Topic · Security
Best supply chain security skills, page 4
Supply chain security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. | aiskillstore/ | 430 | 7 repos | ~563 | Automated safety check: Pass | No licence | today |
| 146 | A skill your agent uses when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project… | cwinvestments/ | 423 | — | ~3.1k | Automated safety check: Pass | Proprietary | 13 days ago |
| 147 | A skill your agent uses when an open-source developer tool, package, CLI, agent, or MCP server must be evaluated for legitimacy, supply-chain risk, telemetry, dangerous capabilities, claim accuracy… | asimons81/ | 126 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 148 | 148.Security Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks. | notque/ | 439 | — | ~2.6k | Automated safety check: Notes | MIT | 6 days ago |
| 149 | 149.Create Policy Create OPA governance policies for Harness via MCP. An agent skill from harness/harness-skills. | harness/ | 115 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 150 | 150.CI CD Security CI/CD pipeline security, supply chain security, SLSA compliance, artifact signing, dependency scanning | Hack23/ | 239 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 151 | 151.Moai Ref Secops DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning… | modu-ai/ | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | today |
| 152 | Software supply-chain defensive security reference: SBOM generation and verification (SPDX / CycloneDX), dependency-confusion defense, malicious-package triage playbook, SLSA provenance levels… | modu-ai/ | 1.2k | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | today |
| 153 | A skill your agent uses when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. | jabrena/ | 447 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 154 | A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products… | jabrena/ | 447 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 155 | 155.Sca Security Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to… | hardw00t/ | 104 | — | ~3k | Automated safety check: Pass | No licence | 5 mo ago |
| 156 | 156.Security Testing Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests… | petrkindlmann/ | 168 | — | ~4.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 157 | External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~4.3k | Automated safety check: Warn | MIT | today |
| 158 | Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 159 | Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 160 | Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies. | jeremylongshore/ | 2.8k | — | ~2.2k | Automated safety check: Notes | MIT | today |
| 161 | 161.Supply Chain Interactive supply chain dashboard mapping suppliers, customers, and financial interdependencies | daloopa/ | 489 | — | ~14k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 162 | 162.Securing Systems Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. | telagod/ | 243 | — | ~581 | Automated safety check: Pass | MIT | 2 mo ago |
| 163 | Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation. | majiayu000/ | 287 | — | ~561 | Automated safety check: Pass | MIT | yesterday |
| 164 | 164.Update Deps Inventory, assess, update, and validate third-party dependencies across Bun, Python/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk. | stella/ | 258 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | today |
| 165 | Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable… | Goldziher/ | 159 | — | ~250 | Automated safety check: Pass | MIT | today |
| 166 | Weekly. An agent skill from markfulton/ai-employees. | markfulton/ | 498 | — | ~14k | Automated safety check: Pass | MIT | 2 days ago |
| 167 | Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust. | borghei/ | 886 | — | ~1.8k | Automated safety check: Pass | MIT | 2 days ago |
| 168 | NIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities, covering the 10 minimum security measures. | borghei/ | 886 | — | ~8.1k | Automated safety check: Pass | MIT | 2 days ago |
| 169 | 169.Security Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries… | telagod/ | 243 | — | ~907 | Automated safety check: Pass | MIT | 2 mo ago |
| 170 | A skill your agent uses when auditing project dependencies for known vulnerabilities, supply chain risk, or provenance issues — covers Go modules, Maven/JVM, and CI integration for automated scanning | Habitat-Thinking/ | 114 | — | ~2.1k | Automated safety check: Pass | Unknown | 19 days ago |
| 171 | A skill your agent uses when reviewing GitHub Actions workflow files for security issues, hardening CI pipelines, or assessing supply chain risk in a repository that uses GitHub Actions | Habitat-Thinking/ | 114 | — | ~1.3k | Automated safety check: Pass | Unknown | 19 days ago |
| 172 | Audit dependency manifests and lockfiles for SBOM extraction, risky install scripts, unpinned versions, remote/git dependency sources, dependency-confusion and typosquat/known-malicious package… | ptn1411/ | 220 | — | ~445 | Automated safety check: Pass | No licence | 17 days ago |
| 173 | Draft, adapt, and review contracts and clauses aligned with The Chancery Lane Project's methodology for reducing carbon emissions through legal agreements. | lawve-ai/ | 842 | — | ~1.4k | Automated safety check: Pass | Unknown | 7 days ago |
| 174 | 174.Nis2 Navigator NIS2 Compliance Navigator — scope classification, Art. An agent skill from lawve-ai/awesome-legal-skills. | lawve-ai/ | 842 | — | ~3.6k | Automated safety check: Pass | AGPL-3.0 | 7 days ago |
| 175 | Audit local AI model, adapter, tokenizer, configuration, and packaging artifacts for provenance, integrity, dependency, serialization, license, and loading-risk evidence. | cyberful/ | 135 | — | ~535 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 176 | 176.Phx Deps Audit Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. | oliver-kriska/ | 565 | — | ~2.2k | Automated safety check: Pass | MIT | 4 days ago |
| 177 | Run evidence-backed workflows for supply chain, dependency neighborhoods, architecture, performance, unsafe and ownership review, upgrades, and ecosystem integration. | richlander/ | 151 | — | ~4.4k | Automated safety check: Pass | No licence | today |
| 178 | Manages the flow of goods and inputs — sourcing, inventory, lead times, fulfillment, and supply risk. | cbrock84/ | 2k | — | ~825 | Automated safety check: Pass | MIT | 22 days ago |
| 179 | Supply Chain Bottleneck Analyzer for Shopify/DTC stores. An agent skill from nexscope-ai/eCommerce-Skills. | nexscope-ai/ | 1.1k | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 180 | Supply Chain Bottleneck Analyzer for Walmart Marketplace sellers. | nexscope-ai/ | 1.1k | — | ~855 | Automated safety check: Pass | MIT | 1 mo ago |
| 181 | Supply Chain Optimization (Lite) - Diagnose bottlenecks and provide cost reduction strategies through conversation | nexscope-ai/ | 1.1k | — | ~852 | Automated safety check: Pass | MIT | 1 mo ago |
| 182 | Supply Chain Bottleneck Analyzer for TikTok Shop sellers. An agent skill from nexscope-ai/eCommerce-Skills. | nexscope-ai/ | 1.1k | — | ~1k | Automated safety check: Pass | MIT | 1 mo ago |
| 183 | 183.Henry Ford A skill your agent uses whenever reasoning about manufacturing, scaling production, pricing strategies, operational efficiency, vertical integration, or labor compensation. | K-Dense-AI/ | 129 | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 184 | A skill your agent uses whenever you need to reason like John D. | K-Dense-AI/ | 129 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 185 | Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development | Hack23/ | 239 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | today |
| 186 | 186.Dependency Audit Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. | Mathews-Tom/ | 328 | — | ~2.7k | Automated safety check: Pass | MIT | 3 days ago |
| 187 | Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface. | LearnPrompt/ | 110 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 188 | 188.Common Security Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website). | macalbert/ | 138 | — | ~1.6k | Automated safety check: Notes | MIT | 4 days ago |
| 189 | 189.Market Research Industry and market research. An agent skill from brycewang-stanford/Auto-Empirical-Research-Skills. | brycewang-stanford/ | 4.5k | — | ~4.5k | Automated safety check: Notes | Unknown | 4 days ago |
| 190 | A skill your agent uses when positioning a Journal of Operations Management (JOM) manuscript within the operations and supply chain management conversation — joining a live OM/SCM debate… | franklee16/ | 223 | 1 repo | ~870 | Automated safety check: Pass | No licence | 21 days ago |
| 191 | A skill your agent uses when targeting Journal of Operations Management (JOM) or deciding whether an empirical / survey-based / behavioral operations-and-supply-chain manuscript fits this venue. | franklee16/ | 223 | 1 repo | ~1.5k | Automated safety check: Pass | No licence | 21 days ago |
| 192 | A skill your agent uses when positioning a Manufacturing & Service Operations Management (M&SOM) manuscript within the operations-management literature — engaging the canonical OM streams… | franklee16/ | 223 | 1 repo | ~845 | Automated safety check: Pass | No licence | 21 days ago |
Explore related skills
Category
More topics in Security
- Security review637
- Web application vulnerabilities468
- Vulnerability scanning305
- Static analysis and SAST284
- Security operations246
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38