Search
Security · GitHub Actions · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 2 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 3 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 4 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 5 | Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe… | openclaw/ | 392k | — | ~14k | Automated safety check: Pass | MIT | today |
| 6 | Run Warden security scans in this repo using Sentry's warden-skills. | UsefulSoftwareCo/ | 4.1k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 7 | Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. | mistralai/ | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 8 | Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. | getknit/ | 132 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 5 days ago |
| 9 | Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates. | AgentSecOps/ | 220 | 1 repo | ~4.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 10 | 10.Snapshot Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions. | boostsecurityio/ | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 11 | Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments. | irahardianto/ | 157 | — | ~2.7k | Automated safety check: Notes | MIT | 4 days ago |
| 12 | Detecta riscos básicos de segurança em repositórios (segredos expostos, configurações perigosas, padrões inseguros) e gera recomendações com evidências. | glaucia86/ | 121 | — | ~819 | Automated safety check: Warn | MIT | 3 mo ago |
| 13 | 13.AWS Iam Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | today |
| 14 | 14.Atmos CI Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs… | cloudposse/ | 1.4k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | today |
| 15 | Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets… | mukul975/ | 34k | — | ~655 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2… | davila7/ | 32k | — | ~1.7k | Automated safety check: Notes | MIT | today |
| 17 | The non-obvious invariants of the proactive nightly Claude audit workflow (.github/workflows/claude-nightly-audit.yml): the day-of-week mode selector, the two-key dedup scheme (clusterkey per… | amd/ | 1.6k | — | ~4.4k | Automated safety check: Pass | MIT | yesterday |
| 18 | Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. | tobihagemann/ | 409 | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 19 | CI/CD pipeline security, supply chain security, SLSA compliance, artifact signing, dependency scanning | Hack23/ | 239 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 20 | Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support | Hack23/ | 239 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | today |
| 21 | Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot. | ccplugins/ | 970 | — | ~486 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 22 | Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. | aiskillstore/ | 430 | — | ~3.2k | Automated safety check: Pass | No licence | today |