CaseyLabs/kc-secure-repo-template

Security-hardened GitHub repository template, designed to prevent supply-chain attacks. Includes vulnerability scanning and AI agent skills.

This repository also configures its own agents. See what kc-secure-repo-template tells them →

9Stars on the repository
10Mods indexed here, across every type
6d agoLast push, which is what freshness is scored on
customA LICENSE file GitHub cannot name, so bodies are not copied

github-hardening

01

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when updating or reviewing GitHub-side hardening guidance for derived repositories, including required settings, rulesets, scanning, review protections, and workflow permissions. Use terraform-hardening instead for Terraform-backed changes under config/infra. Do not use for ordinary in-repo implementation changes…

not rated 9 6d ago A 70 tokens

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when adding or revising optional language-specific guidance for Go, Node.js, SQL, or small polyglot derived repositories without bloating the generic template. Keep language behavior optional. Do not use for generic template policy, routine validation, GitHub-settings-only work, or release-integrity-only work.

not rated 9 6d ago A 66 tokens

pr-draft-summary

03

CaseyLabs/kc-secure-repo-template

Skill Codex

Draft a concise pull request handoff after substantive repository changes are finished or ready for review. Trigger when wrapping up code, test, script, workflow, release, security, documentation-with-behavior-impact, or template customization changes and the user needs a PR title/body grounded in the real diff…

not rated 9 6d ago A 93 tokens

release-integrity

04

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when reviewing or improving this template's release-integrity story, including artifact verification, SBOMs, attestations, vulnerability scanning, signing guidance, and release-workflow safety. Do not use for general CI validation, GitHub-settings-only work, or unrelated template customization.

not rated 9 6d ago A 59 tokens

repo-adaptation

05

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when adapting or customizing this repository to meet the needs of the source code under src/, including language and framework needs, dependencies, runtime behavior, Docker, Makefile targets, and customization surfaces. Do not use for routine bug fixes, small refactors, pure workflow validation…

not rated 9 6d ago A 74 tokens

security-review

06

CaseyLabs/kc-secure-repo-template

Skill Codex

Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching.

not rated 9 6d ago A 27 tokens

terraform-hardening

07

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when changing or reviewing the Terraform-backed GitHub repository hardening workspace under config/infra, including provider pins, rulesets, default branch protection, required checks, secret scanning, Dependabot security updates, token handling, plan/apply behavior, and infra documentation. Do not use for…

not rated 9 6d ago A 89 tokens

workflow-validation

08

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when validating repository workflows after changes to Docker-first Makefile targets, Dockerfiles, scripts, CI, release packaging, smoke tests, or documentation alignment. Do not use for repo redesign, GitHub-policy-only changes, or instruction-only skill edits with no workflow impact.

not rated 9 6d ago A 57 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: