Search

Supply chain security

233 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

trufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0yesterday
2
2.Skill InspectorOfficial

Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

NVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0today
3
3.Skill ScannerOfficial

Scan agent skills for security issues. An agent skill from getsentry/skills.

getsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0yesterday
4

Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

yan-labs/serenity-aleabitoreddit4811 repo~3.3kAutomated safety check: PassNo licence9 days ago
5

A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

zhaoxuya520/reverse-skill41k4 repos~953Automated safety check: WarnMIT18 days ago
6

A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

vulnersCom/api376—~2.3kAutomated safety check: PassMIT12 days ago
7

Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repo~4kAutomated safety check: PassMITtoday
8

A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

asyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0yesterday
9

Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

backnotprop/plannotator9.3k—~640Automated safety check: PassApache-2.0today
10

A skill your agent uses to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient…

sun461941-hub/ai-project-copilot97—~3kAutomated safety check: PassMIT1 mo ago
11

Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

cdxgen/cdxgen1.1k—~2.5kAutomated safety check: PassApache-2.0today
12

Run a pre-deployment security compliance checklist based on KISA guidelines.

cdppcorp/KESE-KIT360—~1.3kAutomated safety check: PassMIT6 mo ago
13

A skill your agent uses when analyzing stocks through @aleabitoreddit/Serenity-style supply-chain chokepoint thinking: AI/semi photonics, scarce physical bottlenecks, small-cap monopoly or duopoly…

W-Y-P/Serenity-aleabitoreddit-skill119—~2.8kAutomated safety check: PassMIT4 mo ago
14

GitHub Actions security review for workflow exploitation vulnerabilities.

getsentry/skills1k3 repos~2.2kAutomated safety check: NotesApache-2.0yesterday
15

Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

cdxgen/cdxgen1.1k—~2.4kAutomated safety check: PassApache-2.0today
16

Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…

jdx/packslip136—~2.9kAutomated safety check: PassMITyesterday
17

Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

bodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT10 days ago
18

Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.

relizaio/rearm127—~2.9kAutomated safety check: PassAGPL-3.0today
19

Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

Tommy-yw/RunbookHermes5463 repos~5kAutomated safety check: PassMIT4 mo ago
20

Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports.

wiz-sec-public/SITF182—~3.1kAutomated safety check: PassUnknown2 mo ago
21

Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

addyosmani/agent-skills104k1 repo~4.4kAutomated safety check: NotesMIT7 days ago
22

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT2 mo ago
23

Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems.

cdppcorp/KESE-KIT360—~1.1kAutomated safety check: PassMIT6 mo ago
24

NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repo~3.3kAutomated safety check: PassMITtoday
25

Serenity (@aleabitoreddit) 的思维框架与表达方式。基于 6 维度深度调研(1700+ 推文、Substack 长访谈、第三方分析、批评者观点), 提炼 5 个核心心智模型、8 条决策启发式和完整的表达 DNA。

leslieyeo/serenity-reply135—~3kAutomated safety check: PassMIT4 mo ago
26
26.Docs

Update project documentation when features are added or changed.

boostsecurityio/poutine523—~336Automated safety check: PassApache-2.0yesterday
27

Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…

haskaomni/serenity-skill633—~2.6kAutomated safety check: PassMIT2 mo ago
28

Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

backnotprop/plannotator9.3k—~1.8kAutomated safety check: PassApache-2.0today
29

Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

warpdotdev/warp65k1 repo~2.1kAutomated safety check: PassAGPL-3.0today
30

Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more)…

Goldziher/ai-rulez159—~3.3kAutomated safety check: PassMITtoday
31

Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout.

secondsky/sap-skills462—~4.8kAutomated safety check: WarnGPL-3.05 days ago
32

PaiWork-first Serenity (@aleabitoreddit) investment thesis tracking system.

AlphaMao1/AlphaMao_Skills130—~1.8kAutomated safety check: PassMIT17 days ago
33
33.SbomOfficial

Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project.

NVIDIA/OpenShell16k—~1.3kAutomated safety check: PassApache-2.0today
34

Routes truST behaviour changes from the written specification to a native executable test.

johannesPettersson80/trust-platform222—~1.5kAutomated safety check: PassApache-2.0today
35

Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

cdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0today
36

Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

cdppcorp/KESE-KIT360—~1.4kAutomated safety check: PassMIT6 mo ago
37

Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

hashgraph-online/hol-guard838—~605Automated safety check: PassApache-2.0today
38

Runs a security health check on an OpenClaw environment and audits skills before or after installation for supply-chain and data-leak risks.

Tencent/AI-Infra-Guard6.8k—~9.5kAutomated safety check: PassMITyesterday
39

Market intelligence: strategy screener, popularity rankings, top movers with news correlation, quote anomalies, index/ETF constituent stocks, morning briefings, catalyst monitoring for watchlist…

helsome/folio2711 repo~1.7kAutomated safety check: PassMIT7 days ago
40

Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

cdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0today
41

Overview and router for the Interlinked CLI — a local guard, quality-enforcement, simplification-review, semantic-code-search, and observability layer for AI coding agents.

QuentinCody/interlinked-cli178—~4.1kAutomated safety check: PassMITyesterday
42

Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

xenitV1/Antigravity-Workflows1307 repos~1.8kAutomated safety check: NotesMIT8 mo ago
43

SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection.

secondsky/sap-skills462—~5.9kAutomated safety check: WarnGPL-3.05 days ago
44

Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

cdxgen/cdxgen1.1k—~1.5kAutomated safety check: WarnApache-2.0today
45

End-to-end release runbook for playwright-rust — version bump, supply-chain refresh, per-crate CHANGELOGs, tag-prefix routing for the three workspace crates, the safer push-then-tag workflow that…

padamson/playwright-rust157—~4.1kAutomated safety check: PassApache-2.0yesterday
46

Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

AgentSecOps/SecOpsAgentKit2201 repo~2.5kAutomated safety check: PassUnknown5 mo ago
47

Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release…

openclaw/openclaw392k—~2.4kAutomated safety check: PassMITtoday
48

Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

majiayu000/spellbook287—~1.5kAutomated safety check: PassMIT2 days ago