Codebase Cleanup Deps Audit
aiskillstore/marketplace
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.
Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development
$ npx skills add Hack23/cia --skill open-source-policy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Hack23/cia open-source-policy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/open-source-policy .claude/skills/open-source-policy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "open-source-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/open-source-policy into .claude/skills/open-source-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "open-source-policy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Hack23/cia/tree/master/.github/skills/open-source-policyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Hack23/cia --skill open-source-policy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Hack23/cia open-source-policy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/open-source-policy .agents/skills/open-source-policy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "open-source-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/open-source-policy into .agents/skills/open-source-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "open-source-policy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill open-source-policy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Hack23/cia open-source-policy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/open-source-policy .cursor/skills/open-source-policy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "open-source-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/open-source-policy into .cursor/skills/open-source-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "open-source-policy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Hack23/cia.git --path .github/skills/open-source-policy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Hack23/cia --skill open-source-policy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Hack23/cia open-source-policy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/open-source-policy .gemini/skills/open-source-policy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "open-source-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/open-source-policy into .gemini/skills/open-source-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "open-source-policy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Hack23/cia open-source-policyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Hack23/cia --skill open-source-policy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/open-source-policy .github/skills/open-source-policy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "open-source-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/open-source-policy into .github/skills/open-source-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "open-source-policy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill open-source-policy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Hack23/cia open-source-policy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/open-source-policy .opencode/skills/open-source-policy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "open-source-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/open-source-policy into .opencode/skills/open-source-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "open-source-policy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
open-source-policyOpen source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development
Open Source Policy is an agent skill from Hack23/cia. Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development
Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security, Regulatory compliance and Vulnerability scanning. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.combestpractices.coreinfrastructure.orgscorecard.devsonarcloud.ioimg.shields.ioapi.securityscorecards.devslsa.devFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
FOSSA_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Open Source Policy loads about 4.6k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 1,088 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 1,088 words, ~4,641 tokens.
.claude/skills/open-source-policy/SKILL.md (or your agent's skills folder).This skill provides comprehensive open source governance aligned with Hack23 AB's transparency principle, demonstrating that radical openness creates competitive advantage through evidence-based security excellence. It enables repository maintainers to implement required security badges, manage license compliance, generate SBOMs, and maintain security documentation that serves as both operational necessity and client demonstration.
Apply this skill when:
Do NOT use for:
graph TB
REPO["📦 Repository"] --> BADGES["🎖️ Security Badges"]
BADGES --> OSS[OpenSSF Scorecard<br/>Target: ≥7.0]
BADGES --> CII[CII Best Practices<br/>Minimum: Passing]
BADGES --> SLSA[SLSA Level 3<br/>Build Attestation]
BADGES --> QUALITY[Quality Gate<br/>SonarCloud: Passed]
BADGES --> LICENSE[License Compliance<br/>FOSSA: Passing]
OSS --> OSS_CHECKS{15 Automated Checks}
OSS_CHECKS --> BRANCH[Branch Protection]
OSS_CHECKS --> SIGNED[Signed Commits]
OSS_CHECKS --> PINNED[Pinned Dependencies]
OSS_CHECKS --> VULN[Vulnerability Scanning]
OSS_CHECKS --> CODE_REVIEW[Code Review]
CII --> CII_CRITERIA{70+ Criteria}
CII_CRITERIA --> BASICS[Project Basics]
CII_CRITERIA --> CHANGE[Change Control]
CII_CRITERIA --> QUALITY_CII[Quality Assurance]
CII_CRITERIA --> SECURITY[Security]
CII_CRITERIA --> ANALYSIS[Analysis]
SLSA --> BUILD_INTEGRITY[Build Provenance<br/>Signed Artifacts<br/>Reproducible Builds]
QUALITY --> SONAR_METRICS[Code Coverage ≥80%<br/>Complexity Control<br/>Security Hotspots = 0]
LICENSE --> FOSSA_SCAN[Automated License Scan<br/>Attribution Management<br/>Compliance Reports]
BRANCH --> EVIDENCE["📊 Public Evidence"]
SIGNED --> EVIDENCE
QUALITY_CII --> EVIDENCE
BUILD_INTEGRITY --> EVIDENCE
SONAR_METRICS --> EVIDENCE
FOSSA_SCAN --> EVIDENCE
EVIDENCE --> CLIENTS["🤝 Client Trust<br/>Competitive Advantage"]
style REPO fill:#1565C0,stroke:#0D47A1,stroke-width:3px,color:#fff
style BADGES fill:#4CAF50,stroke:#2E7D32,stroke-width:2px,color:#fff
style EVIDENCE fill:#FF9800,stroke:#F57C00,stroke-width:2px
style CLIENTS fill:#9C27B0,stroke:#6A1B9A,stroke-width:2px,color:#fffmain/master:SECURITY_ARCHITECTURE.md with Mermaid diagramsFUTURE_SECURITY_ARCHITECTURE.md for roadmapSECURITY.md with vulnerability disclosure processWORKFLOWS.md documenting CI/CD security gatesLICENSE (Apache 2.0 or compatible)NOTICE for third-party attributionsCODE_OF_CONDUCT.mdCONTRIBUTING.mdCRA-ASSESSMENT.md (EU Cyber Resilience Act)LICENSES/ directory with all dependency licenses.reuse/dep5 for machine-readable licensingTarget score: ≥7.0 across 15 automated checks
1. Branch-Protection (Weight: High)
# .github/branch-protection.yml
required_status_checks:
strict: true
contexts:
- "CodeQL"
- "SonarCloud Code Analysis"
- "Security Scan"
required_pull_request_reviews:
required_approving_review_count: 1
dismiss_stale_reviews: true
enforce_admins: true
restrictions: null2. Signed-Releases (Weight: High)
# .github/workflows/release.yml
- name: Sign artifacts
uses: sigstore/gh-action-sigstore-python@cd84bbf8fc2bdfd61e0b9bb63e1a18050dd9ff99 # v2.1.1
with:
inputs: ./dist/*
- name: Generate SBOM
uses: anchore/sbom-action@d94f46e13c6c62f59525ac9a1e147a99dc0b9bf5 # v0.15.1
with:
format: cyclonedx-json3. Pinned-Dependencies (Weight: High)
# Pin ALL dependencies to specific SHA
# Bad:
uses: actions/checkout@v4
# Good:
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.14. Token-Permissions (Weight: High)
# .github/workflows/*.yml
permissions:
contents: read # Least privilege
security-events: write # Only if needed5. Vulnerabilities (Weight: High)
6. Code-Review (Weight: High)
7. Dangerous-Workflow
pull_request_target without security reviewscript injection from user-controlled data8. License
9. SAST
10. Dependency-Update-Tool
# .github/dependabot.yml
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
open-pull-requests-limit: 1011. Fuzzing (Java/Spring projects)
12. Maintained
13. Packaging
14. Security-Policy
15. Binary-Artifacts
Apply for badge at: https://bestpractices.coreinfrastructure.org/
Basics (13 criteria):
Change Control (6 criteria):
Quality (13 criteria):
Security (11 criteria):
Analysis (10 criteria):
Reference Implementation:
Achieve Supply Chain Levels for Software Artifacts Level 3:
# .github/workflows/release.yml
name: Release with SLSA3
on:
push:
tags:
- 'v*'
permissions:
contents: read
id-token: write # For SLSA attestation
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: Build
run: |
npm ci
npm run build
- name: Generate provenance
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v1.9.0
with:
subjects: "dist/*"Verification:
# Verify SLSA attestation
gh attestation verify artifact.tar.gz --owner Hack23✅ Permissive:
✅ Weak Copyleft:
✅ Documentation:
⚠️ Strong Copyleft:
⚠️ Non-standard:
❌ Never Use:
Setup:
# .github/workflows/fossa.yml
name: FOSSA Scan
on: [push, pull_request]
jobs:
fossa:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- uses: fossas/fossa-action@f61a2c7c4e3c0f1b20a199f4eafe9e8e02d5bd7d # v1.3.3
with:
api-key: ${{ secrets.FOSSA_API_KEY }}Badge:
[](https://app.fossa.com/projects/git%2Bgithub.com%2FHack23%2FREPO?ref=badge_shield)Per Secure Development Policy, generate SBOMs for all releases:
# pom.xml
<plugin>
<groupId>org.cyclonedx</groupId>
<artifactId>cyclonedx-maven-plugin</artifactId>
<version>2.7.11</version>
<executions>
<execution>
<goals>
<goal>makeAggregateBom</goal>
</goals>
</execution>
</executions>
</plugin># .github/workflows/sbom.yml
- name: Generate SPDX SBOM
run: |
npm install -g @cyclonedx/cyclonedx-npm
cyclonedx-npm --output-format spdx --output-file sbom.spdx.jsonArtifact Locations:
target/bom.jsonsbom.spdx.jsonAligned with Vulnerability Management Policy:
| Severity | Detection | Remediation Deadline | Escalation |
|---|---|---|---|
| Critical | Automated (Dependabot/CodeQL) | 24 hours | Immediate CEO notification |
| High | Automated | 7 days | Weekly status update |
| Medium | Automated | 30 days | Monthly review |
| Low | Automated | 90 days | Quarterly review |
Remediation Options:
Per Secure Development Policy:
| Document | Purpose | Mermaid Diagrams | Update Frequency |
|---|---|---|---|
| SECURITY_ARCHITECTURE.md | Current security implementation | Authentication flow, Data flow, Infrastructure | Every release |
| FUTURE_SECURITY_ARCHITECTURE.md | Planned improvements | Target architecture, Migration plan | Quarterly |
| THREAT_MODEL.md | STRIDE analysis, Attack trees | Attack trees, Data flow diagrams | Annually or with major changes |
| WORKFLOWS.md | CI/CD security gates | Pipeline diagram | When workflows change |
| SECURITY.md | Vulnerability disclosure | N/A | Annually |
Mermaid Diagram Types:
flowchart - Authentication/authorization flowssequenceDiagram - Request/response securitygraph - Architecture layerserDiagram - Data model securitySecurity Badge Status:
Documentation:
Step-by-step:
# 1. Clone template
gh repo create Hack23/new-project --template Hack23/cia --public
# 2. Enable security features
gh api repos/Hack23/new-project/vulnerability-alerts -X PUT
gh api repos/Hack23/new-project/automated-security-fixes -X PUT
# 3. Configure branch protection
gh api repos/Hack23/new-project/branches/main/protection -X PUT \
--input branch-protection.json
# 4. Add FOSSA
# Visit https://app.fossa.com/ and add repository
# 5. Register with OpenSSF Scorecard
# Visit https://scorecard.dev/ and add repository
# 6. Apply for CII Best Practices
# Visit https://bestpractices.coreinfrastructure.org/
# 7. Configure SonarCloud
# Visit https://sonarcloud.io/ and import project
# 8. Create required documentation
touch SECURITY_ARCHITECTURE.md
touch FUTURE_SECURITY_ARCHITECTURE.md
touch THREAT_MODEL.md
touch WORKFLOWS.md
touch SECURITY.md
touch CRA-ASSESSMENT.md
# 9. Add badges to README.md
# See badge examples below## Security Posture
[](https://scorecard.dev/viewer/?uri=github.com/Hack23/REPO)
[](https://bestpractices.coreinfrastructure.org/projects/XXXX)
[](https://github.com/Hack23/REPO/attestations)
[](https://sonarcloud.io/summary/new_code?id=Hack23_REPO)
[](https://app.fossa.com/projects/git%2Bgithub.com%2FHack23%2FREPO?ref=badge_shield)
## Security Documentation
[](./THREAT_MODEL.md)
[](./THREAT_MODEL.md#stride-threat-analysis)
[](./SECURITY_ARCHITECTURE.md)Core Hack23 ISMS Policies:
All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC
© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/open-source-policy of Hack23/cia.
Open the folder on GitHubat commit bbed538
Open Source Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Open Source Policy this skillHack23/cia | 239 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| Codebase Cleanup Deps Auditaiskillstore/marketplace | 430 | 7 repos | ~490 | Automated safety check: Pass | None | |
| Dependency AuditMathews-Tom/armory | 328 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Sbom SyftAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3.5k | Automated safety check: Pass | Custom licence | |
| Sca Securityhardw00t/ai-security-arsenal | 104 | — | ~3k | Automated safety check: Pass | None |
aiskillstore/marketplace
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.
Mathews-Tom/armory
Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
AgentSecOps/SecOpsAgentKit
Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.
hardw00t/ai-security-arsenal
Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to…
secondsky/claude-skills
Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.
Hack23/cia
WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms
Hack23/cia
Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
Hack23/cia
External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs
Hack23/cia
AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform
Hack23/cia
AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment
Categories
Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development. Open Source Policy is an agent skill from Hack23/cia.
Open Source Policy fits situations like: tasks that involve Supply chain security; tasks that involve Regulatory compliance; tasks that involve Vulnerability scanning.
Run `npx skills add Hack23/cia --skill open-source-policy -a claude-code`. Or copy the skill folder (.github/skills/open-source-policy in Hack23/cia) into .claude/skills/open-source-policy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Hack23/cia --skill open-source-policy -a codex`. Or copy the skill folder (.github/skills/open-source-policy in Hack23/cia) into .agents/skills/open-source-policy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill open-source-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/open-source-policy, .gemini/skills/open-source-policy, .github/skills/open-source-policy and .opencode/skills/open-source-policy in your project.
Going by SKILL.md and its folder, Open Source Policy needs the command-line tools its instructions call (gh) and credentials named FOSSA_API_KEY.
SKILL.md names 7 domains. In commands or code: github.com, bestpractices.coreinfrastructure.org, scorecard.dev, sonarcloud.io, img.shields.io, api.securityscorecards.dev and slsa.dev; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Open Source Policy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Open Source Policy: Codebase Cleanup Deps Audit (aiskillstore/marketplace, 430 stars), Dependency Audit (Mathews-Tom/armory, 328 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars) and Sbom Syft (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.
Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.