Search
By alpha-omega-security
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.Triage Default pipeline scrutineer runs when a repository is added. | alpha-omega-security/ | 242 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 2 | 2.Zizmor Audit GitHub Actions workflows with zizmor and explain reported hits using bundled trust-boundary references. | alpha-omega-security/ | 242 | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 3 | 3.Bandit Run bandit against the Python source in the repository and map its hits into the findings shape. | alpha-omega-security/ | 242 | — | ~615 | Automated safety check: Notes | MIT | today |
| 4 | Audit the repository against the OpenSSF Baseline with darnit, resolve the controls darnit defers to LLM analysis or could not verify, and record per-control verdicts plus the attained Baseline level. | alpha-omega-security/ | 242 | — | ~1.4k | Automated safety check: Notes | MIT | today |
| 5 | Run git-pkgs list and sbom against the repository and emit one envelope with per-section status. | alpha-omega-security/ | 242 | — | ~596 | Automated safety check: Pass | MIT | today |
| 6 | 6.History Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive. | alpha-omega-security/ | 242 | — | ~2.9k | Automated safety check: Notes | MIT | today |
| 7 | Identify the real maintainers of a repository and the best way to contact them about a security issue. | alpha-omega-security/ | 242 | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 8 | File a low-severity finding as an ordinary public GitHub issue after explicit analyst confirmation. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 9 | Scan the available Git history for secrets with Betterleaks and map detections into the findings shape. | alpha-omega-security/ | 242 | — | ~417 | Automated safety check: Notes | MIT | today |
| 10 | 10.Sbom Generate a CycloneDX SBOM for the repository via git-pkgs sbom. | alpha-omega-security/ | 242 | — | ~290 | Automated safety check: Pass | MIT | today |
| 11 | 11.Semgrep Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape. | alpha-omega-security/ | 242 | — | ~439 | Automated safety check: Pass | MIT | today |
| 12 | Re-audit every past GHSA/CVE advisory published against this repository, anchored on each advisory's fix commit, for four failure modes, a regression of the original bug, a bypass of the fix, an… | alpha-omega-security/ | 242 | — | ~3.5k | Automated safety check: Notes | MIT | today |
| 13 | Decide whether a finding's suggested fix is a breaking change for top dependents. | alpha-omega-security/ | 242 | — | ~1.4k | Automated safety check: Pass | MIT | today |
| 14 | 14.Cna Match Match the repository to a CVE Numbering Authority so disclosures route to the CNA's security contact when one covers the repo. | alpha-omega-security/ | 242 | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 15 | 15.Disclose Draft the disclosure content for a finding in GitHub Security Advisory shape. | alpha-omega-security/ | 242 | — | ~4k | Automated safety check: Pass | MIT | today |
| 16 | 16.Exposure For one (finding, dependent) pair, decide whether the dependent's code reaches the upstream finding. | alpha-omega-security/ | 242 | — | ~989 | Automated safety check: Pass | MIT | today |
| 17 | Compare open findings in one repository and record how they relate. | alpha-omega-security/ | 242 | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 18 | 18.Forensics Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records. | alpha-omega-security/ | 242 | — | ~2.1k | Automated safety check: Notes | MIT | today |
| 19 | 19.Fork Stage a scanned repository into a private repo in the configured GitHub organisation. | alpha-omega-security/ | 242 | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 20 | 20.Mitigate Draft operational mitigations for a finding consumers can apply before a fix ships. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 21 | 21.Patch Propose a code patch for a finding. An agent skill from alpha-omega-security/scrutineer. | alpha-omega-security/ | 242 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 22 | 22.Posture Assess a repository's security posture and its readiness to receive a vulnerability report. | alpha-omega-security/ | 242 | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 23 | 23.Reachability Check whether known sinks in this application's dependencies are reachable from its own trust boundaries. | alpha-omega-security/ | 242 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 24 | 24.Reattack Independently re-attack one immutable proposed patch with root-cause variants and a benign control. | alpha-omega-security/ | 242 | — | ~1.4k | Automated safety check: Notes | MIT | today |
| 25 | 25.Recon Map distinct externally reachable input-processing subsystems into focus areas for the threat-model skill to carry into later security audits. | alpha-omega-security/ | 242 | — | ~951 | Automated safety check: Pass | MIT | today |
| 26 | After a finding has been marked fixed, watch the upstream for a release that contains the fix. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 27 | File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available. | alpha-omega-security/ | 242 | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 28 | 28.Revalidate Cheap finding classifier. An agent skill from alpha-omega-security/scrutineer. | alpha-omega-security/ | 242 | — | ~3.1k | Automated safety check: Pass | MIT | today |
| 29 | 29.Subprojects Enumerate scannable sub-folders inside a repository. An agent skill from alpha-omega-security/scrutineer. | alpha-omega-security/ | 242 | — | ~1.4k | Automated safety check: Pass | MIT | today |
| 30 | 30.Vuln Scan High-recall static source-code vulnerability scan adapted from Anthropic's defending-code reference harness. | alpha-omega-security/ | 242 | — | ~3.2k | Automated safety check: Pass | MIT | today |
| 31 | Focused static audit of device firmware and IoT software for update, boot, provisioning, credential, debug-interface and device-communication boundary failures, using an ISVS-informed threat model. | alpha-omega-security/ | 242 | — | ~1.6k | Automated safety check: Notes | MIT | today |
| 32 | 32.Audit Exfil Focused static audit for attacker-controlled reads, requests, parsers, or error paths that can disclose files, metadata, secrets, or internal responses. | alpha-omega-security/ | 242 | — | ~2.2k | Automated safety check: Notes | MIT | today |
| 33 | Focused static audit for attacker-controlled data reaching command execution, dynamic evaluation, unsafe deserialization, or server-side template execution. | alpha-omega-security/ | 242 | — | ~1.9k | Automated safety check: Notes | MIT | today |
| 34 | Audit package manager clients, registries, and proxies against a bundled threat model. | alpha-omega-security/ | 242 | — | ~1k | Automated safety check: Notes | MIT | today |
| 35 | 35.Audit Pii Focused static audit for real personal or customer-identifying data committed to source or exposed through logs, URLs, telemetry, exports, and responses. | alpha-omega-security/ | 242 | — | ~3k | Automated safety check: Notes | MIT | today |
| 36 | 36.Audit Web Focused static audit of web applications and APIs for session, browser-origin, upload and business-workflow boundary failures, using an ASVS-informed threat model. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Notes | MIT | today |
| 37 | Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized. | alpha-omega-security/ | 242 | — | ~425 | Automated safety check: Pass | MIT | today |
| 38 | Eval-only short-prompt variant of security-deep-dive for A/B testing against the production prompt. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 39 | Run brief --json to produce a structured overview of the repository. | alpha-omega-security/ | 242 | — | ~435 | Automated safety check: Pass | MIT | today |
| 40 | 40.Threat Model Derive a project's security contract from its source and docs, then emit it as structured data other skills can cite. | alpha-omega-security/ | 242 | — | ~6.8k | Automated safety check: Pass | MIT | today |
| 41 | 41.Verify Re-run a finding's reproduction against current HEAD, test its attack tree, grade five fixed evidence criteria, and account for every matched design control. | alpha-omega-security/ | 242 | — | ~5.7k | Automated safety check: Pass | MIT | today |
| 42 | 42.Advisories Fetch published GHSA and CVE advisories affecting any package this repository produces, via advisories.ecosyste.ms. | alpha-omega-security/ | 242 | — | ~696 | Automated safety check: Pass | MIT | today |
| 43 | 43.Critic Judge whether a validated finding can affect a real release build, and record the attacker position, preconditions, impact, counterevidence, and facts that could change that conclusion. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 44 | 44.Ingest Normalize an externally-produced security report in an arbitrary format into scrutineer findings. | alpha-omega-security/ | 242 | — | ~1k | Automated safety check: Pass | MIT | today |
| 45 | 45.Metadata Fetch repository metadata (description, default branch, languages, license, stars, archived, icon) from repos.ecosyste.ms and save it on the repository row. | alpha-omega-security/ | 242 | — | ~748 | Automated safety check: Pass | MIT | today |
| 46 | 46.Packages Look up every package this repository publishes across all registries via packages.ecosyste.ms, with downloads, dependent counts, latest version, registry URL and supply-chain risk flags. | alpha-omega-security/ | 242 | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 47 | 47.Reflect Extract bounded operational lessons from a settled triage cohort without changing finding dispositions or suppressions. | alpha-omega-security/ | 242 | — | ~874 | Automated safety check: Pass | MIT | today |
| 48 | 48.Variants Starting from one confirmed finding, search this repository's current source for distinct sibling instances of the same root cause and emit only validated new findings. | alpha-omega-security/ | 242 | — | ~1.2k | Automated safety check: Notes | MIT | today |