Search

Security · Secrets management

74 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

eigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0yesterday
2

Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

nanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMITyesterday
3

Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

nanocoai/nanoclaw31k—~1.1kAutomated safety check: NotesMITyesterday
4

Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

netdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0today
5

Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling.

ktnyt/cclsp675—~565Automated safety check: PassMIT7 mo ago
6

Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

vechain/x-app-template450—~1.2kAutomated safety check: PassMIT2 mo ago
7

When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

deonmenezes/mantishack503—~510Automated safety check: PassApache-2.08 days ago
8

Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

vinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT3 mo ago
9

Lets the agent list and read the secrets a user has configured, such as API keys and tokens, through two tai tools instead of hardcoding credentials into code or commands.

YaoApp/yao8.1k—~415Automated safety check: PassUnknown3 days ago
10

Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

nanocoai/nanoclaw31k—~856Automated safety check: PassMITyesterday
11

Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets.

zebbern/claude-code-guide4.7k—~831Automated safety check: PassMITyesterday
12

Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.

avelikiy/great_cto103—~884Automated safety check: NotesMITtoday
13

Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

transilienceai/communitytools563—~1.2kAutomated safety check: NotesMIT2 mo ago
14

Loads a missing environment variable or API key from the team's Infisical workspace into the current shell, or runs a command with all project secrets injected.

Devin-AXIS/iPolloWork6.8k1 repo~516Automated safety check: PassUnknownyesterday
15

Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

Jeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT7 days ago
16

Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works.

nanocoai/nanoclaw31k—~598Automated safety check: PassMITyesterday
17

Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills.

microsoft/skills3.1k5 repos~3.1kAutomated safety check: PassMITyesterday
18

How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes.

ibuilder/massing122—~1.7kAutomated safety check: PassMIT2 days ago
19

Azure Key Vault Keys SDK for .NET. An agent skill from microsoft/skills.

microsoft/skills3.1k5 repos~3.1kAutomated safety check: PassMITyesterday
20

Working on RedAmon's supply-chain scanner (offline OSV + GuardDog + retire + trufflehog): the offline OSV database that the scan path does not bootstrap, the world-readable requirement for the…

samugit83/redamon3k—~855Automated safety check: PassMIT2 days ago
21

Static security review for Flutter mobile apps and Dart code: hardcoded secrets, insecure storage, unsafe network calls, leaky logs, vulnerable dependencies.

VeryGoodOpenSource/vgv-ai-flutter-plugin170—~4.4kAutomated safety check: NotesMIT5 days ago
22

Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates.

utkusen/sast-skills1.3k—~6.5kAutomated safety check: NotesMIT6 mo ago
23

Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.

arpitg1304/robotics-agent-skills369—~7.8kAutomated safety check: WarnApache-2.02 mo ago
24

Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

AgentSecOps/SecOpsAgentKit2201 repo~2.6kAutomated safety check: PassUnknown5 mo ago
25
25.Security ReviewOfficial

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

github/awesome-copilot40k1 repo~2.3kAutomated safety check: NotesMIT2 days ago
26

Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

unxed/f42432 repos~3.6kAutomated safety check: PassMITyesterday
27

Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
28

Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
29

RLS validation, security audits, OWASP compliance, and vulnerability scanning.

bybren-llc/safe-agentic-workflow423—~1.4kAutomated safety check: PassMIT2 mo ago
30

Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold…

warpdotdev/oz-for-oss3121 repo~2kAutomated safety check: NotesMIT23 days ago
31

Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible-travel patterns, and credential-stuffing indicators using GuardDuty, Microsoft…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.9kAutomated safety check: PassApache-2.01 mo ago
32

Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
33

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
34

Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets…

mukul975/Anthropic-Cybersecurity-Skills34k—~5.2kAutomated safety check: PassApache-2.01 mo ago
35

Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills.

rampstackco/claude-skills945—~3kAutomated safety check: PassMIT4 days ago
36

Review Next.js security audit patterns for App Router and Server Actions.

IgorWarzocha/Opencode-Workflows122—~1.5kAutomated safety check: NotesNo licence8 mo ago
37
37.Azure ComplianceOfficial

Run Azure compliance and security audits with azqr plus Key Vault expiration checks.

microsoft/GitHub-Copilot-for-Azure2552 repos~997Automated safety check: PassMITyesterday
38

Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

mukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.01 mo ago
39

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

uphiago/recon-skills1.3k—~2.6kAutomated safety check: PassMIT1 mo ago
40

Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

rand/cc-polymath181—~1.9kAutomated safety check: PassMIT7 mo ago
41

Audit MCP (Model Context Protocol) server configurations for security issues.

github/awesome-copilot40k—~3.1kAutomated safety check: PassMIT2 days ago
42

Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

IgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNo licence8 mo ago
43

[omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and…

rlaope/oh-my-hermes3.2k—~2.4kAutomated safety check: PassMITyesterday
44

Azure Key Vault SDK for Python. An agent skill from microsoft/skills.

microsoft/skills3.1k—~2.4kAutomated safety check: PassMITyesterday
45

DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…

modu-ai/moai-adk1.2k—~2.6kAutomated safety check: PassApache-2.0yesterday
46

Open-source intelligence gathering - company repository enumeration, secret scanning, git history analysis, employee footprint, and code exposure discovery.

transilienceai/communitytools563—~494Automated safety check: NotesMIT2 mo ago
47

A skill your agent uses when the user says 'scan for secrets', 'check for leaked keys', 'secrets scanner', 'hardcoded credentials', 'API key leak', or needs to detect exposed secrets in source code.

cwinvestments/memstack423—~6kAutomated safety check: NotesProprietary14 days ago
48

ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation.

jonathan-vella/apex217—~1.6kAutomated safety check: PassMITyesterday