Topic · Security

Best supply chain security skills, page 2

Skills #49–96 of 233, ranked by score.

Supply chain security skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Supply chain security skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

majiayu000/spellbook286—~1.5kAutomated safety check: PassMITtoday
50

Market intelligence: strategy screener, popularity rankings, top movers with news correlation, quote anomalies, index/ETF constituent stocks, morning briefings, catalyst monitoring for watchlist…

helsome/folio2691 repo~1.7kAutomated safety check: PassMIT4 days ago
51

Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and…

cdxgen/cdxgen1.1k—~1.6kAutomated safety check: PassApache-2.0today
52

Probes an AI agent for supply-chain weaknesses: whether it loads untrusted plugins, tools or models, updates dependencies without pinning, or trusts user-supplied artifacts.

Tencent/AI-Infra-Guard6.8k—~760Automated safety check: PassApache-2.0today
53

Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

iflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0today
54

Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

mistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.0today
55

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…

trailofbits/skills7.4k—~1.7kAutomated safety check: NotesCC-BY-SA-4.0today
56

Run a security vulnerability assessment based on KISA guidelines.

cdppcorp/KESE-KIT361—~2.3kAutomated safety check: PassMIT6 mo ago
57

Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…

cdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0today
58

Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

boostsecurityio/poutine523—~214Automated safety check: PassApache-2.0yesterday
59

Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops.

padamson/playwright-rust153—~722Automated safety check: PassApache-2.03 days ago
60

Run git-pkgs list and sbom against the repository and emit one envelope with per-section status.

alpha-omega-security/scrutineer231—~596Automated safety check: PassMITtoday
61

Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

valory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.023 days ago
62

Check the live status of the Strait of Hormuz from the Hormuz Strait Monitor dashboard: open, restricted, or closed status, tanker transits vs normal, stranded vessels, Brent price impact, war-risk…

himself65/finance-skills3.4k—~1.5kAutomated safety check: PassMIT3 days ago
63

Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.

seb1n/awesome-ai-agent-skills206—~2.4kAutomated safety check: PassMIT1 mo ago
64

Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.

boostsecurityio/poutine523—~173Automated safety check: PassApache-2.0yesterday
65
65.Cso

Chief Security Officer mode. An agent skill from no-session/pstack.

no-session/pstack134—~12kAutomated safety check: NotesMIT6 mo ago
66

Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop.

cobusgreyling/loop-engineering11k—~300Automated safety check: PassMITtoday
67
67.Soak

Manages the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools.

nubjs/nub4.4k—~1.3kAutomated safety check: WarnMITtoday
68

Supply-chain security controls for the @cipherstash/stack monorepo.

cipherstash/stack157—~5.2kAutomated safety check: WarnMITtoday
69

Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

irahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT3 days ago
70

Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or…

cdxgen/cdxgen1.1k—~1.9kAutomated safety check: PassApache-2.0today
71

Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

dralgorhythm/claude-agentic-framework125—~1.5kAutomated safety check: PassNo licence2 mo ago
72

安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

ReJeCtAll/ExpertTeam-Codex113—~780Automated safety check: PassMIT3 mo ago
73

Operate Syft, Grype, Trivy, Gitleaks, Retire.js, package-manager metadata, and build evidence for advanced software-supply-chain assessment.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
74
74.Oss ReviewOfficial

Open source license compliance check for a dependency list, a single library, or outbound code.

anthropics/claude-for-legal9.6k3 repos~5kAutomated safety check: PassApache-2.08 days ago
75

Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

QuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT5 days ago
76

Working on RedAmon's supply-chain scanner (offline OSV + GuardDog + retire + trufflehog): the offline OSV database that the scan path does not bootstrap, the world-readable requirement for the…

samugit83/redamon3k—~855Automated safety check: PassMITtoday
77

Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses.

jamditis/claude-skills-journalism4161 repo~2kAutomated safety check: WarnMIT3 days ago
78

Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain.

sickn33/agentic-awesome-skills47k2 repos~3.4kAutomated safety check: PassMITtoday
79
79.Nis2

EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art.

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~4.4kAutomated safety check: PassMIT3 days ago
80

Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains.

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~3.8kAutomated safety check: PassMIT3 days ago
81

Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation…

akitaonrails/my-skills212—~4.8kAutomated safety check: PassNo licence14 days ago
82

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

hardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNo licence5 mo ago
83

Verify supply chain integrity for AI agent plugins, tools, and dependencies.

github/awesome-copilot40k1 repo~2.7kAutomated safety check: PassMITtoday
84

Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration.

github/gh-aw5.4k—~2.8kAutomated safety check: PassMITtoday
85

MASTER MALWARE ANALYSIS: Threat Intelligence, Phishing Detection.

Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI507—~419Automated safety check: NotesUnknown3 mo ago
86

Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).

nubjs/nub4.4k—~2.4kAutomated safety check: PassMITtoday
87

Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

AgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassUnknown5 mo ago
88

Assess game build, launcher, update, distribution, mod, plugin, dependency, signing, provenance, and recovery trust.

gmh5225/awesome-game-security3.6k—~227Automated safety check: PassMITtoday
89

Secure the AI model supply chain with artifact signing, provenance attestation, SBOM workflows, dependency controls, and trusted model promotion.

sickn33/agentic-awesome-skills47k2 repos~3.4kAutomated safety check: PassMITtoday
90

Generate the Agent Supply Chain newsletter by researching team activity on GitHub and Confluence, then creating a Confluence draft and Gmail draft

DataDog/datadog-agent3.8k—~1.2kAutomated safety check: PassApache-2.0today
91

Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.

AgentSecOps/SecOpsAgentKit2201 repo~3.5kAutomated safety check: PassUnknown5 mo ago
92
92.Cmmc

Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB).

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~5.5kAutomated safety check: PassMIT3 days ago
93

Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

sickn33/agentic-awesome-skills47k1 repo~2.5kAutomated safety check: NotesMITtoday
94

Runs a hypothesis-driven threat hunt for supply-chain compromise (T1195) by querying SIEM/EDR logs for trojanized software updates, compromised dependencies, unauthorized code modifications, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~899Automated safety check: PassApache-2.01 mo ago
95

Implements code signing for build artifacts (binaries, packages, containers) using GPG, Sigstore, and platform-specific signing tools, establishing trust chains and verifying signatures in…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
96

Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted…

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago