Search
Security · Dependency management
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. | mono/ | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | yesterday |
| 2 | Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and… | activepieces/ | 25k | — | ~2.9k | Automated safety check: Pass | Unknown | today |
| 3 | Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. | gocronx-team/ | 801 | — | ~690 | Automated safety check: Pass | MIT | yesterday |
| 4 | Check if recent cybersecurity alerts from 10 international CERTs affect your current project. | karimhabush/ | 263 | — | ~2.5k | Automated safety check: Pass | MIT | today |
| 5 | Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. | netdata/ | 81k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | today |
| 6 | GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release… | samber/ | 3.4k | — | ~3.7k | Automated safety check: Pass | MIT | 9 days ago |
| 7 | Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk. | bodadotsh/ | 858 | — | ~1k | Automated safety check: Warn | MIT | 10 days ago |
| 8 | CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines. | context-labs/ | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | 6 days ago |
| 9 | Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision. | backnotprop/ | 9.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 10 | Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images. | warpdotdev/ | 65k | 1 repo | ~2.1k | Automated safety check: Pass | AGPL-3.0 | today |
| 11 | Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout. | secondsky/ | 462 | — | ~4.8k | Automated safety check: Warn | GPL-3.0 | 5 days ago |
| 12 | Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop. | cobusgreyling/ | 11k | — | ~626 | Automated safety check: Pass | MIT | today |
| 13 | Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages. | ruby-git/ | 1.8k | — | ~806 | Automated safety check: Pass | MIT | 9 days ago |
| 14 | 14.Cve Doctor Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix. | getlago/ | 163 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 15 | Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline. | mono/ | 5.6k | — | ~5.7k | Automated safety check: Pass | MIT | yesterday |
| 16 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 287 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 17 | Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. | alirezarezvani/ | 777 | — | ~1.2k | Automated safety check: Notes | MIT | 3 mo ago |
| 18 | 18.Fix Vulns Automated triage and fixing of Dependabot security vulnerabilities (IN-1189). | linuxfoundation/ | 282 | — | ~3.8k | Automated safety check: Notes | MIT | 9 days ago |
| 19 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.5k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 20 | Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. | getknit/ | 133 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | yesterday |
| 21 | Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle… | axelixlabs/ | 148 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | today |
| 22 | Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch. | cloudposse/ | 1.4k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 23 | 23.Dep Security Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that… | tinyfish-io/ | 2.2k | — | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 24 | Ghost Security - Software Composition Analysis (SCA) scanner. | ghostsecurity/ | 409 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | 12 days ago |
| 25 | Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste. | microsoft/ | 107 | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 26 | Supply-chain security controls for the @cipherstash/stack monorepo. | cipherstash/ | 157 | — | ~5.2k | Automated safety check: Warn | MIT | yesterday |
| 27 | Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run. | dralgorhythm/ | 125 | — | ~1.5k | Automated safety check: Pass | No licence | 2 mo ago |
| 28 | GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL). | secondsky/ | 227 | — | ~4k | Automated safety check: Notes | MIT | 13 days ago |
| 29 | Respond to blocked package installs and manage the Interlinked supply-chain allowlist. | QuentinCody/ | 178 | — | ~2.8k | Automated safety check: Pass | MIT | yesterday |
| 30 | 30.Cve Scan Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart). | softspark/ | 180 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 31 | Scan package manifests and lockfiles for outdated and vulnerable dependencies. | cobusgreyling/ | 11k | — | ~531 | Automated safety check: Pass | MIT | today |
| 32 | Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory… | unxed/ | 243 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | yesterday |
| 33 | Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Golang dependency management — go.mod, installing/upgrading packages, Minimal Version Selection, vulnerability scanning, binary size, Dependabot/Renovate, conflict resolution, go.work. | context-labs/ | 1.1k | — | ~2.4k | Automated safety check: Pass | MIT | 6 days ago |
| 35 | Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. | briiirussell/ | 413 | — | ~3.2k | Automated safety check: Warn | MIT | 4 mo ago |
| 36 | Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. | decebals/ | 751 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 37 | Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 38 | Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. | Varnan-Tech/ | 674 | — | ~3k | Automated safety check: Notes | MIT | 1 mo ago |
| 39 | Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 40 | Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. | c0x12c/ | 106 | — | ~1.6k | Automated safety check: Warn | No licence | 3 mo ago |
| 41 | Scan project dependencies for known vulnerabilities and CVEs. | ruvnet/ | 74k | — | ~258 | Automated safety check: Pass | MIT | yesterday |
| 42 | A skill your agent uses when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project… | cwinvestments/ | 423 | — | ~3.1k | Automated safety check: Pass | Proprietary | 14 days ago |
| 43 | [omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and… | rlaope/ | 3.2k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 44 | 44.Update Deps Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR. | joshukraine/ | 429 | — | ~2.2k | Automated safety check: Pass | MIT | 4 days ago |
| 45 | Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 46 | Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.5k | Automated safety check: Notes | MIT | yesterday |
| 47 | Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies. | owid/ | 159 | — | ~2.8k | Automated safety check: Pass | MIT | yesterday |
| 48 | 48.Sca Audit Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook. | OWASP/ | 188 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |