Token导航 LogoToken导航TokenDH.com
开发需要联网github未标认证来源可访问许可证需确认审计通过

drill-recovery钻恢复

Agent Skill

drill-recovery 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

588

周安装

24

GitHub Stars

12

下载量

190
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:drill-recovery(钻恢复)
来源仓库:https://github.com/quangrau/vibekit
仓库路径:skills/drill-recovery
安装命令:
npx skills add https://github.com/quangrau/vibekit --skill drill-recovery
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/quangrau/vibekit --skill drill-recovery

简介

drill-recovery 提供面向独立 Web 应用的灾难恢复演练场景与安全检查清单,强调实战韧性。

  • 聚焦 SPA、SSR 与全栈项目,覆盖备份策略、故障转移、监控告警与数据恢复流程设计。
  • 采用渐进式学习路径,从项目上下文读取到技术栈扫描,逐步构建高可用架构认知。
  • 适用于个人开发者与小团队,避免复杂运维术语,注重可落地与低成本实践原则。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Disaster Recovery Drills

Disaster drill scenarios and security checklists for indie web apps. Teaches big-tech resilience principles through indie-scale practice.

Scope: Web applications only (SPA, SSR, full-stack). Not mobile, desktop, CLI, or games. Audience: Solo devs, indie builders, vibe-coders. No corporate jargon.

Workflow

Step 1: Read Project Context

Read the project's context file to understand the codebase:

  • Look for CLAUDE.md, GEMINI.md, or AGENTS.md at the project root
  • If none found, ask the human to describe their project briefly

Step 2: Scan Project Stack

Scan the project directly using your file tools. Gather:

From package.json:

  • Framework (next.js, vite-react, nuxt, sveltekit, remix, astro, etc.)
  • Database SDK (@supabase/supabase-js, firebase, prisma, drizzle, mongoose)
  • Auth (supabase-auth, nextauth, lucia, clerk)
  • Payments (stripe, lemonsqueezy)
  • AI APIs (openai, @anthropic-ai/sdk, @google/generative-ai)
  • Monitoring (@sentry/react, dd-trace, logrocket)

From project files:

  • Hosting config (vercel.json, wrangler.toml, netlify.toml, fly.toml)
  • TypeScript (tsconfig.json)
  • CI/CD (.github/workflows/)
  • Edge functions (supabase/functions/*)
  • Database tables (from supabase/migrations/ or prisma/schema.prisma)
  • Storage buckets (from migrations or storage config)

From env/security files:

  • .gitignore covers.env files?
  • Client-side env vars (NEXT_PUBLIC_*, VITE_*) — flag only if they contain actual secrets, not public-by-design keys like anon keys or site keys
  • CSP headers configured? (check _headers, middleware, next.config)
  • RLS enabled? (check migration files for ENABLE ROW LEVEL SECURITY)

If no project files are available, ask 3-5 quick questions: stack, hosting, database, users, backups.

Step 3: Load Previous State

Check for docs/.dr-state.json. This tracks completed items across runs.

{
  "last_run": "2026-02-21",
  "checklist_completed": ["monitoring_added", "ci_pipeline_added"],
  "drills_completed": [
    { "domain": "secrets", "difficulty": "beginner", "date": "2026-02-21" }
  ],
  "runbook_exists": true,
  "postmortem_exists": false,
  "stack_snapshot": {
    "edge_functions": ["advance-game", "submit-answer"],
    "tables": ["users", "questions", "game_sessions"],
    "services": ["supabase", "cloudflare", "resend"],
    "storage_buckets": ["question-images"]
  }
}

If it exists:

  • Skip checklist items in checklist_completed — these are items the human confirmed they fixed, NOT items that were already safe at scan time. Items that are "already safe" (e.g., RLS enabled, CSP configured) are handled by the conciseness rules — the agent re-scans and re-skips them naturally every run. Never auto-populate checklist_completed.
  • Skip drill domains already done at that difficulty
  • Don't re-ask about runbook/postmortem if already created
  • Show a brief "Previously completed" summary

Only add to checklist_completed when the human explicitly confirms they fixed an action item (e.g., "I added Sentry" → add "monitoring_added").

If it doesn't exist, this is a first run — create it after this session.

Step 4: Choose Mode

Present two options:

📋 CHECKLIST — "Am I prepared?" Proactive audit with prioritized fixes. Best for: first-time use, new projects, pre-launch, quarterly review.

🔥 EXERCISE DRILL — "Can I handle it?" Simulated incident in three phases:

  • Before: Prep your playbook, confirm monitoring, define stop conditions
  • During: Scenario injects with pause-and-think prompts
  • After: Observation log, follow-up TODOs with deadlines Best for: after basics are solid, building muscle memory, testing response speed. Solo devs play all roles: incident commander, service owner, on-call, comms lead.

Recommend Checklist first if the user has never done this.

Step 5: Generate & Write Persistent Doc

Generate the output AND write it to docs/. The file is the real deliverable.

File path: docs/DR_<MODE>_<DATE>.md

  • Checklist → docs/DR_CHECKLIST_2026-02-21.md
  • Drill → docs/DR_DRILL_<DOMAIN>_2026-02-21.md

Tone: Notes to future me at 2am. Practical, direct, copy-paste-friendly.

Conciseness rules:

  • Only include items that need action. If something is safe or properly configured, skip it entirely. No "this is fine" entries.
  • Skip items already completed in .dr-state.json
  • Every section must earn its place. Empty = omit.

Checklist doc structure

# <Project Name> — DR Checklist

> **Version**: 1.0
> **Created**: <date>
> **Profile**: <framework> / <hosting> / <database>

## Recovery Targets

| Metric | Target | Why |
|--------|--------|-----|
| **RTO** | < X hour | <1 sentence> |
| **RPO** | < X hours | <1 sentence> |

### What matters most

| Tier | Data | Recovery |
|------|------|----------|
| Critical | <actual tables> | <method> |
| Can rebuild | <derived data> | <method> |
| Expendable | <ephemeral data> | Restart |

## Your Stack

<ASCII diagram — keep it simple, only real services>

### Weak spots

<Only single points of failure with no mitigation yet. Skip if none.>

## Action Items

<Only items needing action. Severity first, then quick wins.>

| # | What | How | Effort |
|---|------|-----|--------|
| 1 | <problem> | <specific fix with command> | ⚡/🔧 |

## Readiness

<Scores — only domains below 8/10. If solid, skip it.>

Drill doc structure

Keep it concise. The doc is a practice exercise, not a textbook. Teach through the scenario itself, not extra sections explaining concepts.

# <Project Name> — Drill: <Vivid Scenario Title>

> **Domain**: <emoji> <domain> | **Difficulty**: <level> | **Created**: <date>

## Before you start

<3-4 honest self-check questions. Short. No fluff.>

## Scenario

<Background — 2-3 sentences setting the scene with real stack details.>

### ⏱️ INJECT 1 — <timestamp>

<What happened. Real error messages, real service names, real URLs.
End with 1-2 pause-and-think questions in bold.>

### ⏱️ INJECT 2 — <timestamp>

<Escalation or new info. Same format.>

## Resolution

**Right now:** <commands>
**Today:** <stabilize>
**This week:** <prevent recurrence>

## TODOs

| # | What | Deadline | Done? |
|---|------|----------|-------|
| 1 | ... | This week | ☐ |

**The takeaway:** <1-2 sentences. What big-tech calls this, what to
actually do at indie scale. No jargon walls.>

*Next suggested drill: <pick untried domain from .dr-state.json>*

Drill domains

Pick from these 7 domains (or random weighted by detected risks):

  • cost — 💸 Cost & Billing (DDoS, billing spikes, API abuse)
  • data — 🗑️ Data Loss (backup failure, accidental delete, corruption)
  • secrets — 🔐 Secrets & Credentials (leaked keys, rotation)
  • access — 🔓 Access Control (broken auth, IDOR, missing RLS)
  • availability — 🚫 Availability (outage, deploy failure, DNS)
  • code — 🤖 Code Vulnerabilities (XSS, SQLi, dependency CVEs)
  • recovery — 🔄 Recoverability (rebuild from scratch, lost env vars)

Difficulty controls inject count:

  • beginner: 2 injects, ~15 min
  • intermediate: 3 injects, ~20 min
  • advanced: 4 injects, ~30 min

Read references/risk-domains.md for extra scenario seeds and checklist items if you need more variety.

Step 6: Offer Follow-Up Docs

After writing the main doc, ask the human — don't assume:

  1. Runbook drift check: Check if docs/RUNBOOK.md exists.

- If no → ask: "Want me to write a docs/RUNBOOK.md with step-by-step recovery commands for your stack?" Only write if they say yes. - If yes → compare current stack against stack_snapshot in .dr-state.json (or scan runbook content if no state file). Look for: - New edge functions not in the runbook - New tables not covered by recovery scenarios - New services with no runbook entry - Removed components still referenced - If drift found → tell human: "Your docs/RUNBOOK.md is missing coverage for: X, Y. Want me to update it?" - If no drift → skip silently

  1. Post-mortem (Drill mode only): Ask: "Want me to save a post-mortem to docs/POSTMORTEM_<DOMAIN>_<DATE>.md? Useful to track patterns." Only write if they say yes.
  2. Backup script: If no backup strategy detected, ask: "Want me to generate a scripts/dr-backup.sh?" Only write if they say yes.

Update docs/.dr-state.json after each run:

  • checklist_completed / drills_completed for this session
  • stack_snapshot with current edge functions, tables, services, buckets
  • runbook_exists / postmortem_exists flags

Step 7: Follow Up

  • For Checklist: offer to generate fix code for top action items
  • For Drill: offer to implement the top TODO right now
  • Suggest next drill: pick an untried domain from .dr-state.json
  • Remind: "Run this again next quarter — I'll skip what you've already fixed."

Reference Files

The references/ directory has supplemental content for deeper scenarios:

  • references/risk-domains.md — All 7 risk domains with extra scenario seeds and checklist item libraries

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.47%
按下载量换算67

Claude

28.75%
按下载量换算55

Cursor

16.87%
按下载量换算32

Gemini CLI

9.65%
按下载量换算18

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills