01 Oct 2026 Β· 8 min read
Setting Up Google Antigravity: Rules, Skills and MCP
A verified walkthrough of AGENTS.md rules, SKILL.md packs, subagents, MCP servers, hooks and plugins in Google Antigravity.
google-antigravity setup-guide mcpBy Kelvin Β· 02 October 2026 Β· Updated 02 Oct 2026 Β· 8 min read

A backend developer pointing a coding agent at a feature branch is one kind of risk. A DevOps engineer pointing the same agent at a Kubernetes cluster, a Terraform state file, or a production incident channel is a different kind entirely. The upside is real β an agent that can read a stack trace, open the right dashboard, and draft the fix without you tabbing between six tools β but the blast radius is bigger, and "it deleted a test file" turns into "it deleted a namespace."
This post puts together a stack for that job specifically: one agent, a skill pack that actually knows infrastructure, a guardrail layer that screens actions before they run, a way to watch what every agent session is doing, and three MCP servers that connect it to the tools a DevOps engineer actually lives in β errors, clusters, and tickets.

Claude Code is the obvious anchor here, not because it's the only capable terminal agent but because of what it's built to plug into. It reads a CLAUDE.md for project context, keeps automatic memory between sessions, and β more relevant for this stack β supports hooks that run your own shell commands before or after the agent acts, plus native GitHub Actions and GitLab CI/CD integration. That combination means you can insert real checks (a policy script, a dry-run plan, a Slack ping) at the exact moment an agent is about to do something, rather than hoping it stays within scope.
Anthropic's agentic coding tool for the terminal, IDE, desktop and web
π₯ Claude Pro billed annually: $17/month instead of $20Install is a one-liner on macOS, Linux and WSL:
curl -fsSL https://claude.ai/install.sh | bash
Homebrew (brew install --cask claude-code) and WinGet are documented alternatives. From there, everything below β skills, plugins, MCP servers β layers on top of the same CLI.
A generic coding agent will happily write a Terraform resource block with the wrong provider version pinned, or a Dockerfile that ignores your base-image policy. What closes that gap is a skill pack written specifically for the DevOps side of full-stack work. Claude Skills (Fullstack Dev Skills) bundles 67 skills covering languages and frameworks alongside DevOps and security workflows, plus Jira integration for the ticket side of the job.
67 full-stack skills for languages, frameworks, DevOps and security, plus Jira workflows
Inside Claude Code, it installs as a plugin:
/plugin marketplace add jeffallan/claude-skills
/plugin install fullstack-dev-skills@jeffallan
Agent Skills load on demand β the agent only pulls in the DevOps-specific instructions when a task actually calls for them, so you're not paying a context-window tax for skills you're not using on a given ticket.
The riskiest part of handing an agent infrastructure access isn't a single bad command β it's a bad command running unreviewed because nobody was watching that session. ECC (Everything Claude Code) is worth layering in specifically for its AgentShield scanning and hooks, on top of a large bundled set of roughly 290 skills and 68 agents. The scanning piece matters most for this stack: it's a layer that screens agent actions rather than trusting the model's judgment alone.
All-in-one agent harness: ~290 skills, 68 agents, hooks, memory and AgentShield scanning
npx [email protected] setup
Or, from inside Claude Code:
/plugin marketplace add https://github.com/affaan-m/ECC
/plugin install ecc@ecc
This is also where the hooks from the base Claude Code install earn their keep: a PreToolUse hook that blocks kubectl delete against a production context, or that requires a Terraform plan to be reviewed before apply, costs a few lines of shell and removes an entire class of "the agent did something destructive while I was in a meeting" incidents.
Once you're running more than one agent session β one on an incident, one scaffolding a new service, one triaging a backlog of Dependabot PRs β you need visibility into what each one is actually doing, not just a terminal window you have to Alt-Tab to. Claude Code Agent Monitor is a self-hosted, real-time dashboard for Claude Code and Codex sessions: agents, tool calls, and running cost, all in one view.
Self-hosted real-time dashboard for Claude Code and Codex sessions, agents, tools and cost
git clone https://github.com/hoangsonww/Claude-Code-Agent-Monitor.git
cd Claude-Code-Agent-Monitor
npm run setup
npm run install-hooks
npm run dev
For a DevOps engineer specifically, the cost tracking matters as much as the activity feed β a runaway agent loop against a large repo can burn through a token budget fast, and a dashboard that surfaces that in real time is cheaper than finding out at the end of the month.

Skills and hooks shape how the agent behaves; MCP servers decide what it can actually touch. For this stack, three servers cover the loop a DevOps engineer runs daily β see an error, check the cluster, track the fix β and each comes from a different part of the ecosystem:
| Server | What it connects to | Category |
|---|---|---|
| Sentry MCP | Errors, stack traces, issues | Dev tools |
| Kubernetes MCP Server | Pods, logs, any resource, Helm | Cloud infrastructure |
| Linear MCP | Issues, projects, comments | Productivity |
Sentry's MCP server: pull errors, stack traces and issues into your agent
π₯ Sentry for Startups: up to $5,000 in credits (12-month expiry) for companies founded in the last 2 years with under $5M raisedclaude mcp add --transport http sentry https://mcp.sentry.dev/mcp/{organizationSlug}/{projectSlug}
Scoping it to a single project, as shown above, keeps the agent from browsing every error across every team by default.
Native Go MCP server for Kubernetes and OpenShift: pods, logs, any resource, Helm and more
claude mcp add-json kubernetes-mcp-server \
'{"command":"npx","args":["-y","kubernetes-mcp-server@latest","--read-only"],"env":{"KUBECONFIG":"'${HOME}'/.kube/mcp-viewer.kubeconfig"}}' \
-s user
That --read-only flag and a dedicated viewer kubeconfig aren't decoration β they're the difference between an agent that can describe a crashing pod and one that can also delete it. Start read-only, and only widen scope for a specific session once you trust the workflow.
Linear's hosted MCP server for issues, projects and comments
π₯ Startup program: free Business plan access via 466+ partner VCs/accelerators/communities, or use Linear's free plan directlyclaude mcp add --transport http linear-server https://mcp.linear.app/mcp
After adding it, run /mcp inside Claude Code and complete the OAuth sign-in in your browser β this one authenticates per user rather than per API key, which matters if more than one engineer shares the same agent setup.
With all five pieces installed, a realistic incident-response flow looks like this:
None of that requires the agent to have unrestricted access to anything β each piece narrows scope rather than widening it, which is the actual design goal for this role.
Not every week is an incident. A quieter, more common flow looks like this instead: a teammate opens a ticket in Linear asking for a new staging environment variable to be rolled out across three services. You hand the ticket description to Claude Code, it reads the Linear MCP server to pull the full context and acceptance criteria, uses a DevOps skill from the Fullstack Dev Skills pack to locate every place the variable needs to be added (Helm values, a Terraform variable block, a CI secret reference), and drafts the changes as a single PR rather than three separate ones. The Kubernetes MCP server, still read-only, confirms the current rollout state before anything is proposed. Nothing here touches a live cluster directly β the agent proposes, a human applies β which is the right default for anyone running this stack on a production account rather than a sandbox.
The specific commands above are Claude Code's, but the shape of the stack isn't locked to one vendor. MCP is an open protocol, so the same Sentry, Kubernetes and Linear servers connect the same way to Cursor, OpenCode or any other app that speaks MCP β only the add-server command differs. Agent Skills are similarly portable: a skill written as a SKILL.md file works in any agent that supports the format, and the Fullstack Dev Skills pack and ECC both target that standard rather than a single app's proprietary plugin system. The one piece that's genuinely Claude-Code-specific here is the hooks configuration syntax; other agents that support hooks (several do, including Cursor) use their own config format for the same underlying idea β intercepting an action before it runs.
Most of this stack is free or open-source; the main recurring cost is the agent plan itself.
| Component | Pricing |
|---|---|
| Claude Code | Included in paid Claude plans (Pro, Max, Team); no free tier |
| Fullstack Dev Skills | Free, open-source plugin |
| ECC | Freemium β core setup is free |
| Claude Code Agent Monitor | Free, self-hosted |
| Sentry MCP | Freemium, tied to your Sentry plan |
| Kubernetes MCP Server | Free, open-source |
| Linear MCP | Freemium, tied to your Linear plan |
Check current plan pricing on each vendor's own page before budgeting β see /deals for active student, startup and annual-billing discounts across the directory, including on Claude Code itself.
This is a starting stack, not a fixed one. If your infrastructure runs on AWS or Cloudflare instead of a self-managed Kubernetes cluster, swap in the matching MCP server from /ecosystem β the pattern of "one error-tracking server, one infrastructure server, one ticketing server" holds regardless of which specific vendors you use. If you're new to any of the underlying concepts here, the glossary covers hooks, MCP, and Agent Skills in plain terms, and Claude Code's own skills, subagents and MCP server listings are worth browsing directly for anything more specific to your stack.
The takeaway: the risk in giving an agent DevOps access isn't the agent itself β it's unscoped access. Read-only kubeconfigs, project-scoped Sentry servers, and hooks that gate destructive commands turn "an agent with production access" into "an agent with exactly the access this task needs," which is the only version of that sentence worth shipping.
Anthropic's agentic coding tool for the terminal, IDE, desktop and web
π₯ Claude Pro billed annually: $17/month instead of $20Native Go MCP server for Kubernetes and OpenShift: pods, logs, any resource, Helm and more
Sentry's MCP server: pull errors, stack traces and issues into your agent
π₯ Sentry for Startups: up to $5,000 in credits (12-month expiry) for companies founded in the last 2 years with under $5M raisedAll-in-one agent harness: ~290 skills, 68 agents, hooks, memory and AgentShield scanning
Linear's hosted MCP server for issues, projects and comments
π₯ Startup program: free Business plan access via 466+ partner VCs/accelerators/communities, or use Linear's free plan directly67 full-stack skills for languages, frameworks, DevOps and security, plus Jira workflows
Self-hosted real-time dashboard for Claude Code and Codex sessions, agents, tools and cost

01 Oct 2026 Β· 8 min read
A verified walkthrough of AGENTS.md rules, SKILL.md packs, subagents, MCP servers, hooks and plugins in Google Antigravity.
google-antigravity setup-guide mcp
30 Sep 2026 Β· 8 min read
A practical walkthrough of Copilot instructions, agent mode, MCP servers and the CLI, with verified commands from the docs.
github-copilot agent-mode mcp
29 Sep 2026 Β· 8 min read
Why Agent Skills load in stages instead of all at once, and how a sharp description keeps your agent fast and accurate.
agent-skills skill-md context-windowBrowse 296 apps, skills, subagents and MCP servers, mapped to the apps they work with.
See the ecosystem map