Topic · Security

Best supply chain security skills, page 3

Skills #97–144 of 233, ranked by score.

Supply chain security skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Supply chain security skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
97

Signs and verifies container image provenance with Sigstore Cosign, covering key-based and keyless OIDC signing (Fulcio, Rekor transparency log), SLSA attestations, and enforcing signature…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: NotesApache-2.01 mo ago
98

Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
99

Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
100

Audit the combined default-branch state after one or more PR merges or before deployment/release.

akitaonrails/my-skills212—~3.4kAutomated safety check: PassNo licence15 days ago
101

Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies.

rileyhilliard/claude-essentials130—~1.5kAutomated safety check: PassMIT1 mo ago
102

Produces a dynamic CycloneDX BOM by executing a command under the cdxgen safer-exec sandbox with tracebom, tracing dlopen shared-library loads, eBPF HTTP URL access, cryptographic library and…

cdxgen/cdxgen1.1k—~2kAutomated safety check: PassApache-2.0today
103

Runs the cdxgen SBOM fidelity loop: scan with --introspect or --profile introspect, read the cdxgen fidelity report, execute its ranked remediations (the catalog spans the mainstream build…

cdxgen/cdxgen1.1k—~4.5kAutomated safety check: PassApache-2.0today
104

Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering…

cdxgen/cdxgen1.1k—~2.5kAutomated safety check: PassApache-2.0today
105

Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to…

microsoft/apm4k—~339Automated safety check: PassMITyesterday
106

A skill your agent uses when evaluating US stocks through Serenity / @aleabitoreddit's AI and semiconductor supply-chain lens: upstream chokepoints, photonics/CPO bottlenecks, hyperscaler capex…

questflowai/investorskills1.9k—~935Automated safety check: PassMIT1 mo ago
107

Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…

cloudposse/atmos1.4k—~3.8kAutomated safety check: PassApache-2.0today
108

Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

sickn33/agentic-awesome-skills47k1 repo~1kAutomated safety check: NotesMITyesterday
109

Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT.

mukul975/Anthropic-Cybersecurity-Skills34k—~745Automated safety check: PassApache-2.01 mo ago
110

Generate domain permutations with dnstwist and check DNS resolution to detect typosquatting, homograph phishing, and brand impersonation domains registered against your organization.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.01 mo ago
111

Identify poisoned training data and backdoored ML models across the pipeline using IBM's Adversarial Robustness Toolbox (activation clustering, spectral signatures, trigger reconstruction), Cleanlab…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
112

Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets…

mukul975/Anthropic-Cybersecurity-Skills34k—~655Automated safety check: PassApache-2.01 mo ago
113

Implements NERC CIP controls for Bulk Electric System (BES) cyber systems: asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007)…

mukul975/Anthropic-Cybersecurity-Skills34k—~4.3kAutomated safety check: PassApache-2.01 mo ago
114

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.01 mo ago
115

Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

briiirussell/cybersecurity-skills413—~3.2kAutomated safety check: WarnMIT4 mo ago
116

Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls.

wshobson/agents40k—~2.5kAutomated safety check: PassMIT3 days ago
117

Constructs secure, efficient CI/CD pipelines with supply chain security (SLSA), monorepo optimization, caching strategies, and parallelization patterns for GitHub Actions, GitLab CI, and Argo…

ancoleman/ai-design-components526—~2.7kAutomated safety check: PassMIT10 mo ago
118

Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.

ancoleman/ai-design-components526—~3.8kAutomated safety check: PassMIT10 mo ago
119

Authors a Dynamics 365 Finance and Supply Chain Management Solution Blueprint from scratch through a structured, section-by-section architect interview, establishing scope, target operating model…

github/awesome-copilot40k—~2.7kAutomated safety check: PassMITtoday
120

Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.

inkline/inkline1.5k—~1.1kAutomated safety check: PassNo licence27 days ago
121

Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

trilwu/secskills156—~2.9kAutomated safety check: PassMIT1 mo ago
122

Harden AI/LLM deployments against prompt injection, data exfiltration, model theft, and supply chain attacks.

sickn33/agentic-awesome-skills47k1 repo~2.7kAutomated safety check: PassMITyesterday
123

Reach for this skill whenever Claude encounters situations involving supply chain innovation, B2B customer respect, community revitalization, vocational education, or navigating massive business…

K-Dense-AI/mimeographs129—~1.6kAutomated safety check: PassMIT1 mo ago
124

Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

davila7/claude-code-templates32k—~1.7kAutomated safety check: NotesMITtoday
125
125.Ism

Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains.

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance942—~3.6kAutomated safety check: PassMIT3 days ago
126
126.Sbom

Generate a CycloneDX SBOM for the repository via git-pkgs sbom.

alpha-omega-security/scrutineer231—~290Automated safety check: PassMITtoday
127

当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。

zhaji2333/CkSKILLS113—~688Automated safety check: WarnMIT23 days ago
128

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
129

Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
130

Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.01 mo ago
131

Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

mukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.01 mo ago
132

Simulates and detects software supply chain attacks: typosquatting detection via Levenshtein distance against popular PyPI package names, dependency confusion testing against private registries…

mukul975/Anthropic-Cybersecurity-Skills34k—~716Automated safety check: PassApache-2.01 mo ago
133

Verifies artifact signatures and SLSA provenance using Sigstore's cosign (verify, verify-attestation, verify-blob-attestation) and slsa-verifier (verify-artifact), enforcing keyless OIDC builder…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
134

Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs.

different-ai/openwork24k—~939Automated safety check: WarnUnknowntoday
135

Usar para generar Software Bill of Materials para cumplimiento del CRA.

686f6c61/alfred-dev117—~780Automated safety check: PassMIT1 mo ago
136

Analyze how stocks move together using Yahoo Finance price history (yfinance): find correlated peers for a ticker, measure correlation, beta, and spread between specific tickers, cluster a group…

himself65/finance-skills3.4k—~3.3kAutomated safety check: PassMIT3 days ago
137

Atmos SBOM provenance: CycloneDX and SPDX generation from vendor and Terraform evidence, coverage diagnostics, NTIA validation, and native CI workflow-artifact publication

cloudposse/atmos1.4k—~1.4kAutomated safety check: PassApache-2.0today
138

Apply Karpathy-style minimalism and anti-dependency principles to code and system design.

LearnPrompt/andrej-karpathy-skills109—~1.6kAutomated safety check: PassMIT3 mo ago
139

Inventories project dependencies and runtimes across ecosystems and reports known CVEs, supply-chain risks and a prioritized upgrade plan.

criptogus/agent-evolve-network288—~974Automated safety check: PassCC-BY-SA-4.028 days ago
140

Weekly supply-chain hygiene scan (Perplexity Bumblebee). An agent skill from Szotasz/marveen.

Szotasz/marveen115—~2.1kAutomated safety check: PassMITtoday
141

云原生与软件供应链安全防御。容器/K8s 加固、Service Mesh、CI/CD 安全、SLSA/SBOM/Sigstore、云 IAM、Secrets 管理、IaC 安全。Use when hardening Kubernetes clusters, auditing CI/CD pipelines, implementing supply chain security…

telagod/code-abyss243—~778Automated safety check: PassMIT2 mo ago
142

A skill your agent uses when scanning code or configuration for security vulnerabilities.

WrongStack/WrongStack370—~2.1kAutomated safety check: PassMITtoday
143

Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat.

epam/ai-dial-chat504—~1.9kAutomated safety check: PassApache-2.0today
144

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.

aiskillstore/marketplace4307 repos~490Automated safety check: PassNo licenceyesterday