Search
Supply chain security
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. | trufflesecurity/ | 28k | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 2 | Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT. | NVIDIA/ | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 3 | Scan agent skills for security issues. An agent skill from getsentry/skills. | getsentry/ | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 4 | Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment. | yan-labs/ | 481 | 1 repo | ~3.3k | Automated safety check: Pass | No licence | 9 days ago |
| 5 | A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability. | zhaoxuya520/ | 41k | 4 repos | ~953 | Automated safety check: Warn | MIT | 18 days ago |
| 6 | A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK. | vulnersCom/ | 376 | — | ~2.3k | Automated safety check: Pass | MIT | 12 days ago |
| 7 | 7.Eu Cra Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the… | Sushegaad/ | 946 | 1 repo | ~4k | Automated safety check: Pass | MIT | today |
| 8 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 9 | Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible. | backnotprop/ | 9.3k | — | ~640 | Automated safety check: Pass | Apache-2.0 | today |
| 10 | A skill your agent uses to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient… | sun461941-hub/ | 97 | — | ~3k | Automated safety check: Pass | MIT | 1 mo ago |
| 11 | 11.AI Bom Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their… | cdxgen/ | 1.1k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 12 | Run a pre-deployment security compliance checklist based on KISA guidelines. | cdppcorp/ | 360 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 13 | A skill your agent uses when analyzing stocks through @aleabitoreddit/Serenity-style supply-chain chokepoint thinking: AI/semi photonics, scarce physical bottlenecks, small-cap monopoly or duopoly… | W-Y-P/ | 119 | — | ~2.8k | Automated safety check: Pass | MIT | 4 mo ago |
| 14 | GitHub Actions security review for workflow exploitation vulnerabilities. | getsentry/ | 1k | 3 repos | ~2.2k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 15 | 15.Bom Audit Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk… | cdxgen/ | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | today |
| 16 | 16.Packslip Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and… | jdx/ | 136 | — | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 17 | Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk. | bodadotsh/ | 858 | — | ~1k | Automated safety check: Warn | MIT | 10 days ago |
| 18 | Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM. | relizaio/ | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | today |
| 19 | Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. | Tommy-yw/ | 546 | 3 repos | ~5k | Automated safety check: Pass | MIT | 4 mo ago |
| 20 | 20.Attack Flow Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports. | wiz-sec-public/ | 182 | — | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 21 | Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data. | addyosmani/ | 104k | 1 repo | ~4.4k | Automated safety check: Notes | MIT | 7 days ago |
| 22 | 22.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 283 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 23 | 23.Kesekit Fix Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems. | cdppcorp/ | 360 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 24 | 24.Nist 800 53 NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200… | Sushegaad/ | 946 | 1 repo | ~3.3k | Automated safety check: Pass | MIT | today |
| 25 | Serenity (@aleabitoreddit) 的思维框架与表达方式。基于 6 维度深度调研(1700+ 推文、Substack 长访谈、第三方分析、批评者观点), 提炼 5 个核心心智模型、8 条决策启发式和完整的表达 DNA。 | leslieyeo/ | 135 | — | ~3k | Automated safety check: Pass | MIT | 4 mo ago |
| 26 | 26.Docs Update project documentation when features are added or changed. | boostsecurityio/ | 523 | — | ~336 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 27 | Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation… | haskaomni/ | 633 | — | ~2.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 28 | Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision. | backnotprop/ | 9.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 29 | Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images. | warpdotdev/ | 65k | 1 repo | ~2.1k | Automated safety check: Pass | AGPL-3.0 | today |
| 30 | 30.AI Rulez Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more)… | Goldziher/ | 159 | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 31 | Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout. | secondsky/ | 462 | — | ~4.8k | Automated safety check: Warn | GPL-3.0 | 5 days ago |
| 32 | PaiWork-first Serenity (@aleabitoreddit) investment thesis tracking system. | AlphaMao1/ | 130 | — | ~1.8k | Automated safety check: Pass | MIT | 17 days ago |
| 33 | Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project. | NVIDIA/ | 16k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 34 | Routes truST behaviour changes from the written specification to a native executable test. | johannesPettersson80/ | 222 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 35 | 35.Bom Explore Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences… | cdxgen/ | 1.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 36 | Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot). | cdppcorp/ | 360 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 37 | Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. | hashgraph-online/ | 838 | — | ~605 | Automated safety check: Pass | Apache-2.0 | today |
| 38 | Runs a security health check on an OpenClaw environment and audits skills before or after installation for supply-chain and data-leak risks. | Tencent/ | 6.8k | — | ~9.5k | Automated safety check: Pass | MIT | yesterday |
| 39 | Market intelligence: strategy screener, popularity rankings, top movers with news correlation, quote anomalies, index/ETF constituent stocks, morning briefings, catalyst monitoring for watchlist… | helsome/ | 271 | 1 repo | ~1.7k | Automated safety check: Pass | MIT | 7 days ago |
| 40 | 40.Bom Signing Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 41 | 41.Interlinked Overview and router for the Interlinked CLI — a local guard, quality-enforcement, simplification-review, semantic-code-search, and observability layer for AI coding agents. | QuentinCody/ | 178 | — | ~4.1k | Automated safety check: Pass | MIT | yesterday |
| 42 | Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows. | xenitV1/ | 130 | 7 repos | ~1.8k | Automated safety check: Notes | MIT | 8 mo ago |
| 43 | SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. | secondsky/ | 462 | — | ~5.9k | Automated safety check: Warn | GPL-3.0 | 5 days ago |
| 44 | Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Warn | Apache-2.0 | today |
| 45 | End-to-end release runbook for playwright-rust — version bump, supply-chain refresh, per-crate CHANGELOGs, tag-prefix routing for the three workspace crates, the safer push-then-tag workflow that… | padamson/ | 157 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 46 | Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds. | AgentSecOps/ | 220 | 1 repo | ~2.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 47 | Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release… | openclaw/ | 392k | — | ~2.4k | Automated safety check: Pass | MIT | today |
| 48 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 287 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |