Search
Security · npm
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2 | Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues. | verdaccio/ | 18k | — | ~853 | Automated safety check: Pass | MIT | 2 days ago |
| 3 | Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge. | TheDecipherist/ | 551 | — | ~1.3k | Automated safety check: Notes | MIT | 5 mo ago |
| 4 | Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity. | activepieces/ | 25k | — | ~3.6k | Automated safety check: Pass | Unknown | today |
| 5 | Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps. | zereight/ | 2k | 1 repo | ~859 | Automated safety check: Notes | MIT | today |
| 6 | Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk… | cdxgen/ | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk. | bodadotsh/ | 858 | — | ~1k | Automated safety check: Warn | MIT | 10 days ago |
| 8 | Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM. | relizaio/ | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 9 | Check and apply security updates across the photofield project (api/Go, ui/npm, docs/npm, e2e/npm). | SmilyOrg/ | 608 | — | ~808 | Automated safety check: Pass | MIT | 1 mo ago |
| 10 | Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision. | pegasi-ai/ | 392 | — | ~1.4k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 11 | Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. | zebbern/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 12 | Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision. | backnotprop/ | 9.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 13 | Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. | hashgraph-online/ | 845 | — | ~605 | Automated safety check: Pass | Apache-2.0 | today |
| 14 | 14.Ship Release The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main. | ibuilder/ | 122 | — | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 15 | Remediate security vulnerabilities found by Grype or pnpm audit. | stacklok/ | 171 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 16 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 287 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 17 | Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. | alirezarezvani/ | 777 | — | ~1.2k | Automated safety check: Notes | MIT | 3 mo ago |
| 18 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.5k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 19 | Pin the npm registry to the public default and fetch published release notes | cisco-ai-defense/ | 2.6k | — | ~180 | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 20 | 20.Dep Security Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that… | tinyfish-io/ | 2.2k | — | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 21 | Supply-chain security controls for the @cipherstash/stack monorepo. | cipherstash/ | 157 | — | ~5.2k | Automated safety check: Warn | MIT | yesterday |
| 22 | Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run. | dralgorhythm/ | 125 | — | ~1.5k | Automated safety check: Pass | No licence | 2 mo ago |
| 23 | Respond to blocked package installs and manage the Interlinked supply-chain allowlist. | QuentinCody/ | 178 | — | ~2.8k | Automated safety check: Pass | MIT | yesterday |
| 24 | Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. | alirezarezvani/ | 28k | 1 repo | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 25 | Bootstrap a development environment and set the npm registry to https://npm.artifacts-mirror.internal-corp.dev | cisco-ai-defense/ | 2.6k | — | ~169 | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 26 | Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. | bagofwords1/ | 459 | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 27 | 27.Cve Scan Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart). | softspark/ | 180 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 28 | Scan package manifests and lockfiles for outdated and vulnerable dependencies. | cobusgreyling/ | 11k | — | ~531 | Automated safety check: Pass | MIT | today |
| 29 | 29.Corpus Sweep Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run). | nubjs/ | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 30 | Audit and manage dependencies across multi-language projects. | alirezarezvani/ | 28k | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 31 | Pre-production audit, hardening, and go-live checklists for FrontMCP servers. | agentfront/ | 146 | — | ~6.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 32 | Automate browsers (Playwright) and Windows desktop applications (UI automation) for reverse-engineering evidence collection, UI-driven workflows, and network observation during analysis. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 2 days ago |
| 33 | Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. | briiirussell/ | 413 | — | ~3.2k | Automated safety check: Warn | MIT | 4 mo ago |
| 34 | Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction. | inkline/ | 1.5k | — | ~1.1k | Automated safety check: Pass | No licence | 29 days ago |
| 35 | Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. | Varnan-Tech/ | 674 | — | ~3k | Automated safety check: Notes | MIT | 1 mo ago |
| 36 | Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2… | davila7/ | 33k | — | ~1.7k | Automated safety check: Notes | MIT | yesterday |
| 37 | Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. | c0x12c/ | 106 | — | ~1.6k | Automated safety check: Warn | No licence | 3 mo ago |
| 40 | Audit MCP (Model Context Protocol) server configurations for security issues. | github/ | 40k | — | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 41 | Scan project dependencies for known vulnerabilities and CVEs. | ruvnet/ | 74k | — | ~258 | Automated safety check: Pass | MIT | yesterday |
| 42 | Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat. | epam/ | 504 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 43 | A skill your agent uses when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project… | cwinvestments/ | 423 | — | ~3.1k | Automated safety check: Pass | Proprietary | 14 days ago |
| 44 | Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. | tobihagemann/ | 408 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 45 | Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.). | hardisgroupcom/ | 403 | — | ~1.3k | Automated safety check: Notes | AGPL-3.0 | yesterday |
| 46 | 46.Update Deps Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR. | joshukraine/ | 429 | — | ~2.2k | Automated safety check: Pass | MIT | 4 days ago |
| 47 | Execute this skill enables comprehensive vulnerability scanning using the vulnerability-scanner plugin. | jeremylongshore/ | 2.8k | — | ~927 | Automated safety check: Pass | MIT | yesterday |
| 48 | 48.Sca Security Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to… | hardw00t/ | 105 | — | ~3k | Automated safety check: Pass | No licence | 5 mo ago |