".
Generate onboarding documentation — what this project does, how to set up locally, where things live, key decisions, how to deploy. Written for day-one engineers who know nothing. Use when asked for "onboarding docs", "new engineer guide", "how to get started", or "developer setup".
Implement a reusable, accessible, typed component from a design spec. Use when asked to "create a component", "build a widget", "implement this design", or "reusable UI element".
Verify observability posture — audit monitoring coverage, find blind spots, prioritize gaps. Use when asked "is monitoring sufficient", "observability review", "are we covered", or "pre-launch monitoring check".
ML reconnaissance — inventory all models, pipelines, data sources, and monitoring. Use when asked "what ML do we have", "model inventory", or "ML assessment".