Search

Security · GitHub Actions · For developers

38 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

asyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0today
2

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos844—~581Automated safety check: PassApache-2.0today
3

Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

duriantaco/skylos844—~545Automated safety check: PassApache-2.0today
4

GitHub Actions security review for workflow exploitation vulnerabilities.

getsentry/skills1k3 repos~2.2kAutomated safety check: NotesApache-2.0today
5

GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

samber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT8 days ago
6

CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

context-labs/whip1.1k—~3.5kAutomated safety check: PassMIT5 days ago
7

Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

vechain/x-app-template450—~1.2kAutomated safety check: PassMIT2 mo ago
8

Update project documentation when features are added or changed.

boostsecurityio/poutine523—~336Automated safety check: PassApache-2.0today
9

Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

trailofbits/skills7.5k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0today
10

Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe…

openclaw/openclaw392k—~14kAutomated safety check: PassMITtoday
11

Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

malloydata/publisher116—~5.1kAutomated safety check: PassMITtoday
12
12.Code SecurityOfficial

Security guidelines for writing secure code. An agent skill from semgrep/skills.

semgrep/skills324—~1.2kAutomated safety check: PassUnknown2 mo ago
13

Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

mistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.0today
14

Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

getknit/knit133—~1.2kAutomated safety check: PassGPL-3.0today
15

Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.

AgentSecOps/SecOpsAgentKit2201 repo~4.4kAutomated safety check: PassUnknown5 mo ago
16

Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

boostsecurityio/poutine523—~214Automated safety check: PassApache-2.0today
17

Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.

boostsecurityio/poutine523—~173Automated safety check: PassApache-2.0today
18

Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

irahardianto/awesome-agv156—~2.7kAutomated safety check: NotesMIT5 days ago
19

Detecta riscos básicos de segurança em repositórios (segredos expostos, configurações perigosas, padrões inseguros) e gera recomendações com evidências.

glaucia86/repocheckai121—~819Automated safety check: WarnMIT3 mo ago
20

Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

dralgorhythm/claude-agentic-framework125—~1.5kAutomated safety check: PassNo licence2 mo ago
21

Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~3.4kAutomated safety check: PassMITyesterday
22
22.CodeqlOfficial

Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.

github/awesome-copilot40k1 repo~3.4kAutomated safety check: PassMITyesterday
23

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

github/awesome-copilot40k1 repo~2.4kAutomated safety check: PassMITyesterday
24

Automated code review and security linting integration for CI/CD pipelines using reviewdog.

AgentSecOps/SecOpsAgentKit2201 repo~3kAutomated safety check: PassUnknown5 mo ago
25

Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
26

Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
27

Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
28

Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…

cloudposse/atmos1.4k—~4.7kAutomated safety check: PassApache-2.0today
29

Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

davila7/claude-code-templates33k—~1.7kAutomated safety check: NotesMITtoday
30

CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows).

pskoett/pskoett-ai-skills315—~1.1kAutomated safety check: PassNo licence5 days ago
31

PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills.

alirezarezvani/claude-skills28k—~1.9kAutomated safety check: PassMIT1 mo ago
32

PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

tetherto/qvac685—~2.5kAutomated safety check: PassApache-2.0today
33

Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

tobihagemann/turbo408—~1.5kAutomated safety check: PassMITyesterday
34

External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k1 repo~4.3kAutomated safety check: WarnMITyesterday
35

Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support

Hack23/cia239—~3.8kAutomated safety check: PassApache-2.0today
36

Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

ccplugins/awesome-claude-code-plugins970—~486Automated safety check: NotesApache-2.01 mo ago
37

Read-only GitHub Actions workflow security audit for one repository, a repository set, or a whole GitHub org.

apache/magpie114—~3.8kAutomated safety check: PassApache-2.0today
38

Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution.

aiskillstore/marketplace433—~3.2kAutomated safety check: PassNo licencetoday