Search
Security · npm · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2 | Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge. | TheDecipherist/ | 551 | — | ~1.3k | Automated safety check: Notes | MIT | 5 mo ago |
| 3 | Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps. | zereight/ | 2k | 1 repo | ~859 | Automated safety check: Notes | MIT | today |
| 4 | Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk… | cdxgen/ | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | today |
| 5 | Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM. | relizaio/ | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 6 | Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision. | backnotprop/ | 9.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. | alirezarezvani/ | 777 | — | ~1.2k | Automated safety check: Notes | MIT | 3 mo ago |
| 8 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.5k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 9 | Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run). | nubjs/ | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 10 | Pre-production audit, hardening, and go-live checklists for FrontMCP servers. | agentfront/ | 146 | — | ~6.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 11 | Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. | briiirussell/ | 413 | — | ~3.2k | Automated safety check: Warn | MIT | 4 mo ago |
| 12 | Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction. | inkline/ | 1.5k | — | ~1.1k | Automated safety check: Pass | No licence | 1 mo ago |
| 13 | Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2… | davila7/ | 33k | — | ~1.7k | Automated safety check: Notes | MIT | yesterday |
| 14 | Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. | c0x12c/ | 106 | — | ~1.6k | Automated safety check: Warn | No licence | 3 mo ago |
| 16 | Scan project dependencies for known vulnerabilities and CVEs. | ruvnet/ | 74k | — | ~258 | Automated safety check: Pass | MIT | yesterday |
| 17 | Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. | tobihagemann/ | 408 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 18 | Execute this skill enables comprehensive vulnerability scanning using the vulnerability-scanner plugin. | jeremylongshore/ | 2.8k | — | ~927 | Automated safety check: Pass | MIT | yesterday |
| 19 | Usar antes de aceptar una dependencia nueva. An agent skill from 686f6c61/alfred-dev. | 686f6c61/ | 117 | — | ~379 | Automated safety check: Pass | MIT | 1 mo ago |
| 20 | Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface. | LearnPrompt/ | 110 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 21 | Audit npm dependencies for security vulnerabilities, outdated packages, and unused dependencies. | OneWave-AI/ | 336 | — | ~835 | Automated safety check: Pass | MIT | 9 days ago |
| 22 | TencentOS Server 全栈运维诊断,根据用户的自然语言描述,自动识别需要的能力接口,查询能力实现,使用具体能力解决客户问题。覆盖磁盘空间/分区/文件系统/LVM/健康检测、网络连通性/丢包/延迟排查、CPU火焰图/系统调用热点/调度延迟/中断均衡/文件IO延迟/进程IO追踪分析、内存泄漏/OOM诊断、系统日志/服务管理/时间同步/软件包/软件源管理、kdump配置与故障排查、等保三级… | infometa/ | 348 | — | ~3.2k | Automated safety check: Pass | No licence | yesterday |