cloud-finops — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cloud-finops (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Built by OptimNow. Covers cloud financial management across AWS, Azure, GCP, AI inference costs, GenAI capacity planning, SaaS asset management, and tagging governance - grounded in enterprise delivery experience.
| Tool | One-step install | |
|---|---|---|
| <img src="https://img.shields.io/badge/-Claude%20Code-D97757?logo=anthropic&logoColor=white" alt="Claude Code" height="22"/> | At the Claude Code prompt: /plugin marketplace add https://github.com/OptimNow/cloud-finops-skills.git then /plugin install cloud-finops@optimnow | |
| <img src="https://img.shields.io/badge/-Claude.ai%20%2F%20Desktop-D97757?logo=anthropic&logoColor=white" alt="Claude.ai / Claude Desktop" height="22"/> | Download the latest release zip, then Settings -> Skills -> Upload zip | |
| <img src="https://img.shields.io/badge/-ChatGPT-10A37F?logo=openai&logoColor=white" alt="ChatGPT" height="22"/> | Self-host: ./install.sh --tool chatgpt --grouped _(a public Cloud FinOps GPT is on the Roadmap)_ | |
| <img src="https://img.shields.io/badge/-Gemini-4285F4?logo=googlegemini&logoColor=white" alt="Gemini" height="22"/> | Self-host: ./install.sh --tool gemini _(a public Cloud FinOps Gem is on the Roadmap)_ | |
| <img src="https://img.shields.io/badge/-Cursor-000000?logo=cursor&logoColor=white" alt="Cursor" height="22"/> <img src="https://img.shields.io/badge/-Windsurf-3DDC91?logoColor=white" alt="Windsurf" height="22"/> <img src="https://img.shields.io/badge/-Codex-412991?logo=openai&logoColor=white" alt="Codex" height="22"/> <img src="https://img.shields.io/badge/-Aider-0F172A?logoColor=white" alt="Aider" height="22"/> <img src="https://img.shields.io/badge/-Copilot-181717?logo=githubcopilot&logoColor=white" alt="Copilot" height="22"/> <img src="https://img.shields.io/badge/-Kiro%20IDE-FF6F00?logoColor=white" alt="Kiro IDE" height="22"/> <img src="https://img.shields.io/badge/-Gemini%20CLI-4285F4?logo=googlegemini&logoColor=white" alt="Gemini CLI" height="22"/> | One-liner: `curl -sL https://raw.githubusercontent.com/OptimNow/cloud-finops-skills/main/install.sh \ | bash -s -- --tool <name>` |
| <img src="https://img.shields.io/badge/-Auto--detect-555555?logo=gnubash&logoColor=white" alt="Auto-detect" height="22"/> | `curl -sL https://raw.githubusercontent.com/OptimNow/cloud-finops-skills/main/install.sh \ | bash` |
| <img src="https://img.shields.io/badge/-MCP%20server-7C3AED?logoColor=white" alt="MCP server" height="22"/> | pip install cloud-finops-mcp then add to your MCP client config (Claude Code / Cursor / Codex / Windsurf / Cline). Snippets: ./install.sh --tool mcp. Six tools - faceted retrieval over the 28 references and 23 named-pattern playbooks. |
Full options, troubleshooting, and the model-agnostic API loader: see INSTALLATION.md.
A Skill is a structured knowledge file that you attach to an AI agent or a large language model. It gives the model accurate, domain-specific context that it would not otherwise have access to.
Without it, general-purpose LLMs make confident but incorrect statements on FinOps topics. They miscalculate PTU break-even rates. They confuse Azure and AWS reservation mechanics. They give generic advice that ignores how billing actually works on Bedrock or Azure OpenAI. The answers sound plausible. Most of the time, they are wrong on the details that matter.
This skill corrects that by injecting verified, curated FinOps knowledge directly into the model's context - covering billing models, cost allocation patterns, optimisation frameworks, and governance practices across the major cloud providers and AI platforms.
The closest analogy is RAG (Retrieval-Augmented Generation). Like RAG, it extends a model's knowledge beyond its training data. Unlike RAG, it requires no vector database, no embedding pipeline, and no retrieval infrastructure. You copy a folder into your agent setup and the model gains structured expertise on cloud financial management.
This makes it portable: the same skill works with Claude, GPT, Gemini, or any MCP-compatible agent - with no changes to the files.
To keep responses consistent across models, add a response contract to your system prompt (see INSTALLATION.md, "API integration / Recommended response contract"). This ensures structured, billing-grounded answers even when model defaults differ.
their workflow
No AI infrastructure experience is required to use this skill. If you can copy a folder and follow the installation steps, you can add FinOps expertise to any compatible agent.
workloads as an edge case. This skill treats them as a primary concern, with dedicated reference files for each major AI platform.
establish what you are spending, understand what is driving it, then act. It does not recommend optimisation steps before the visibility preconditions are met.
billing actually works (CUR columns, Azure cost-management semantics, BigQuery export, FOCUS conformance) rather than in vendor marketing or framework positioning. Vendor sustainability and savings claims are read critically, with primary sources cited.
revenue generator do not need to reach Run; Crawl plus selective Walk is the right state when cloud is a cost centre. Verticals where cloud IS the product need Run because cloud efficiency directly drives gross margin. Pushing every organisation toward the same maturity ceiling is malpractice.
what business outcome does this protect or unlock. Cost reduction without a value lens is a leak.
allocation, anomaly management, commitment management, rightsizing, and governance, all of which produce measurable outputs. "Culture of FinOps" framing tends to substitute slideware for those outputs. In the agentic era this matters more, not less: agents execute discipline, not culture.
These principles will grow into a skills/cloud-finops/doctrine/ directory of opposable theses with their own primary sources; see the Roadmap section of CLAUDE.md.
The skill provides accurate, framework-aligned guidance across the following domains:
patterns, unit economics for AI features, ROI frameworks, and AI cost governance
funding, practice operations, cross-functional governance for AI investments
spillover mechanics, throughput units, cross-provider comparison
hidden cost surface, ML-Ops maturity rubric, hybrid routing patterns (LiteLLM, Portkey)
prompt caching, Batch API, governance controls
model modernisation, optimisation framework, use case economics, cost visibility
Savings Plans, Enterprise Discount Program (EDP) negotiation, RDS cost management, multi-organisation billing, cost allocation, SCPs, and AWS-native quick wins
Azure Hybrid Benefit, EA-to-MCA transition impact, and Azure-specific optimisation patterns
virtual tagging, MCP-based automation, and compliance monitoring
DBCU commitments, Photon multiplier, amortised vs PAYG split), cluster and Spark optimisation, Unity Catalog costs
pause / resume, Reserved Capacity, Pro/PPU to Fabric migration governance trap
Budgets including AI feature budgets, Cortex governance, resource monitor scope
cost attribution with LiteLLM proxy, seat + usage vs BYOK architecture comparison, optimisation levers, cross-tool spend overlap audit
governance, SaaS Management Platforms (SMPs), shadow IT detection, sprawl patterns, and the connection to AI transition readiness
marketplace channel governance, Tier 1 vendor co-management, consumption-based SaaS overage monitoring, entitlement integration, and maturity framework
integration, carbon-aware workload shifting, region selection, GHG Protocol reporting
capability across AWS / Azure / GCP native tooling, layered detection, masked-anomaly failure mode, integration with Security
legacy mapping, defensible allocation keys, shared-services hard cases, InvoiceId reconciliation, showback report design
prerequisites (ERP readiness, transfer pricing, cross-border tax, SOX-equivalent controls), chargeback-revolt anti-pattern
forecast-then-commit rule, double-bubble cost discipline, M&A integration playbook
FOCUS-emitting K8s allocation, container rightsizing methodology, Karpenter, Spot diversification
idle, overprovisioned, commitment mismatches, schedule blindness, modernisation, AI/ML inefficiency), two-signal classification, three-tier confidence, WasteLine appliance for AWS
These questions illustrate what this skill is designed to answer accurately. A general-purpose LLM without this skill will produce plausible but unreliable answers to most of them - particularly on billing mechanics, capacity economics, and provider-specific behaviour.
<div> <a href="https://www.loom.com/share/cc76d419adc64b1784e58621d6934d3e"> <p>Cloud FinOps skill - Watch Video</p> </a> <a href="https://www.loom.com/share/cc76d419adc64b1784e58621d6934d3e"> <img style="max-width:300px;" src="https://cdn.loom.com/sessions/thumbnails/cc76d419adc64b1784e58621d6934d3e-906aded8593a48f3-full-play.gif#t=0.1"> </a> </div>
cloud-finops-skills/
├── README.md ← This file
├── CLAUDE.md ← Project context for Claude Code and contributors
├── AGENTS.md ← Codex CLI entry point (mirrors CLAUDE.md)
├── llms.txt ← LLM discovery index (cross-agent)
├── INSTALLATION.md ← Setup instructions (incl. MCP server)
├── LICENSE.md ← CC BY-SA 4.0
├── install.sh ← Cross-tool installer (12 targets)
├── mcp_server/ ← cloud-finops-mcp PyPI package
└── skills/cloud-finops/ ← Install this folder
├── SKILL.md ← Entry point + domain router (Claude Code, generic agents)
├── POWER.md ← Entry point (Kiro IDE)
├── references/
│ ├── optimnow-methodology.md ← OptimNow reasoning philosophy
│ ├── finops-for-ai.md ← AI cost management
│ ├── finops-ai-value-management.md ← AI investment governance
│ ├── finops-genai-capacity.md ← GenAI capacity models (cross-provider)
│ ├── finops-ai-self-hosted-vs-managed.md ← Self-hosted vs managed AI inference decision
│ ├── finops-anthropic.md ← Anthropic billing + governance
│ ├── finops-aws.md ← AWS-specific FinOps
│ ├── finops-bedrock.md ← AWS Bedrock billing
│ ├── finops-azure.md ← Azure-specific FinOps
│ ├── finops-azure-openai.md ← Azure OpenAI Service (PTUs)
│ ├── finops-gcp.md ← GCP-specific FinOps
│ ├── finops-vertexai.md ← GCP Vertex AI billing
│ ├── finops-tagging.md ← Tagging and naming governance
│ ├── finops-framework.md ← Full FinOps Foundation framework
│ ├── finops-databricks.md ← Databricks allocation, governance, and optimisation
│ ├── finops-fabric.md ← Microsoft Fabric capacity FinOps
│ ├── finops-snowflake.md ← Snowflake optimisation
│ ├── finops-ai-dev-tools.md ← AI coding tools (Cursor, Claude Code, etc.)
│ ├── finops-oci.md ← OCI optimisation
│ ├── finops-sam.md ← SaaS asset management (SAM)
│ ├── finops-itam.md ← ITAM collaboration (BYOL, marketplace, entitlements)
│ ├── greenops-cloud-carbon.md ← GreenOps and cloud carbon
│ ├── finops-anomaly-management.md ← Anomaly management (standalone Inform-phase capability)
│ ├── finops-allocation-showback.md ← Cost allocation methodology + showback
│ ├── finops-chargeback.md ← Chargeback maturity ladder + Finance/accounting prerequisites
│ ├── finops-onboarding-workloads.md ← Migration-time cost hygiene + M&A integration
│ ├── finops-kubernetes.md ← Kubernetes cross-cluster discipline (EKS/GKE/AKS)
│ └── finops-waste-detection-playbooks.md ← Seven-category waste taxonomy + WasteLine
└── playbooks/ ← 23 RAG-friendly named-pattern runbooks (~2-4 KB each)The SKILL.md file is the entry point for Claude Code and generic agents. POWER.md is the entry point for Kiro IDE. Both route queries to the same reference files - the domain-specific content is shared.
The "Install in 5 seconds" table at the top of this README covers the one-step path for every supported tool. For per-tool blocks, troubleshooting, the model-agnostic API loader, and the recommended response contract, see [INSTALLATION.md](./INSTALLATION.md).
A version-tagged release zip (cloud-finops-vX.Y.Z.zip) is attached to every GitHub release for Claude Desktop / claude.ai users who prefer downloading over building locally.
For agents that want tool-style retrieval rather than full-context injection, the skill is also published as an MCP server (cloud-finops-mcp on PyPI):
pip install cloud-finops-mcp
./install.sh --tool mcp # prints config snippets for every MCP-aware clientSix tools across two surfaces. References (long-form provider/discipline files): list_references, get_reference, find_references (faceted by FinOps Capability/Phase). Playbooks (small named-pattern runbooks): list_playbooks, get_playbook, find_playbooks (faceted by scope / service / waste category / confidence). Wires into Claude Code, Cursor, Codex CLI, Windsurf, Cline, and any other MCP-aware client. See mcp_server/ and the INSTALLATION.md MCP section.
This is a living repository. Reference files are refreshed monthly (around the 1st of each month), driven by an automated scan of 29 data sources - cloud provider pricing pages, release notes, billing changelogs, and FinOps community publications. Changes are reviewed before being applied, so the content reflects verified updates rather than raw feed output.
AI cost management is moving particularly fast - new model releases, capacity options, and billing mechanics appear every few weeks. Watch or star this repo to be notified when updates are published.
Process and credit. Open an issue first for anything larger than a typo or single fact correction, so we can scope before you write. Pull requests should keep the existing structure of the file you are touching, follow the conventions in CLAUDE.md (FCP frontmatter, no em dashes, British spelling in prose, license footer), and pass the FCP coverage check (./scripts/fcp-coverage.sh --check).
You keep authorship: every contribution lives in the commit history under your name and shows up in git blame. Substantive contributors are visible in the repo's contributors list on GitHub.
License and what that means for you. All contributions are licensed under CC BY-SA 4.0. This is an OptimNow-maintained repo, but CC BY-SA was chosen specifically so anyone - including you - can fork, customise, and redistribute under their own brand, as long as they credit and share-alike. If you want a project under your own name rather than contributing here, fork freely; see "Adapting this skill for your organisation" below for the fork playbook. Both paths are first-class.
Practitioner experience is the highest-value contribution. Frameworks and vendor docs are already public; what is rare is "we tried X in production, this is what actually billed". Issues and PRs that bring that lens are welcome in any of the layers below.
Concrete contribution types we actively want:
CUD / Reservation discount depth that has shifted, a refund cap that does not match the latest contract terms. Cite the primary source (provider doc, your invoice, an enrollment agreement) so the change is verifiable.
skills/cloud-finops/playbooks/. Follow the format documented in playbooks/README.md: symptoms / detection query / fix / anti-pattern / sources, ~2-4 KB. Examples we'd love: Lambda cold-start sprawl, Bedrock model proliferation, Snowflake warehouse fragmentation, Databricks all-purpose-cluster default-on, Cloud Run min-instance creep.
false positives in your data, an anti-pattern you saw burn a team, a fix step that does not work without a precondition we missed.
files section of [CLAUDE.md`](./CLAUDE.md) lists the P2/P3 items (forecasting, unit economics, practice operations, education & enablement, benchmarking, cost warehouse) with the rationale and trigger to revisit. If your engagement has surfaced one of those, that is the trigger - open an issue with the engagement context and we will scope the file together.
--tool <new-tool> for a codingassistant or agent we do not yet support. Match the existing installer pattern in install.sh (idempotent, dry-run-safe, exclude local-only files like .claude/ and .backups/).
not work, or worked under conditions we do not flag. These end up as anti-pattern blocks in the relevant reference or playbook.
and ideally a source. The repo is opinionated; it should also be falsifiable.
tool, a guard rail false-positives. Open an issue with the exact command and output.
parallel directory rather than a fork, when you can commit to keeping them in sync with the next refresh.
What we push back on:
practitioner-grade evidence behind the claim.
The pipeline that powers the monthly refresh has hard guard rails (see the Lessons learned section of CLAUDE.md for why). Hand-written contributions go through human review for the same reasons.
in this repo connects cost to a business outcome; contributions should follow that pattern.
Fork this repository and customise the reference files for your organisation's context: your cloud stack, your internal policies, your tag taxonomy, your preferred methodology.
A fork gives you a stable base that you can pull upstream updates into at your own pace, without overwriting your customisations. Typical customisations include:
finops-tagging.mdOptimNow is a boutique FinOps consultancy helping organisations connect cloud and AI spend to measurable business value. Based in France with European reach.
Open-source tools built by OptimNow:
This skill incorporates content derived from the following sources:
descriptions, and maturity model structure are based on the FinOps Framework.
informed several provider-specific best practices and quick-win patterns.
All referenced content has been adapted with additional context from OptimNow's consulting delivery experience. Any errors or opinionated interpretations are our own.
This skill is independently maintained and is not affiliated with or endorsed by the FinOps Foundation.
Licensed under CC BY-SA 4.0. See LICENSE.md.
You are free to use, adapt, and redistribute this skill - including for commercial purposes - as long as you credit OptimNow and share any derivatives under the same license.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.