Search

Security · GitHub Actions

43 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

asyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.03 days ago
2

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~581Automated safety check: PassApache-2.0today
3

Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~545Automated safety check: PassApache-2.0today
4

GitHub Actions security review for workflow exploitation vulnerabilities.

getsentry/skills1k3 repos~2.2kAutomated safety check: NotesApache-2.06 days ago
5

GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

samber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT7 days ago
6

CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

context-labs/whip1.1k—~3.5kAutomated safety check: PassMIT3 days ago
7

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassUnknown5 mo ago
8

Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

vechain/x-app-template450—~1.2kAutomated safety check: PassMIT2 mo ago
9

Update project documentation when features are added or changed.

boostsecurityio/poutine523—~336Automated safety check: PassApache-2.02 days ago
10

Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

trailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
11

Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe…

openclaw/openclaw392k—~13kAutomated safety check: PassMITtoday
12

Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

malloydata/publisher116—~5.1kAutomated safety check: PassMITtoday
13

Run Warden security scans in this repo using Sentry's warden-skills.

UsefulSoftwareCo/executor4.1k—~1.3kAutomated safety check: PassMITtoday
14

Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

mistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.0yesterday
15
15.Code SecurityOfficial

Security guidelines for writing secure code. An agent skill from semgrep/skills.

semgrep/skills322—~1.2kAutomated safety check: PassUnknown2 mo ago
16

Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

getknit/knit131—~1.2kAutomated safety check: PassGPL-3.04 days ago
17

Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.

AgentSecOps/SecOpsAgentKit2201 repo~4.4kAutomated safety check: PassUnknown5 mo ago
18

Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

boostsecurityio/poutine523—~214Automated safety check: PassApache-2.02 days ago
19

Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.

boostsecurityio/poutine523—~173Automated safety check: PassApache-2.02 days ago
20

Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

irahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT3 days ago
21

Detecta riscos básicos de segurança em repositórios (segredos expostos, configurações perigosas, padrões inseguros) e gera recomendações com evidências.

glaucia86/repocheckai121—~819Automated safety check: WarnMIT3 mo ago
22

Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

dralgorhythm/claude-agentic-framework125—~1.5kAutomated safety check: PassNo licence2 mo ago
23

Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~3.4kAutomated safety check: PassMITyesterday
24
24.CodeqlOfficial

Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.

github/awesome-copilot40k1 repo~3.4kAutomated safety check: PassMITtoday
25

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

github/awesome-copilot40k1 repo~2.4kAutomated safety check: PassMITtoday
26

Automated code review and security linting integration for CI/CD pipelines using reviewdog.

AgentSecOps/SecOpsAgentKit2201 repo~3kAutomated safety check: PassUnknown5 mo ago
27

Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
28

Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
29

Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
30

Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…

cloudposse/atmos1.4k—~3.8kAutomated safety check: PassApache-2.0today
31

Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets…

mukul975/Anthropic-Cybersecurity-Skills34k—~655Automated safety check: PassApache-2.01 mo ago
32

Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

davila7/claude-code-templates32k—~1.7kAutomated safety check: NotesMITtoday
33

CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows).

pskoett/pskoett-ai-skills311—~1.1kAutomated safety check: PassNo licence3 days ago
34

PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills.

alirezarezvani/claude-skills28k—~1.9kAutomated safety check: PassMIT1 mo ago
35

PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

tetherto/qvac681—~2.5kAutomated safety check: PassApache-2.0today
36

The non-obvious invariants of the proactive nightly Claude audit workflow (.github/workflows/claude-nightly-audit.yml): the day-of-week mode selector, the two-key dedup scheme (clusterkey per…

amd/gaia1.6k—~4.4kAutomated safety check: PassMITtoday
37

Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

tobihagemann/turbo407—~1.5kAutomated safety check: PassMITyesterday
38

CI/CD pipeline security, supply chain security, SLSA compliance, artifact signing, dependency scanning

Hack23/cia239—~1.3kAutomated safety check: PassApache-2.0yesterday
39

External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k1 repo~4.3kAutomated safety check: WarnMITyesterday
40

Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support

Hack23/cia239—~3.8kAutomated safety check: PassApache-2.0yesterday
41

Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

ccplugins/awesome-claude-code-plugins968—~486Automated safety check: NotesApache-2.01 mo ago
42

Read-only GitHub Actions workflow security audit for one repository, a repository set, or a whole GitHub org.

apache/magpie112—~3.8kAutomated safety check: PassApache-2.0today
43

Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution.

aiskillstore/marketplace430—~3.2kAutomated safety check: PassNo licenceyesterday