Search
Security · GitHub Actions
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 2 | 2.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 3 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 4 | GitHub Actions security review for workflow exploitation vulnerabilities. | getsentry/ | 1k | 3 repos | ~2.2k | Automated safety check: Notes | Apache-2.0 | 6 days ago |
| 5 | GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release… | samber/ | 3.4k | — | ~3.7k | Automated safety check: Pass | MIT | 7 days ago |
| 6 | CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines. | context-labs/ | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | 3 days ago |
| 7 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 8 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 9 | 9.Docs Update project documentation when features are added or changed. | boostsecurityio/ | 523 | — | ~336 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 10 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 11 | Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe… | openclaw/ | 392k | — | ~13k | Automated safety check: Pass | MIT | today |
| 12 | Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in… | malloydata/ | 116 | — | ~5.1k | Automated safety check: Pass | MIT | today |
| 13 | Run Warden security scans in this repo using Sentry's warden-skills. | UsefulSoftwareCo/ | 4.1k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 14 | Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. | mistralai/ | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 15 | Security guidelines for writing secure code. An agent skill from semgrep/skills. | semgrep/ | 322 | — | ~1.2k | Automated safety check: Pass | Unknown | 2 mo ago |
| 16 | Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. | getknit/ | 131 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 4 days ago |
| 17 | Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates. | AgentSecOps/ | 220 | 1 repo | ~4.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 18 | 18.Snapshot Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions. | boostsecurityio/ | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 19 | Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository. | boostsecurityio/ | 523 | — | ~173 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 20 | Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments. | irahardianto/ | 157 | — | ~2.7k | Automated safety check: Notes | MIT | 3 days ago |
| 21 | Detecta riscos básicos de segurança em repositórios (segredos expostos, configurações perigosas, padrões inseguros) e gera recomendações com evidências. | glaucia86/ | 121 | — | ~819 | Automated safety check: Warn | MIT | 3 mo ago |
| 22 | Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run. | dralgorhythm/ | 125 | — | ~1.5k | Automated safety check: Pass | No licence | 2 mo ago |
| 23 | 23.AWS Iam Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 24 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | today |
| 25 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 26 | 26.Reviewdog Automated code review and security linting integration for CI/CD pipelines using reviewdog. | AgentSecOps/ | 220 | 1 repo | ~3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 27 | Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | 30.Atmos CI Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs… | cloudposse/ | 1.4k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | today |
| 31 | Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets… | mukul975/ | 34k | — | ~655 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2… | davila7/ | 32k | — | ~1.7k | Automated safety check: Notes | MIT | today |
| 33 | CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows). | pskoett/ | 311 | — | ~1.1k | Automated safety check: Pass | No licence | 3 days ago |
| 34 | PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills. | alirezarezvani/ | 28k | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 35 | PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). | tetherto/ | 681 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 36 | The non-obvious invariants of the proactive nightly Claude audit workflow (.github/workflows/claude-nightly-audit.yml): the day-of-week mode selector, the two-key dedup scheme (clusterkey per… | amd/ | 1.6k | — | ~4.4k | Automated safety check: Pass | MIT | today |
| 37 | Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. | tobihagemann/ | 407 | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 38 | CI/CD pipeline security, supply chain security, SLSA compliance, artifact signing, dependency scanning | Hack23/ | 239 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 39 | External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~4.3k | Automated safety check: Warn | MIT | yesterday |
| 40 | Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support | Hack23/ | 239 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 41 | Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot. | ccplugins/ | 968 | — | ~486 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 42 | Read-only GitHub Actions workflow security audit for one repository, a repository set, or a whole GitHub org. | apache/ | 112 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | today |
| 43 | Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. | aiskillstore/ | 430 | — | ~3.2k | Automated safety check: Pass | No licence | yesterday |