Agent skill

Implementing Devsecops Security Scanning

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

Apache-2.0Auto-check passedSecurity

Install Implementing Devsecops Security Scanning

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-devsecops-security-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-devsecops-security-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-devsecops-security-scanning .claude/skills/implementing-devsecops-security-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-devsecops-security-scanning
GitHub stars
34k
Token cost
~3.1k tokens
SKILL.md length
590 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

  • Works in 7 steps: Add Secrets Detection with Gitleaks → Add SAST Scanning with Semgrep → Add SCA Scanning with Trivy → …
  • Setting up automated security scanning in CI/CD
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 1 more section
  • Runs Python scripts from its folder; calls pip; reaches github.com; needs GITHUB_TOKEN

What it does

Implementing Devsecops Security Scanning is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Use when setting up automated security scanning in CI/CD, shifting security left, meeting compliance mandates (SOC 2, PCI-DSS, ISO 27001), or gating deployments on critical vulnerabilities.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Static analysis and SAST, SOC 2 and security compliance and Secrets management. It works with Semgrep and Trivy. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Setting up automated security scanning in CI/CD
  • Shifting security left
  • Meeting compliance mandates (SOC 2
  • Gating deployments on critical vulnerabilities

Example prompts

  • “Use the implementing-devsecops-security-scanning skill to integrate SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA…”
  • “/implementing-devsecops-security-scanning”

Requirements

  • Python 3
  • Docker
  • A credential in GITHUB_TOKEN

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Add Secrets Detection with Gitleaks
  2. Add SAST Scanning with Semgrep
  3. Add SCA Scanning with Trivy
  4. Add DAST Scanning with OWASP ZAP
  5. Aggregate Results and Enforce Security Gates
  6. Configure Branch Protection Rules
  7. Set Up Developer Feedback Loop

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Devsecops Security Scanning loads about 3.1k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 590 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 590 words, ~3,067 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-devsecops-security-scanning/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-devsecops-security-scanning
description
Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Use when setting up automated security scanning in CI/CD, shifting security left, meeting compliance mandates (SOC 2, PCI-DSS, ISO 27001), or gating deployments on critical vulnerabilities.
domain
cybersecurity
subdomain
application-security
tags
devsecops, SAST, DAST, SCA, semgrep, trivy, owasp-zap, gitleaks, CI-CD, shift-left
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, PR.PS-04, ID.RA-01, PR.DS-10
mitre_attack
T1078, T1190, T1059, T1610, T1611

Implementing DevSecOps Security Scanning

When to Use

  • Setting up automated security scanning in a new or existing CI/CD pipeline
  • Shifting security left by catching vulnerabilities before code reaches production
  • Meeting compliance requirements (SOC 2, PCI-DSS, ISO 27001) that mandate automated security testing
  • Integrating SAST, DAST, and SCA together to achieve comprehensive application security coverage
  • Establishing security gates that block deployments containing critical or high-severity vulnerabilities

Do not use as a replacement for manual penetration testing. Automated scanning catches common vulnerability patterns but cannot replace human-driven security assessments for business logic flaws and complex attack chains.

Prerequisites

  • CI/CD platform: GitHub Actions, GitLab CI, Jenkins, or Azure DevOps
  • Container runtime (Docker) for running scanning tools
  • A staging environment URL for DAST scanning (DAST cannot test static code)
  • Repository access with permissions to modify CI/CD workflow files
  • Tool-specific requirements:
    • Semgrep: free for open-source rulesets (p/security-audit, p/owasp-top-ten)
    • Trivy: free, no account required
    • OWASP ZAP: free, Docker image available
    • Gitleaks: free, no account required

Workflow

Step 1: Add Secrets Detection with Gitleaks

Secrets detection runs first because leaked credentials are the highest-priority finding. Add to .github/workflows/security.yml:

yaml
name: DevSecOps Security Pipeline
on:
  push:
    branches: [main, develop]
  pull_request:
    branches: [main]

jobs:
  secrets-scan:
    name: Secrets Detection (Gitleaks)
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0  # Full history for scanning all commits

      - name: Run Gitleaks
        uses: gitleaks/gitleaks-action@v2
        env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

Configure .gitleaks.toml in the repository root for custom rules and allowlists:

toml
[extend]
useDefault = true

[allowlist]
description = "Global allowlist"
paths = [
  '''\.gitleaks\.toml''',
  '''test/fixtures/.*''',
  '''docs/examples/.*'''
]

[[rules]]
id = "custom-internal-api-key"
description = "Internal API key pattern"
regex = '''INTERNAL_KEY_[A-Za-z0-9]{32}'''
tags = ["internal", "api-key"]
Step 2: Add SAST Scanning with Semgrep

Semgrep performs static code analysis to find security vulnerabilities, bugs, and code patterns:

yaml
  sast-scan:
    name: SAST (Semgrep)
    runs-on: ubuntu-latest
    container:
      image: semgrep/semgrep
    steps:
      - uses: actions/checkout@v4

      - name: Run Semgrep SAST scan
        run: |
          semgrep scan \
            --config p/security-audit \
            --config p/owasp-top-ten \
            --config p/secrets \
            --severity ERROR \
            --error \
            --json \
            --output semgrep-results.json \
            .

      - name: Upload SAST results
        if: always()
        uses: actions/upload-artifact@v4
        with:
          name: semgrep-results
          path: semgrep-results.json

For custom rules, create .semgrep/custom-rules.yml:

yaml
rules:
  - id: no-exec-user-input
    patterns:
      - pattern: exec($INPUT)
      - pattern-not: exec("...")
    message: >
      User input passed to exec(). This is a command injection vulnerability.
    severity: ERROR
    languages: [python]
    metadata:
      cwe: "CWE-78: OS Command Injection"
      owasp: "A03:2021 - Injection"

  - id: no-raw-sql-queries
    patterns:
      - pattern: cursor.execute(f"...")
      - pattern: cursor.execute("..." + ...)
    message: >
      SQL query built with string concatenation or f-strings. Use parameterized queries.
    severity: ERROR
    languages: [python]
    metadata:
      cwe: "CWE-89: SQL Injection"
      owasp: "A03:2021 - Injection"
Step 3: Add SCA Scanning with Trivy

Trivy scans dependencies, container images, IaC files, and generates SBOM:

yaml
  sca-scan:
    name: SCA & Container Scan (Trivy)
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Run Trivy filesystem scan (dependencies)
        uses: aquasecurity/trivy-action@0.28.0
        with:
          scan-type: 'fs'
          scan-ref: '.'
          severity: 'CRITICAL,HIGH'
          exit-code: '1'
          format: 'json'
          output: 'trivy-fs-results.json'

      - name: Run Trivy IaC scan (Terraform, CloudFormation)
        uses: aquasecurity/trivy-action@0.28.0
        with:
          scan-type: 'config'
          scan-ref: '.'
          severity: 'CRITICAL,HIGH'
          exit-code: '1'
          format: 'json'
          output: 'trivy-iac-results.json'

      - name: Upload SCA results
        if: always()
        uses: actions/upload-artifact@v4
        with:
          name: trivy-results
          path: trivy-*.json

  container-scan:
    name: Container Image Scan (Trivy)
    runs-on: ubuntu-latest
    needs: [sast-scan]  # Build image only after SAST passes
    steps:
      - uses: actions/checkout@v4

      - name: Build Docker image
        run: docker build -t app:${{ github.sha }} .

      - name: Scan container image
        uses: aquasecurity/trivy-action@0.28.0
        with:
          image-ref: 'app:${{ github.sha }}'
          severity: 'CRITICAL,HIGH'
          exit-code: '1'
          format: 'json'
          output: 'trivy-image-results.json'

      - name: Generate SBOM
        uses: aquasecurity/trivy-action@0.28.0
        with:
          image-ref: 'app:${{ github.sha }}'
          format: 'cyclonedx'
          output: 'sbom.json'

      - name: Upload SBOM
        uses: actions/upload-artifact@v4
        with:
          name: sbom
          path: sbom.json
Step 4: Add DAST Scanning with OWASP ZAP

DAST runs against a deployed staging environment. It is slower than SAST/SCA and should run asynchronously or on a schedule:

yaml
  dast-scan:
    name: DAST (OWASP ZAP)
    runs-on: ubuntu-latest
    needs: [deploy-staging]  # Must run after app is deployed to staging
    steps:
      - uses: actions/checkout@v4

      - name: Run ZAP Baseline Scan (fast, suitable for CI)
        uses: zaproxy/action-baseline@v0.14.0
        with:
          target: ${{ vars.STAGING_URL }}
          rules_file_name: '.zap/rules.tsv'
          cmd_options: '-a -j'

      # For nightly full scans, use action-full-scan instead:
      # - name: Run ZAP Full Scan (comprehensive, 30-60 min)
      #   uses: zaproxy/action-full-scan@v0.12.0
      #   with:
      #     target: ${{ vars.STAGING_URL }}

Create .zap/rules.tsv to configure alert thresholds:

tsv
10010	IGNORE	(Cookie No HttpOnly Flag - acceptable for non-sensitive cookies)
10011	IGNORE	(Cookie Without Secure Flag - staging uses HTTP)
90033	WARN	(Loosely Scoped Cookie)
10038	FAIL	(Content Security Policy Header Not Set)
40012	FAIL	(Cross Site Scripting - Reflected)
40014	FAIL	(Cross Site Scripting - Persistent)
40018	FAIL	(SQL Injection)
90019	FAIL	(Server Side Code Injection)
90020	FAIL	(Remote OS Command Injection)
Step 5: Aggregate Results and Enforce Security Gates

Create a summary job that aggregates all scan results and enforces pass/fail gates:

yaml
  security-gate:
    name: Security Gate
    runs-on: ubuntu-latest
    needs: [secrets-scan, sast-scan, sca-scan, container-scan]
    if: always()
    steps:
      - name: Check scan results
        run: |
          echo "Checking security scan results..."

          # Fail the pipeline if any upstream job failed
          if [[ "${{ needs.secrets-scan.result }}" == "failure" ]]; then
            echo "BLOCKED: Secrets detected in repository"
            exit 1
          fi

          if [[ "${{ needs.sast-scan.result }}" == "failure" ]]; then
            echo "BLOCKED: SAST found critical/high vulnerabilities"
            exit 1
          fi

          if [[ "${{ needs.sca-scan.result }}" == "failure" ]]; then
            echo "BLOCKED: SCA found critical/high vulnerable dependencies"
            exit 1
          fi

          if [[ "${{ needs.container-scan.result }}" == "failure" ]]; then
            echo "BLOCKED: Container image has critical/high vulnerabilities"
            exit 1
          fi

          echo "All security gates passed"
Step 6: Configure Branch Protection Rules

Enforce the security pipeline as a required status check:

GitHub Repository > Settings > Branches > Branch Protection Rules

Branch name pattern: main
  Require status checks to pass before merging: Enabled
    Required status checks:
      - Secrets Detection (Gitleaks)
      - SAST (Semgrep)
      - SCA & Container Scan (Trivy)
      - Security Gate
  Require branches to be up to date before merging: Enabled
Step 7: Set Up Developer Feedback Loop

Configure pre-commit hooks so developers catch issues before pushing:

yaml
# .pre-commit-config.yaml
repos:
  - repo: https://github.com/gitleaks/gitleaks
    rev: v8.22.1
    hooks:
      - id: gitleaks

  - repo: https://github.com/semgrep/semgrep
    rev: v1.102.0
    hooks:
      - id: semgrep
        args: ['--config', 'p/security-audit', '--config', 'p/owasp-top-ten', '--error']

Install and activate pre-commit:

bash
pip install pre-commit
pre-commit install
pre-commit run --all-files  # Test against existing codebase
Show full SKILL.md (266 more words)Show less

Key Concepts

TermDefinition
SAST (Static Application Security Testing)Analyzes source code without executing it to find security vulnerabilities; runs fast, catches issues early, but cannot find runtime flaws
DAST (Dynamic Application Security Testing)Tests a running application by sending requests and analyzing responses; finds runtime issues but requires a deployed environment
SCA (Software Composition Analysis)Scans project dependencies against vulnerability databases (NVD, GitHub Advisory) to find known-vulnerable libraries
SBOM (Software Bill of Materials)Machine-readable inventory of all components and dependencies in an application, used for vulnerability tracking and compliance
Shift LeftSecurity practice of moving security testing earlier in the SDLC, from post-deployment to pre-commit and CI stages
Security GateA CI/CD pipeline checkpoint that blocks deployment if security scan results exceed defined severity thresholds
Pre-commit HookLocal Git hook that runs security checks before code is committed, providing the fastest developer feedback loop

Verification

  • Gitleaks blocks commits and PRs containing hardcoded secrets (test with a dummy API key)
  • Semgrep scan runs on every PR and reports findings as annotations or comments
  • Trivy filesystem scan detects a known-vulnerable dependency (test by adding a vulnerable package)
  • Trivy container scan runs successfully against the built Docker image
  • SBOM is generated and stored as a build artifact in CycloneDX or SPDX format
  • OWASP ZAP baseline scan runs against the staging URL without crashing
  • Security gate job blocks merges to main when any scan finds critical/high severity issues
  • Branch protection rules enforce required status checks before merge
  • Pre-commit hooks catch secrets and SAST findings locally before push
  • Developer documentation explains how to interpret scan results and fix common findings

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-devsecops-security-scanning of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Devsecops Security Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Devsecops Security Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Devsecops Security Scanning this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Security Scanericrisco/rsc-harness167—~2.8kAutomated safety check: NotesMIT
Detection Breadthdeonmenezes/mantishack505—~510Automated safety check: PassApache-2.0
Security ReviewerJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Sast BanditAgentSecOps/SecOpsAgentKit2201 repos~2.6kAutomated safety check: PassCustom licence
Golang Securityunxed/f42412 repos~3.6kAutomated safety check: PassMIT

Similar skills

  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    167 GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check: notes
  • Detection Breadth

    deonmenezes/mantishack

    When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

    505 GitHub stars~510 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Sast Bandit

    AgentSecOps/SecOpsAgentKit

    Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

    220 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    241 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed
  • DefectDojo Vulnerability Management

    AgentSecOps/SecOpsAgentKit

    Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

    220 GitHub stars~2.3k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Implementing Devsecops Security Scanning

What does Implementing Devsecops Security Scanning do?

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Implementing Devsecops Security Scanning is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

When should I use Implementing Devsecops Security Scanning?

Implementing Devsecops Security Scanning fits situations like: setting up automated security scanning in CI/CD; shifting security left; meeting compliance mandates (SOC 2; gating deployments on critical vulnerabilities.

How do I install Implementing Devsecops Security Scanning in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-devsecops-security-scanning -a claude-code`. Or copy the skill folder (skills/implementing-devsecops-security-scanning in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-devsecops-security-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Devsecops Security Scanning in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-devsecops-security-scanning -a codex`. Or copy the skill folder (skills/implementing-devsecops-security-scanning in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-devsecops-security-scanning in your project. Codex loads it when a task matches its description.

Can I use Implementing Devsecops Security Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-devsecops-security-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-devsecops-security-scanning, .gemini/skills/implementing-devsecops-security-scanning, .github/skills/implementing-devsecops-security-scanning and .opencode/skills/implementing-devsecops-security-scanning in your project.

What does Implementing Devsecops Security Scanning need to run?

Going by SKILL.md and its folder, Implementing Devsecops Security Scanning needs Python for the scripts in its folder, the command-line tools its instructions call (pip) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; Docker; A credential in GITHUB_TOKEN.

Does Implementing Devsecops Security Scanning access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Implementing Devsecops Security Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Devsecops Security Scanning use?

Implementing Devsecops Security Scanning is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Devsecops Security Scanning use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 510 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Devsecops Security Scanning?

Skills that share tags, products or a category with Implementing Devsecops Security Scanning: Security Scan (ericrisco/rsc-harness, 167 stars), Detection Breadth (deonmenezes/mantishack, 505 stars), Security Reviewer (Jeffallan/claude-skills, 12k stars) and Sast Bandit (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Devsecops Security Scanning?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.