Search

Security · npm · For developers

52 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

asyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0yesterday
2

Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

verdaccio/verdaccio18k—~853Automated safety check: PassMIT2 days ago
3

Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

TheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT5 mo ago
4

Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity.

activepieces/activepieces25k—~3.6kAutomated safety check: PassUnknowntoday
5

Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

zereight/gitlab-mcp2k1 repo~859Automated safety check: NotesMITtoday
6

Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

bodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT10 days ago
7

Check and apply security updates across the photofield project (api/Go, ui/npm, docs/npm, e2e/npm).

SmilyOrg/photofield608—~808Automated safety check: PassMIT1 mo ago
8

Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.

pegasi-ai/reins392—~1.4kAutomated safety check: WarnApache-2.0yesterday
9

Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

zebbern/claude-code-guide4.7k—~1.3kAutomated safety check: PassMITyesterday
10

Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

backnotprop/plannotator9.3k—~1.8kAutomated safety check: PassApache-2.0today
11

Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

hashgraph-online/hol-guard845—~605Automated safety check: PassApache-2.0today
12

The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main.

ibuilder/massing122—~2.3kAutomated safety check: PassMIT2 days ago
13

Remediate security vulnerabilities found by Grype or pnpm audit.

stacklok/toolhive-studio171—~2.3kAutomated safety check: NotesApache-2.0yesterday
14

Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

majiayu000/spellbook287—~1.5kAutomated safety check: PassMIT2 days ago
15

Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…

tinyfish-io/tinyfish-cookbook2.2k—~2.4kAutomated safety check: PassMIT2 days ago
16

Supply-chain security controls for the @cipherstash/stack monorepo.

cipherstash/stack157—~5.2kAutomated safety check: WarnMITyesterday
17

Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

dralgorhythm/claude-agentic-framework125—~1.5kAutomated safety check: PassNo licence2 mo ago
18

Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

QuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT2 days ago
19

Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.

bagofwords1/bagofwords459—~1.7kAutomated safety check: PassUnknowntoday
20

Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

softspark/ai-toolkit180—~1.3kAutomated safety check: NotesApache-2.0yesterday
21

Scan package manifests and lockfiles for outdated and vulnerable dependencies.

cobusgreyling/loop-engineering11k—~531Automated safety check: PassMITtoday
22

Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).

nubjs/nub4.4k—~2.4kAutomated safety check: PassMITyesterday
23

Pre-production audit, hardening, and go-live checklists for FrontMCP servers.

agentfront/frontmcp146—~6.5kAutomated safety check: PassApache-2.0yesterday
24

Automate browsers (Playwright) and Windows desktop applications (UI automation) for reverse-engineering evidence collection, UI-driven workflows, and network observation during analysis.

sickn33/agentic-awesome-skills47k1 repo~1.3kAutomated safety check: PassMIT2 days ago
25

Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

Varnan-Tech/opendirectory674—~3kAutomated safety check: NotesMIT1 mo ago
26

Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

davila7/claude-code-templates33k—~1.7kAutomated safety check: NotesMITyesterday
27

Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
28

Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.

c0x12c/ai-toolkit106—~1.6kAutomated safety check: WarnNo licence3 mo ago
29

Audit MCP (Model Context Protocol) server configurations for security issues.

github/awesome-copilot40k—~3.1kAutomated safety check: PassMIT2 days ago
30

Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat.

epam/ai-dial-chat504—~1.9kAutomated safety check: PassApache-2.0yesterday
31

A skill your agent uses when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project…

cwinvestments/memstack423—~3.1kAutomated safety check: PassProprietary14 days ago
32

Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

tobihagemann/turbo408—~1.5kAutomated safety check: PassMIT2 days ago
33

Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.).

hardisgroupcom/sfdx-hardis403—~1.3kAutomated safety check: NotesAGPL-3.0yesterday
34

Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR.

joshukraine/dotfiles429—~2.2kAutomated safety check: PassMIT5 days ago
35

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to…

hardw00t/ai-security-arsenal105—~3kAutomated safety check: PassNo licence5 mo ago
36

Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: WarnApache-2.01 mo ago
37

Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: WarnApache-2.01 mo ago
38

Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema.

jeremylongshore/tons-of-skills-marketplace2.8k—~2.5kAutomated safety check: NotesMITyesterday
39

Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.

jeremylongshore/tons-of-skills-marketplace2.8k—~2.2kAutomated safety check: NotesMITyesterday
40

Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.

owid/etl159—~2.8kAutomated safety check: PassMITyesterday
41

Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

OWASP/secure-agent-playbook188—~494Automated safety check: PassCC-BY-4.015 days ago
42

Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.

ArabelaTso/Skills-4-SE253—~2.1kAutomated safety check: PassApache-2.01 mo ago
43

Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

jwynia/agent-skills170—~1.7kAutomated safety check: PassMIT7 mo ago
44

扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。

rongxinzy/RongxinAI154—~868Automated safety check: PassMITyesterday
45

Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

Goldziher/ai-rulez159—~250Automated safety check: PassMITyesterday
46

Comprehensive security vulnerability analysis for codebases and infrastructure.

aiskillstore/marketplace433—~1.2kAutomated safety check: NotesNo licenceyesterday
47

Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses.

jamditis/claude-skills-journalism416—~2kAutomated safety check: WarnMIT6 days ago
48

Dependency gatekeeper. An agent skill from ccplugins/awesome-claude-code-plugins.

ccplugins/awesome-claude-code-plugins970—~1.5kAutomated safety check: PassMIT1 mo ago