Search
Security · CI/CD
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability. | zhaoxuya520/ | 41k | 4 repos | ~953 | Automated safety check: Warn | MIT | 19 days ago |
| 2 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 3 | GitHub Actions security review for workflow exploitation vulnerabilities. | getsentry/ | 1k | 3 repos | ~2.2k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 4 | GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release… | samber/ | 3.4k | — | ~3.7k | Automated safety check: Pass | MIT | 9 days ago |
| 5 | CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines. | context-labs/ | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | 6 days ago |
| 6 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 7 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 8 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.5k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 9 | A skill your agent uses when the user wants to build, create, or develop anything — websites, apps, APIs, services, platforms. | nagisanzenin/ | 181 | — | ~16k | Automated safety check: Notes | No licence | 1 mo ago |
| 10 | Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe… | openclaw/ | 392k | — | ~14k | Automated safety check: Pass | MIT | today |
| 11 | Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline. | mono/ | 5.6k | — | ~5.7k | Automated safety check: Pass | MIT | yesterday |
| 12 | 12.Blue Team A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing… | gaasher/ | 174 | — | ~3.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 13 | Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds. | AgentSecOps/ | 220 | 1 repo | ~2.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 14 | Security guidelines for writing secure code. An agent skill from semgrep/skills. | semgrep/ | 324 | — | ~1.2k | Automated safety check: Pass | Unknown | 2 mo ago |
| 15 | Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. | mistralai/ | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 16 | Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. | getknit/ | 133 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | yesterday |
| 17 | Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates. | AgentSecOps/ | 220 | 1 repo | ~4.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 18 | Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository. | boostsecurityio/ | 523 | — | ~173 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 19 | Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments. | irahardianto/ | 156 | — | ~2.7k | Automated safety check: Notes | MIT | 6 days ago |
| 20 | Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL). | secondsky/ | 227 | — | ~4k | Automated safety check: Notes | MIT | 13 days ago |
| 22 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | 2 days ago |
| 23 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 24 | 24.Sca Trivy Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license… | AgentSecOps/ | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 25 | 25.Reviewdog Automated code review and security linting integration for CI/CD pipelines using reviewdog. | AgentSecOps/ | 220 | 1 repo | ~3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 26 | 26.Sast Bandit Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. | AgentSecOps/ | 220 | 1 repo | ~2.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 27 | Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory… | unxed/ | 243 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | yesterday |
| 28 | Deploy DefectDojo as a centralized vulnerability management dashboard that ingests findings from 200+ security scanners, deduplicates results, tracks remediation metrics, and integrates with CI/CD… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Runs a hypothesis-driven threat hunt for supply-chain compromise (T1195) by querying SIEM/EDR logs for trojanized software updates, compromised dependencies, unauthorized code modifications, and… | mukul975/ | 34k | — | ~899 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Implements code signing for build artifacts (binaries, packages, containers) using GPG, Sigstore, and platform-specific signing tools, establishing trust chains and verifying signatures in… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | 36.Atmos CI Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs… | cloudposse/ | 1.4k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 37 | Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets… | mukul975/ | 34k | — | ~655 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Implements API security testing on the 42Crunch platform, combining API Audit for static analysis of OpenAPI definitions, API Conformance Scan for dynamic vulnerability testing, and API Protect for… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 40 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 41 | Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 42 | Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. | wshobson/ | 40k | — | ~2.5k | Automated safety check: Pass | MIT | 6 days ago |
| 43 | Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines. | ancoleman/ | 525 | — | ~3.8k | Automated safety check: Pass | MIT | 10 mo ago |
| 44 | Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2… | davila7/ | 33k | — | ~1.7k | Automated safety check: Notes | MIT | yesterday |
| 45 | 当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。 | zhaji2333/ | 115 | — | ~688 | Automated safety check: Warn | MIT | 26 days ago |
| 46 | Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed… | mukul975/ | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 47 | PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills. | alirezarezvani/ | 28k | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 48 | 48.Codeql Use the open-source CodeQL ecosystem for .NET security analysis. | managedcode/ | 486 | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |