Repository

AgentSecOps/SecOpsAgentKit agent skills

Every skill in the AgentSecOps/SecOpsAgentKit repository on GitHub, ranked by score, with the commands to install them.
skills
24
GitHub stars
220

GitHub description: “Security operations toolkit for AI coding agents. Give Claude Code 25+ skills to catch vulnerabilities, scan containers, detect secrets, and enforce policies automatically.”

Stars
220 (42 forks)
Licence
Unknown
Last push
Apr 2026
Created
Nov 2025
  • agents
  • claude-code
  • security
  • ai-agents
  • anthropic
  • appsec
  • dast
  • devsecops
  • llm-tools
  • sast
  • security-automation
  • security-tools
  • shift-left
  • vulnerability-scanning

Install all skills

skills CLI (any agent)
npx skills add AgentSecOps/SecOpsAgentKit

Add --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).

Skills in AgentSecOps/SecOpsAgentKit, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Skills in AgentSecOps/SecOpsAgentKit, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

AgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassUnknown5 mo ago
2

Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks.

AgentSecOps/SecOpsAgentKit2202 repos~4.1kAutomated safety check: PassUnknown5 mo ago
3

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassUnknown5 mo ago
4

Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

AgentSecOps/SecOpsAgentKit2201 repo~4.8kAutomated safety check: NotesUnknown5 mo ago
5

Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

AgentSecOps/SecOpsAgentKit2201 repo~2.5kAutomated safety check: PassUnknown5 mo ago
6

Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.

AgentSecOps/SecOpsAgentKit2201 repo~4.4kAutomated safety check: PassUnknown5 mo ago
7

Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

AgentSecOps/SecOpsAgentKit2201 repo~3.3kAutomated safety check: NotesUnknown5 mo ago
8

Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans.

AgentSecOps/SecOpsAgentKit2201 repo~3.3kAutomated safety check: PassUnknown5 mo ago
9

Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web…

AgentSecOps/SecOpsAgentKit2201 repo~4.1kAutomated safety check: NotesUnknown5 mo ago
10

Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection.

AgentSecOps/SecOpsAgentKit2201 repo~3.7kAutomated safety check: PassUnknown5 mo ago
11
11.Pytm

Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification.

AgentSecOps/SecOpsAgentKit2202 repos~4.4kAutomated safety check: NotesUnknown5 mo ago
12

Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

AgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassUnknown5 mo ago
13

Generic detection rule creation and management using Sigma, the universal SIEM rule format.

AgentSecOps/SecOpsAgentKit2201 repo~4kAutomated safety check: PassUnknown5 mo ago
14

SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

AgentSecOps/SecOpsAgentKit2201 repo~4.9kAutomated safety check: NotesUnknown5 mo ago
15

Infrastructure as Code (IaC) security scanning using Checkov with 750+ built-in policies for Terraform, CloudFormation, Kubernetes, Dockerfile, and ARM templates.

AgentSecOps/SecOpsAgentKit2201 repo~4.6kAutomated safety check: PassUnknown5 mo ago
16

Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.

AgentSecOps/SecOpsAgentKit2201 repo~3.1kAutomated safety check: PassUnknown5 mo ago
17

Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

AgentSecOps/SecOpsAgentKit2201 repo~3.5kAutomated safety check: PassUnknown5 mo ago
18

Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.

AgentSecOps/SecOpsAgentKit2201 repo~4.6kAutomated safety check: NotesUnknown5 mo ago
19

Automated code review and security linting integration for CI/CD pipelines using reviewdog.

AgentSecOps/SecOpsAgentKit2201 repo~3kAutomated safety check: PassUnknown5 mo ago
20

Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

AgentSecOps/SecOpsAgentKit2201 repo~2.6kAutomated safety check: PassUnknown5 mo ago
21

Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.

AgentSecOps/SecOpsAgentKit2201 repo~3.5kAutomated safety check: PassUnknown5 mo ago
22

Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions.

AgentSecOps/SecOpsAgentKit2201 repo~2.8kAutomated safety check: PassUnknown5 mo ago
23

Automated SQL injection detection and exploitation tool for web application security testing.

AgentSecOps/SecOpsAgentKit2201 repo~3.2kAutomated safety check: PassUnknown5 mo ago
24

API specification linting and security validation using Stoplight's Spectral with support for OpenAPI, AsyncAPI, and Arazzo specifications.

AgentSecOps/SecOpsAgentKit2201 repo~5.6kAutomated safety check: PassUnknown5 mo ago

Questions, answered from the data.

What is the best skill in AgentSecOps/SecOpsAgentKit?

Sast Semgrep from AgentSecOps/SecOpsAgentKit ranks first of the 24 skills in AgentSecOps/SecOpsAgentKit listed here, with the highest score: its repository has 220 GitHub stars, 2 other GitHub owners carry a copy, its SKILL.md loads about 2.4k tokens and it passes the automated safety check with no findings. Next come Secrets Gitleaks and DefectDojo Vulnerability Management.

Are the skills in AgentSecOps/SecOpsAgentKit official?

None yet. All 24 skills in AgentSecOps/SecOpsAgentKit listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.

How do I install all skills from AgentSecOps/SecOpsAgentKit?

Run npx skills add AgentSecOps/SecOpsAgentKit in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.