Topic · Security
Best supply chain security skills, page 2
Supply chain security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 286 | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 50 | Market intelligence: strategy screener, popularity rankings, top movers with news correlation, quote anomalies, index/ETF constituent stocks, morning briefings, catalyst monitoring for watchlist… | helsome/ | 269 | 1 repo | ~1.7k | Automated safety check: Pass | MIT | 4 days ago |
| 51 | 51.Bom Slimmer Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and… | cdxgen/ | 1.1k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 52 | Probes an AI agent for supply-chain weaknesses: whether it loads untrusted plugins, tools or models, updates dependencies without pinning, or trusts user-supplied artifacts. | Tencent/ | 6.8k | — | ~760 | Automated safety check: Pass | Apache-2.0 | today |
| 53 | Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | today |
| 54 | Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. | mistralai/ | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | today |
| 55 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 56 | Run a security vulnerability assessment based on KISA guidelines. | cdppcorp/ | 361 | — | ~2.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 57 | Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 58 | 58.Snapshot Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions. | boostsecurityio/ | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 59 | 59.Supply Chain Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops. | padamson/ | 153 | — | ~722 | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 60 | 60.Dependencies Run git-pkgs list and sbom against the repository and emit one envelope with per-section status. | alpha-omega-security/ | 231 | — | ~596 | Automated safety check: Pass | MIT | today |
| 61 | Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment… | valory-xyz/ | 129 | — | ~11k | Automated safety check: Notes | Apache-2.0 | 23 days ago |
| 62 | Check the live status of the Strait of Hormuz from the Hormuz Strait Monitor dashboard: open, restricted, or closed status, tanker transits vs normal, stranded vessels, Brent price impact, war-risk… | himself65/ | 3.4k | — | ~1.5k | Automated safety check: Pass | MIT | 3 days ago |
| 63 | Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk. | seb1n/ | 206 | — | ~2.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 64 | Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository. | boostsecurityio/ | 523 | — | ~173 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 65 | 65.Cso Chief Security Officer mode. An agent skill from no-session/pstack. | no-session/ | 134 | — | ~12k | Automated safety check: Notes | MIT | 6 mo ago |
| 66 | Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop. | cobusgreyling/ | 11k | — | ~300 | Automated safety check: Pass | MIT | today |
| 67 | 67.Soak Manages the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools. | nubjs/ | 4.4k | — | ~1.3k | Automated safety check: Warn | MIT | today |
| 68 | Supply-chain security controls for the @cipherstash/stack monorepo. | cipherstash/ | 157 | — | ~5.2k | Automated safety check: Warn | MIT | today |
| 69 | Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments. | irahardianto/ | 157 | — | ~2.7k | Automated safety check: Notes | MIT | 3 days ago |
| 70 | Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or… | cdxgen/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 71 | Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run. | dralgorhythm/ | 125 | — | ~1.5k | Automated safety check: Pass | No licence | 2 mo ago |
| 72 | 安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex. | ReJeCtAll/ | 113 | — | ~780 | Automated safety check: Pass | MIT | 3 mo ago |
| 73 | Operate Syft, Grype, Trivy, Gitleaks, Retire.js, package-manager metadata, and build evidence for advanced software-supply-chain assessment. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 74 | Open source license compliance check for a dependency list, a single library, or outbound code. | anthropics/ | 9.6k | 3 repos | ~5k | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 75 | Respond to blocked package installs and manage the Interlinked supply-chain allowlist. | QuentinCody/ | 178 | — | ~2.8k | Automated safety check: Pass | MIT | 5 days ago |
| 76 | Working on RedAmon's supply-chain scanner (offline OSV + GuardDog + retire + trufflehog): the offline OSV database that the scan path does not bootstrap, the world-readable requirement for the… | samugit83/ | 3k | — | ~855 | Automated safety check: Pass | MIT | today |
| 77 | Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses. | jamditis/ | 416 | 1 repo | ~2k | Automated safety check: Warn | MIT | 3 days ago |
| 78 | Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | today |
| 79 | 79.Nis2 EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. | Sushegaad/ | 942 | 1 repo | ~4.4k | Automated safety check: Pass | MIT | 3 days ago |
| 80 | 80.Nzism Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. | Sushegaad/ | 942 | 1 repo | ~3.8k | Automated safety check: Pass | MIT | 3 days ago |
| 81 | 81.PR Audit Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation… | akitaonrails/ | 212 | — | ~4.8k | Automated safety check: Pass | No licence | 14 days ago |
| 82 | Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and… | hardw00t/ | 104 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 83 | Verify supply chain integrity for AI agent plugins, tools, and dependencies. | github/ | 40k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | today |
| 84 | Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration. | github/ | 5.4k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 85 | MASTER MALWARE ANALYSIS: Threat Intelligence, Phishing Detection. | Dokhacgiakhoa/ | 507 | — | ~419 | Automated safety check: Notes | Unknown | 3 mo ago |
| 86 | 86.Corpus Sweep Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run). | nubjs/ | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | today |
| 87 | 87.Sca Trivy Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license… | AgentSecOps/ | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 88 | Assess game build, launcher, update, distribution, mod, plugin, dependency, signing, provenance, and recovery trust. | gmh5225/ | 3.6k | — | ~227 | Automated safety check: Pass | MIT | today |
| 89 | Secure the AI model supply chain with artifact signing, provenance attestation, SBOM workflows, dependency controls, and trusted model promotion. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | today |
| 90 | Generate the Agent Supply Chain newsletter by researching team activity on GitHub and Confluence, then creating a Confluence draft and Gmail draft | DataDog/ | 3.8k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 91 | 91.Sbom Syft Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives. | AgentSecOps/ | 220 | 1 repo | ~3.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 92 | 92.Cmmc Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). | Sushegaad/ | 942 | 1 repo | ~5.5k | Automated safety check: Pass | MIT | 3 days ago |
| 93 | 93.Bumblebee Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs. | sickn33/ | 47k | 1 repo | ~2.5k | Automated safety check: Notes | MIT | today |
| 94 | Runs a hypothesis-driven threat hunt for supply-chain compromise (T1195) by querying SIEM/EDR logs for trojanized software updates, compromised dependencies, unauthorized code modifications, and… | mukul975/ | 34k | — | ~899 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 95 | Implements code signing for build artifacts (binaries, packages, containers) using GPG, Sigstore, and platform-specific signing tools, establishing trust chains and verifying signatures in… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 96 | Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38