Search
Security · SOC 2 and security compliance
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Run a pre-deployment security compliance checklist based on KISA guidelines. | cdppcorp/ | 360 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 2 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 3 | Senior ISMS Audit Expert for internal and external information security management system auditing. | davila7/ | 33k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | today |
| 4 | Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and… | sangrokjung/ | 852 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 5 | Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. | alirezarezvani/ | 28k | 1 repo | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 6 | 安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust… | telagod/ | 244 | — | ~712 | Automated safety check: Pass | MIT | 2 mo ago |
| 7 | Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export. | GRCEngClub/ | 419 | — | ~2.4k | Automated safety check: Notes | Unknown | 7 days ago |
| 8 | Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence. | github/ | 5.4k | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 9 | Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC 2, and HIPAA. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Provides step-by-step procedures for remediating Amazon S3 bucket misconfigurations that expose sensitive data: enabling S3 Block Public Access, auditing bucket policies and ACLs, enforcing… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. | aiskillstore/ | 433 | 6 repos | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 15 | Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001). | ancoleman/ | 525 | — | ~6.3k | Automated safety check: Pass | MIT | 10 mo ago |
| 16 | Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.5k | Automated safety check: Notes | MIT | yesterday |
| 17 | Audit a Python project's installed dependencies for known CVEs by wrapping pip-audit (PyPA's official vulnerability auditor) and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT | yesterday |
| 18 | Probe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes the full file tree under any reachable directory, including files the… | jeremylongshore/ | 2.8k | — | ~1.8k | Automated safety check: Notes | MIT | yesterday |
| 19 | Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards. | jeremylongshore/ | 2.8k | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 20 | Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present. | jeremylongshore/ | 2.8k | — | ~2.1k | Automated safety check: Notes | MIT | yesterday |
| 21 | Cross-framework infrastructure security audit across cloud, network, and CI/CD. | borghei/ | 891 | — | ~2.1k | Automated safety check: Pass | MIT | 4 days ago |
| 22 | Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for… | forcedotcom/ | 1.1k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 23 | Run a third-party / vendor security review and assign a risk tier with required controls. | mohitagw15856/ | 1.4k | — | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 24 | AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. | LeoYeAI/ | 2.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 25 | A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed… | jeremylongshore/ | 2.8k | — | ~3.7k | Automated safety check: Notes | MIT | yesterday |
| 26 | Security vulnerability scanner and OWASP compliance auditor for codebases. | curiositech/ | 244 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 27 | Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow. | dralgorhythm/ | 125 | — | ~496 | Automated safety check: Pass | No licence | 2 mo ago |
| 28 | 28.Security Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security. | travisjneuman/ | 100 | — | ~3.3k | Automated safety check: Pass | MIT | yesterday |