Service CLI Coverage

The first-party CLI map for SaaS and infrastructure products in Kevin's agent stack. It is discovery/routing intelligence, not blanket permission to mutate external systems.

Policy

Use Security and Review Skills before working with a SaaS or infrastructure product that does not already have a more specific skill. Prefer service-specific skills and plugin MCPs when available; otherwise use this table to choose the first-party CLI.

Before mutation, agents must identify the current account/context, run read-only commands first, use dry-run/plan/preview when available, and ask before destructive, expensive, production, or customer-data actions.

2026-06-24 Skill Promotions

The latest capability harvest promoted narrow skills for service areas that should no longer fall through to the generic CLI registry by default: specialized Azure operations, Firebase AI/Data Connect/App Hosting/Crashlytics/Remote Config, Google Workspace write/append/triage/Slides/Tasks, Vercel AI SDK/token CLI, Better Auth, Stitch workflows, and Excalidraw diagram generation. Use those skills first when the task names the matching product surface; return to this CLI map for broader SaaS/infra services or when no installed skill owns the work.

Coverage Table

Developer Platform

Service CLI Use
GitHub gh Prefer for issues, PRs, checks, releases, and repository metadata.
GitLab glab Prefer for GitLab issues, merge requests, pipelines, and projects.

Cloud

Service CLI Use
AWS aws Prefer for AWS account work after profile and permission checks.
Google Cloud gcloud Includes gcloud, gsutil, and auth helpers.
Azure az Prefer for Azure resource discovery and deployments.

Edge

Service CLI Use
Cloudflare wrangler Workers, Pages, KV, R2, D1, Queues. Use cloudflared for tunnels.
Cloudflare Tunnel cloudflared Use for local tunnels and named tunnel management.

Hosting

Service CLI Use
Vercel vercel Prefer for dev, deploy, env pull, domains, and project linking.
Netlify netlify Prefer for Netlify deploys, functions, and site config.
Fly.io flyctl Prefer for Fly apps, machines, volumes, and secrets.
Railway railway Prefer for Railway project linking and service variables.
Render render Use only after confirming the current Render CLI surface.
Heroku heroku Prefer for dynos, config vars, logs, releases, and add-ons.

Database

Service CLI Use
Supabase supabase Prefer for migrations, db diff, db push, and type generation.
Firebase firebase Prefer for emulators, deploys, auth, and project config.
Neon neon Use for Neon projects, branches, and connection strings.
PlanetScale pscale Use when PlanetScale remains the project database.
Turso turso Use for libSQL database, branch, and auth-token work.
Upstash upstash Use for Redis, QStash, Vector, and Kafka resources.
PostgreSQL psql Prefer for direct SQL when credentials are already local.
MySQL mysql Prefer for direct MySQL inspection when safe.
MongoDB mongosh Prefer for direct MongoDB shell inspection.
ClickHouse clickhouse Prefer for ClickHouse local or remote SQL.

Warehouse

Service CLI Use
Snowflake snow Prefer for Snowflake SQL, stages, and app workflows.
Databricks databricks Prefer for jobs, repos, clusters, and workspace assets.
BigQuery bq Ships with Google Cloud SDK.

Payments And Commerce

Service CLI Use
Stripe stripe Prefer for webhook listen, trigger, fixtures, and logs.
Shopify shopify Prefer for themes, apps, Hydrogen, and extension workflows. For agent-authored ecommerce pages, start with a repo folder containing brand facts, theme context, and skills, then let the agent operate Shopify CLI before escalating to custom Shopify MCP/app work. Current npm authority: @shopify/cli@4.4.0 (published 2026-07-06) and @shopify/hydrogen@2026.4.4 (published 2026-06-15). Route storefront framework decisions through Shopify Hydrogen, especially for the Vercel + Shopify rebuild / preview-branch signal. Source: X/@oliviercroguy, 2026-03-12; Source: npm registry, 2026-07-06

Auth

Service CLI Use
Clerk clerk Use after verifying current Clerk CLI support.
Auth0 auth0 Prefer for tenants, apps, logs, and quickstarts.
Okta okta Verify current support before use; Okta surfaces have changed over time.

Observability

Service CLI Use
Sentry sentry-cli Prefer for releases, source maps, debug files, and issue metadata.
Datadog datadog-ci Prefer for CI visibility, sourcemaps, synthetics, and test metadata.
New Relic newrelic Prefer for New Relic entities, workloads, and diagnostics.
Grafana grafana Grafana CLI is mostly server/admin; prefer API/MCP for hosted data.

Communications

Service CLI Use
Twilio twilio Prefer for phone numbers, messaging, and account diagnostics.
SendGrid sendgrid Verify maintenance before relying on it for production.
Service CLI Use
Contentful contentful Prefer for spaces, migrations, and content models.
Sanity sanity Prefer for schema, datasets, deploys, and local studio workflows.
Strapi strapi Prefer for Strapi app scaffolding and admin work.
Algolia algolia Prefer for indices, settings, and API key inspection.

AI And Agent Infrastructure

Service CLI Use
Hugging Face hf Prefer for model, dataset, and Space workflows.
Modal modal Prefer for Modal apps, sandboxes, secrets, and logs.
E2B e2b Verify current CLI commands before automation.

Infrastructure

Service CLI Use
Docker docker Prefer for container build/run/compose when local daemon is available.
Kubernetes kubectl Require explicit context/namespace checks before mutating.
Helm helm Prefer for chart templating, installs, and releases.
Terraform terraform Use plan before apply. Never mutate infra without approval.
Pulumi pulumi Use preview before up. Never mutate infra without approval.
Ansible ansible Prefer check mode first when possible.

CI

Service CLI Use
CircleCI circleci Prefer for config validation and local job checks.
Buildkite bk Prefer for Buildkite pipelines, builds, and logs.

Promotion State

Already promoted to service-specific skills: Cloudflare/Wrangler, Supabase, Clerk, Firebase, Azure, Google Workspace, Next.js, and browser-use. Already routed through plugin/MCP surfaces: Vercel, Stripe, Figma, PostHog, Sentry, Datadog, Linear, Slack, Shopify, ClickHouse.

Current missing areas covered by this page rather than bespoke skills: GitLab, AWS, Google Cloud, Docker, Kubernetes, Helm, Terraform, Pulumi, Ansible, Sentry CLI, Datadog CI, New Relic, Grafana, Snowflake, Databricks, BigQuery, Auth0, Okta, Twilio, SendGrid, Contentful, Sanity, Strapi, Algolia, Hugging Face, Netlify, Fly.io, Railway, Heroku, Neon, PlanetScale, Turso, Upstash, MongoDB, MySQL, PostgreSQL, CircleCI, and Buildkite.


Timeline