Topic · Security
Best supply chain security skills, page 3
Supply chain security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Signs and verifies container image provenance with Sigstore Cosign, covering key-based and keyless OIDC signing (Fulcio, Rekor transparency log), SLSA attestations, and enforcing signature… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 98 | Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 99 | Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 100 | 100.PR Post Audit Audit the combined default-branch state after one or more PR merges or before deployment/release. | akitaonrails/ | 212 | — | ~3.4k | Automated safety check: Pass | No licence | 15 days ago |
| 101 | Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies. | rileyhilliard/ | 130 | — | ~1.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 102 | Produces a dynamic CycloneDX BOM by executing a command under the cdxgen safer-exec sandbox with tracebom, tracing dlopen shared-library loads, eBPF HTTP URL access, cryptographic library and… | cdxgen/ | 1.1k | — | ~2k | Automated safety check: Pass | Apache-2.0 | today |
| 103 | Runs the cdxgen SBOM fidelity loop: scan with --introspect or --profile introspect, read the cdxgen fidelity report, execute its ranked remediations (the catalog spans the mainstream build… | cdxgen/ | 1.1k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | today |
| 104 | 104.Sbom Generate Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering… | cdxgen/ | 1.1k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 105 | Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to… | microsoft/ | 4k | — | ~339 | Automated safety check: Pass | MIT | yesterday |
| 106 | 106.Serenity A skill your agent uses when evaluating US stocks through Serenity / @aleabitoreddit's AI and semiconductor supply-chain lens: upstream chokepoints, photonics/CPO bottlenecks, hyperscaler capex… | questflowai/ | 1.9k | — | ~935 | Automated safety check: Pass | MIT | 1 mo ago |
| 107 | 107.Atmos CI Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs… | cloudposse/ | 1.4k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | today |
| 108 | Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. | sickn33/ | 47k | 1 repo | ~1k | Automated safety check: Notes | MIT | yesterday |
| 109 | Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. | mukul975/ | 34k | — | ~745 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 110 | Generate domain permutations with dnstwist and check DNS resolution to detect typosquatting, homograph phishing, and brand impersonation domains registered against your organization. | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 111 | Identify poisoned training data and backdoored ML models across the pipeline using IBM's Adversarial Robustness Toolbox (activation clustering, spectral signatures, trigger reconstruction), Cleanlab… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 112 | Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets… | mukul975/ | 34k | — | ~655 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 113 | Implements NERC CIP controls for Bulk Electric System (BES) cyber systems: asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007)… | mukul975/ | 34k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 114 | Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 115 | 115.Dependency Audit Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. | briiirussell/ | 413 | — | ~3.2k | Automated safety check: Warn | MIT | 4 mo ago |
| 116 | Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. | wshobson/ | 40k | — | ~2.5k | Automated safety check: Pass | MIT | 3 days ago |
| 117 | Constructs secure, efficient CI/CD pipelines with supply chain security (SLSA), monorepo optimization, caching strategies, and parallelization patterns for GitHub Actions, GitLab CI, and Argo… | ancoleman/ | 526 | — | ~2.7k | Automated safety check: Pass | MIT | 10 mo ago |
| 118 | Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines. | ancoleman/ | 526 | — | ~3.8k | Automated safety check: Pass | MIT | 10 mo ago |
| 119 | Authors a Dynamics 365 Finance and Supply Chain Management Solution Blueprint from scratch through a structured, section-by-section architect interview, establishing scope, target operating model… | github/ | 40k | — | ~2.7k | Automated safety check: Pass | MIT | today |
| 120 | 120.Platform Trust Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction. | inkline/ | 1.5k | — | ~1.1k | Automated safety check: Pass | No licence | 27 days ago |
| 121 | Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP… | trilwu/ | 156 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 122 | Harden AI/LLM deployments against prompt injection, data exfiltration, model theft, and supply chain attacks. | sickn33/ | 47k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | yesterday |
| 123 | 123.Diane Hendricks Reach for this skill whenever Claude encounters situations involving supply chain innovation, B2B customer respect, community revitalization, vocational education, or navigating massive business… | K-Dense-AI/ | 129 | — | ~1.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 124 | Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2… | davila7/ | 32k | — | ~1.7k | Automated safety check: Notes | MIT | today |
| 125 | 125.Ism Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. | Sushegaad/ | 942 | — | ~3.6k | Automated safety check: Pass | MIT | 3 days ago |
| 126 | 126.Sbom Generate a CycloneDX SBOM for the repository via git-pkgs sbom. | alpha-omega-security/ | 231 | — | ~290 | Automated safety check: Pass | MIT | today |
| 127 | 当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。 | zhaji2333/ | 113 | — | ~688 | Automated safety check: Warn | MIT | 23 days ago |
| 128 | Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 129 | Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 130 | Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 131 | Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed… | mukul975/ | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 132 | Simulates and detects software supply chain attacks: typosquatting detection via Levenshtein distance against popular PyPI package names, dependency confusion testing against private registries… | mukul975/ | 34k | — | ~716 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 133 | Verifies artifact signatures and SLSA provenance using Sigstore's cosign (verify, verify-attestation, verify-blob-attestation) and slsa-verifier (verify-artifact), enforcing keyless OIDC builder… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 134 | Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs. | different-ai/ | 24k | — | ~939 | Automated safety check: Warn | Unknown | today |
| 135 | 135.Sbom Generate Usar para generar Software Bill of Materials para cumplimiento del CRA. | 686f6c61/ | 117 | — | ~780 | Automated safety check: Pass | MIT | 1 mo ago |
| 136 | Analyze how stocks move together using Yahoo Finance price history (yfinance): find correlated peers for a ticker, measure correlation, beta, and spread between specific tickers, cluster a group… | himself65/ | 3.4k | — | ~3.3k | Automated safety check: Pass | MIT | 3 days ago |
| 137 | 137.Atmos Sbom Atmos SBOM provenance: CycloneDX and SPDX generation from vendor and Terraform evidence, coverage diagnostics, NTIA validation, and native CI workflow-artifact publication | cloudposse/ | 1.4k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 138 | Apply Karpathy-style minimalism and anti-dependency principles to code and system design. | LearnPrompt/ | 109 | — | ~1.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 139 | Inventories project dependencies and runtimes across ecosystems and reports known CVEs, supply-chain risks and a prioritized upgrade plan. | criptogus/ | 288 | — | ~974 | Automated safety check: Pass | CC-BY-SA-4.0 | 28 days ago |
| 140 | Weekly supply-chain hygiene scan (Perplexity Bumblebee). An agent skill from Szotasz/marveen. | Szotasz/ | 115 | — | ~2.1k | Automated safety check: Pass | MIT | today |
| 141 | 云原生与软件供应链安全防御。容器/K8s 加固、Service Mesh、CI/CD 安全、SLSA/SBOM/Sigstore、云 IAM、Secrets 管理、IaC 安全。Use when hardening Kubernetes clusters, auditing CI/CD pipelines, implementing supply chain security… | telagod/ | 243 | — | ~778 | Automated safety check: Pass | MIT | 2 mo ago |
| 142 | 142.Security Scanner A skill your agent uses when scanning code or configuration for security vulnerabilities. | WrongStack/ | 370 | — | ~2.1k | Automated safety check: Pass | MIT | today |
| 143 | Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat. | epam/ | 504 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 144 | You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. | aiskillstore/ | 430 | 7 repos | ~490 | Automated safety check: Pass | No licence | yesterday |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38