paruff/uFawkesAI

An AI agent starter template that implements the DORA AI Capabilities Model — built for GitHub Copilot, Claude Code, Cursor, and Codex

This repository also configures its own agents. See what uFawkesAI tells them →

2Stars on the repository
126Mods indexed here, across every type
19d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

design-compliance

73

paruff/uFawkesAI

Skill Claude CodeCodex

Verify that build output matches the design. Use when validating architecture alignment, component boundaries, interfaces, and integration points.

not rated 2 19d ago A 27 tokens original MIT

gitops-overlay

74

paruff/uFawkesAI

Skill Claude CodeCodex

Validate GitOps overlays for correctness and compliance. Use when reviewing kustomize builds, environment overlays, image tags, and secrets.

not rated 2 19d ago A 30 tokens original MIT

k8s-policy

75

paruff/uFawkesAI

Skill Claude CodeCodex

Validate Kubernetes manifests for compliance. Use when reviewing resource limits, securityContext, network policies, and secret usage.

not rated 2 19d ago A 27 tokens original MIT

pipeline-policy

76

paruff/uFawkesAI

Skill Claude CodeCodex

Validate CI/CD pipeline correctness. Use when reviewing pipeline definitions for required stages, security gates, SBOM, and signing.

not rated 2 19d ago A 27 tokens original MIT

policy-validation

77

paruff/uFawkesAI

Skill Claude CodeCodex

Validate build output against organizational policies. Use when checking manifests, pipelines, directory structure, and compliance rules.

not rated 2 19d ago A 24 tokens original MIT

secret-governance

78

paruff/uFawkesAI

Skill Claude CodeCodex

Validate secret usage and governance. Use when reviewing secret storage, rotation policies, and access patterns.

not rated 2 19d ago A 24 tokens original MIT

security-rbac

79

paruff/uFawkesAI

Skill Claude CodeCodex

Validate RBAC, service accounts, and security posture. Use when reviewing roles, bindings, token permissions, and container security settings.

not rated 2 19d ago A 30 tokens original MIT

spec-compliance

80

paruff/uFawkesAI

Skill Claude CodeCodex

Verify that build output satisfies the specification. Use when comparing implementation against functional and non-functional requirements.

not rated 2 19d ago A 23 tokens original MIT

container-security

81

paruff/uFawkesAI

Skill Claude CodeCodex

Ensure container images built by PIPE are secure, minimal, and free of vulnerabilities. Use when scanning container images, validating base images, or checking OS package vulnerabilities.

not rated 2 19d ago A 35 tokens original MIT

paruff/uFawkesAI

Skill Claude CodeCodex

Ensure all images are signed and verifiable before deployment. Use when validating Cosign signatures, keyless signing, or provenance.

not rated 2 19d ago A 31 tokens original MIT

paruff/uFawkesAI

Skill Claude CodeCodex

Scan container layers for OS and application vulnerabilities. Use when scanning image layers, validating CVE severity, or checking remediation suggestions.

not rated 2 19d ago A 31 tokens original MIT

dependency-scanning

84

paruff/uFawkesAI

Skill Claude CodeCodex

Detect vulnerable dependencies in NPM, Python, Go, and container layers. Use when scanning package.json, requirements.txt, Dockerfile, or validating SBOM.

not rated 2 19d ago A 36 tokens original MIT

paruff/uFawkesAI

Skill Claude CodeCodex

Scan JavaScript/TypeScript dependencies for vulnerabilities. Use when scanning package-lock.json, validating dependency trees, or detecting vulnerable transitive dependencies.

not rated 2 19d ago A 34 tokens original MIT

paruff/uFawkesAI

Skill Claude CodeCodex

Generate and validate Software Bill of Materials for Fawkes artifacts. Use when generating SBOM with Syft, validating SBOM schema, or checking dependency completeness.

not rated 2 19d ago A 37 tokens original MIT

sast

87

paruff/uFawkesAI

Skill Claude CodeCodex

Detect insecure code patterns, vulnerabilities, and misconfigurations in OBS, PIPE, and Fawkes services. Use when running Semgrep, CodeQL, or validating secure coding patterns.

not rated 2 19d ago A 40 tokens original MIT

codeql-analysis

88

paruff/uFawkesAI

Skill Claude CodeCodex

Run CodeQL queries to detect deep security vulnerabilities. Use when building CodeQL database, running language-specific queries, or validating results.

not rated 2 19d ago A 30 tokens original MIT

paruff/uFawkesAI

Skill Claude CodeCodex

Run Semgrep rulesets against Fawkes codebases. Use when executing OWASP rules, custom Fawkes rules, or validating findings.

not rated 2 19d ago A 37 tokens original MIT

secret-detection

90

paruff/uFawkesAI

Skill Claude CodeCodex

Ensure no secrets leak into source code, logs, artifacts, or GitOps repos. Use when scanning source code, Git history, container layers, or validating artifact integrity.

not rated 2 19d ago A 38 tokens original MIT

paruff/uFawkesAI

Skill Claude CodeCodex

Detect secrets in source code and Git history. Use when scanning working tree, scanning Git history, or validating findings.

not rated 2 19d ago A 30 tokens original MIT

paruff/uFawkesAI

Skill Claude CodeCodex

Ensure all build artifacts are tamper-proof and verifiable. Use when validating checksums, signatures, or provenance.

not rated 2 19d ago A 28 tokens original MIT

test-execution

93

paruff/uFawkesAI

Skill Claude CodeCodex

Execute all relevant tests and quality gates to validate build output. Use when running tests, collecting results, and measuring coverage.

not rated 2 19d ago A 28 tokens original MIT

e2e-test-execution

94

paruff/uFawkesAI

Skill Claude CodeCodex

Validate full system behavior from the user's perspective. Use when running end-to-end tests to verify complete workflows and acceptance criteria.

not rated 2 19d ago A 31 tokens original MIT

paruff/uFawkesAI

Skill Claude CodeCodex

Validate interactions between components. Use when running integration tests to verify data flow and component boundaries.

not rated 2 19d ago A 23 tokens original MIT

paruff/uFawkesAI

Skill Claude CodeCodex

Stands up a real running instance of the affected component(s) and runs testtype:live-system acceptance criteria against it — real HTTP calls, real process behavior, real evidence. Not a mock, not a simulated environment. Use when tasks.json contains any acceptance criterion tagged testtype: live-system.

not rated 2 19d ago A 65 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: