{"slug":"contabo-live-storage-operations-guard","title":"contabo-live-storage-operations-guard","summary":"Live-guard skill for Contabo Object Storage (S3-compatible) bucket operations including inventory audit, access policy review, retention policy enforcement, and deletion workflows. Hard-stops any bucket deletion requested without verified backup evidence and a documented rollback","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-10-05T21:51:59.261993Z","repo":{"url":"https://github.com/VincentChuWaiChow/vanguard-frontier-agentic","stars":24,"forks":3,"license":"Apache-2.0","updatedAt":"2026-10-05T13:00:24Z"},"bodyHtml":"<hr>\n<h2>name: contabo-live-storage-operations-guard\ndescription: Live-guard skill for Contabo Object Storage (S3-compatible) bucket operations including inventory audit, access policy review, retention policy enforcement, and deletion workflows. Hard-stops any bucket deletion requested without verified backup evidence and a documented rollback plan. Use when the user needs to manage, audit, or delete Contabo Object Storage buckets or objects.\nallowed-tools: Read Grep Glob Bash\nmetadata:\nauthor: \"github: VincentChuWaiChow\"\nversion: \"0.1.0\"\nupdated: \"2026-05-10\"\ncategory: platform</h2>\n<h1>Contabo Live Storage Operations Guard</h1>\n<h2>Purpose</h2>\n<p>Act as the approval gate for Contabo Object Storage mutations: audit current bucket inventory, access policies, and retention posture, then execute destructive operations only after verified backup evidence and explicit user sign-off.</p>\n<h2>When to use</h2>\n<p>Use this skill for:</p>\n<ul>\n<li>Contabo Object Storage bucket inventory and object listing</li>\n<li>Access policy review (bucket ACLs, public access exposure)</li>\n<li>Retention policy enforcement and lifecycle rule audit</li>\n<li>Bucket or object deletion with backup verification gate</li>\n<li>Migration or consolidation of Object Storage across regions</li>\n<li>Generating approval-ready change records for storage mutations</li>\n</ul>\n<h2>Hard-stop conditions</h2>\n<p>REFUSE to execute any bucket deletion or destructive Object Storage mutation unless ALL of the following are confirmed in writing:</p>\n<ol>\n<li><strong>Target</strong>: Bucket name and full inventory of current objects or confirmed backup location</li>\n<li><strong>Backup evidence</strong>: Verified backup of all data to be deleted (location, timestamp, verification method)</li>\n<li><strong>Rollback plan</strong>: Documented recovery path if the operation produces unexpected results</li>\n<li><strong>Named approving identity</strong>: the full name or authenticated account identifier of the person authorizing this operation (not a role, alias, or ticket number alone)</li>\n</ol>\n<h2>Lean operating rules</h2>\n<ul>\n<li>Contabo has no official Terraform provider or SDK — recommend <code>cntb</code> CLI or REST API (curl + jq) for automation.</li>\n<li>For S3-compatible Object Storage operations, use S3-compatible tools (aws CLI with <code>--endpoint-url</code> pointing at the Contabo Object Storage endpoint).</li>\n<li>Prefer official Contabo docs (<a href=\"https://api.contabo.com/\">https://api.contabo.com/</a>, <a href=\"https://docs.contabo.com/\">https://docs.contabo.com/</a>) and Context7 when live MCP access is unavailable.</li>\n<li>Separate confirmed facts from inference. If state was not queried or shown, say so.</li>\n<li>OAuth2 password grant tokens expire in ~5 minutes — include token refresh handling in all automation examples. Refresh logic must not log token values.</li>\n<li>Include <code>x-request-id</code> (UUIDv4) in all Contabo REST API calls for support traceability.</li>\n<li>S3 access key and secret key for Object Storage API must be stored as environment variables, never hardcoded.</li>\n<li>Inventory current buckets and objects via read-only calls before proposing any mutation.</li>\n<li>Label claims as <code>live evidence</code>, <code>user-provided sanitized evidence</code>, <code>documentation-based</code>, or <code>inference</code>.</li>\n</ul>\n<h2>Automation pattern (read-only inventory first)</h2>\n<pre><code># Load credentials from environment — never hardcode\n: \"${CONTABO_CLIENT_ID:?set in env}\"\n: \"${CONTABO_CLIENT_SECRET:?set in env}\"\n: \"${CONTABO_API_USER:?set in env}\"\n: \"${CONTABO_API_PASSWORD:?set in env}\"\n\n# Refresh token before each operation\nTOKEN=$(curl -s \\\n  -d \"client_id=${CONTABO_CLIENT_ID}\" \\\n  -d \"client_secret=${CONTABO_CLIENT_SECRET}\" \\\n  --data-urlencode \"username=${CONTABO_API_USER}\" \\\n  --data-urlencode \"password=${CONTABO_API_PASSWORD}\" \\\n  -d 'grant_type=password' \\\n  'https://auth.contabo.com/auth/realms/contabo/protocol/openid-connect/token' \\\n  | jq -r '.access_token')\n\n# List Object Storage instances (read-only)\ncurl -s \\\n  -H \"Authorization: Bearer ${TOKEN}\" \\\n  -H \"x-request-id: $(uuidgen)\" \\\n  'https://api.contabo.com/v1/storage/object-storages' | jq .\n</code></pre>\n<h2>Response minimum</h2>\n<p>Return, at minimum:</p>\n<ul>\n<li>the target bucket(s) and object inventory evidence level,</li>\n<li>the access policy and retention posture assessment,</li>\n<li>the hard-stop checklist status (all three items confirmed or blocked),</li>\n<li>the rollback plan,</li>\n<li>the assumptions or open questions that require user clarification before proceeding.</li>\n</ul>\n<h2>References</h2>\n<p>Load these only when needed:</p>\n<ul>\n<li><a href=\"references/workflow-and-output.md\">Workflow and output contract</a> — use when executing a full storage operation or formatting the approval-ready change record.</li>\n<li><a href=\"references/safety-checklist.md\">Safety checklist</a> — use before any bucket deletion, object deletion, or irreversible storage mutation; all hard-stop gates must be confirmed before proceeding.</li>\n<li><a href=\"references/official-sources.md\">Official sources</a> — use when grounding Contabo Object Storage API behavior, S3 compatibility, or access policy configuration.</li>\n</ul>\n","files":[{"path":"metadata.json","sizeBytes":1365,"isText":true},{"path":"references/official-sources.md","sizeBytes":1644,"isText":true},{"path":"references/safety-checklist.md","sizeBytes":4073,"isText":true},{"path":"references/workflow-and-output.md","sizeBytes":3287,"isText":true},{"path":"SKILL.md","sizeBytes":4742,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-10-05T21:55:59.814241Z","sha256":"1FC20A7E8032CE9D23772D7F91FDD93BD2352F48C4A8E164CF69917213E94BF5","sizeBytes":7313},"review":null,"source":{"repositoryUrl":"https://github.com/VincentChuWaiChow/vanguard-frontier-agentic","path":"skills/contabo/contabo-live-storage-operations-guard","license":"Apache-2.0","commit":"febe32a08e78fd06b1e466187410d673f1958d87","subtreeSha":"97C7026C01F534A9DFDDF05677B7D097FCA152AC85321F3FF0EDE2E0DF27CB85","lastSyncedAt":"2026-10-05T21:51:58.639905Z"},"reviewedAt":"2026-10-05T22:04:38.014142Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/contabo/contabo-live-storage-operations-guard"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart"},{"target":"git","command":"git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git"}]}