devsecops skills

573 tagged devsecops, measured the same way as everything else here.

Browse within: cybersecurity 219ai-security 209appsec 93ai-hacking 58ai-pentesting 58DAST 57compliance 57bug-bounty 51CISO 48blue-team 48cowork 47data-exfiltration 47malware-detection 47Prompt Injection 42

ai-explore

25

arcasilesgroup/ai-engineering

Skill Claude CodeCodex

Answers questions about this repository by reading it, anchored to file:line, and tours an unfamiliar area for somebody who has just arrived. Trigger for "where does X live", "how does this work", "why does it do that", "what depends on Y", "walk me through", "map this module", "trace this import chain", "onboard me".…

54 3d ago A 115 tokens original Apache-2.0

ai-visual-plan

26

arcasilesgroup/ai-engineering

Skill Claude CodeCodex

Turns a plan — one written here, one pasted from a chat, one another agent produced — into the review surface the human actually reads: the plan's own Markdown, carrying visual blocks the renderer turns into diagrams, file maps, decision tables and open questions, handed over as one page whose link opens in the…

54 3d ago A 134 tokens original Apache-2.0

Synvoya/codeinspectus

Skill Claude CodeCodex

Investigate and remediate exactly one user-selected CodeInspectus finding with evidence-gated reproduction, a separately approved minimal patch, focused regression testing, and an exact-prior-scan rescan. Use when a user asks an agent to examine, reproduce, fix, or verify one CodeInspectus finding without batching…

44 8d ago A 76 tokens original Apache-2.0

Synvoya/codeinspectus

Skill Claude CodeCodex

Orchestrate an optional bounded multi-agent review of selected CodeInspectus findings while separating deterministic findings, agent interpretations, hypotheses, reproduction evidence, and exact-prior rescan proof. Use only when a user explicitly requests multi-agent security review.

44 8d ago A 55 tokens original Apache-2.0

Synvoya/codeinspectus

Skill Claude CodeCodex

Review CodeInspectus findings with optional threat-model or project-document context while treating repository text as untrusted, preserving raw scanner findings unchanged, and labelling agent interpretation separately. Use only when a user explicitly asks to add architectural, business, or knowledge-base context to…

44 8d ago A 62 tokens original Apache-2.0

setup-agent-guard

30

JeongJaeSoon/agent-guard

Skill Claude CodeCodex

Diagnose, install, and verify Agent Guard's plugin-local binary, jq and gitleaks dependencies, the active host integration, and live hook protection. Use when Agent Guard reports degraded protection, a SessionStart warning asks for setup, plugin hooks fail or appear bypassed, or a user asks to finish or repair Agent…

24 2d ago A 72 tokens original MIT

setup-shell

31

JeongJaeSoon/agent-guard

Skill Claude CodeCodex

Install or refresh Agent Guard's plugin-local shell integration. Use when the user explicitly asks to enable or update shell command masking, or when a shell-integration warning directs them to rerun setup-shell.

24 2d ago A 43 tokens original MIT

jfrog/jfrog-skills

Skill Claude CodeCodex

Check/download a package (npm, Maven, PyPI, Go...) via JFrog — safe, allowed, curated? Or: package op fails/blocked (ETARGET, 403, blocked by curation policy, missing version, waiver) — root cause it. Checks the JFrog Public Catalog and stored packages for a version, interprets catalog security signals, and downloads…

21 2d ago A 189 tokens original Apache-2.0

jfrog/jfrog-skills

Skill Claude CodeCodex

Use this skill when the user asks to set up, configure, bind, or connect a package manager (npm, pip, uv, pipenv, maven, gradle, go, docker, helm, ...) to JFrog Artifactory via jf setup and .jfrog/local/package-resolution.json; when a workspace manifest exists with no matching binding entry; or when a session hook…

21 2d ago A 175 tokens original Apache-2.0

jfrog

34

jfrog/jfrog-skills

Skill Claude CodeCodex

Interact with the JFrog Platform via the JFrog CLI, JFrog MCP server and REST/GraphQL APIs. Use this skill when the user wants to manage Artifactory repositories, upload or download artifacts, manage builds, configure permissions, manage users and groups, work with access tokens, configure JFrog CLI servers, search…

21 2d ago A 204 tokens original Apache-2.0

trap

35

bikr/TRAP

Skill Claude CodeCodex

Run a True Readiness Audit (TRAP) — an adversarial, evidence-first production-readiness and security audit of the current codebase. Use when the user asks to security-review, audit, threat-model, or check whether an app is production-ready / safe to ship / safe to deploy — especially for AI- or "vibe"-coded apps, or…

20 1mo ago A 79 tokens original MIT

secureai-scan

36

akanthed/SecureAI-Scan

Skill Claude CodeCodex

Use when the user asks to scan a repo for AI/LLM security issues, wants to know "is this skill safe?" before installing an Agent Skill, needs to "scan my MCP config" or check an MCP server before trusting it, asks about prompt injection / tool poisoning / RAG poisoning risk in their code, or is about to install any…

19 3d ago A 109 tokens original MIT

log-note

38

akanthed/SecureAI-Scan

Skill Claude CodeCodex

Appends a note the user provides to the project's activity log.

19 3d ago A 16 tokens original MIT

best-in-code

39

kingggg5/shipproof

Skill Claude CodeCodex

Run an adaptive, reusable software-delivery harness across AI models with project management, planning, research, design, frontend, backend, QA, durable scoped memory, capability fallbacks, bounded discovery, and human approval gates. Use when the user invokes Harness or asks for an end-to-end build, review, bug…

18 6d ago A 89 tokens original MIT

kingggg5/shipproof

Skill Claude CodeCodex

Audit a repository or service for release-blocking bugs, security, data/privacy, AI-agent, supply-chain, operability, and scale risks. Use for deep code audits, threat models, pre-production reviews, vulnerability triage, incidents, defensive investigation, release gates, or evidence-based 10k-to-1M-user readiness.

18 6d ago A 72 tokens original MIT

kingggg5/shipproof

Skill Claude CodeCodex

Design, write, refactor, or optimize production code so it is secure, correct, resource-bounded, observable, and maintainable. Use for full-stack features, APIs, databases, AI/RAG/MCP tools, CPU/RAM/latency work, 10k-to-1M-user planning, or authorized kernel, browser, parser, protocol, and defensive…

18 6d ago A 86 tokens original MIT

Coff0xc/coffee-skill

Skill Claude CodeCodex

A guide for creating and checking editable Office files, including PowerPoint presentations, Word documents, PDFs, and Excel workbooks. It also covers checking layout, formulas, and file structure.

16 3mo ago A 85 tokens

Coff0xc/coffee-skill

Skill Claude CodeCodex

Coff0xc lightweight skill router/composer. Use only when the user asks AI to decide which coff0xc skills to use, chain skills, build a task/workflow graph, orchestrate vibe coding, handle cross-domain/multi-domain work, or recover an uncertain trigger. Also for broad plan work spanning dev API UI or security cloud…

16 3mo ago A 109 tokens

Coff0xc/coffee-skill

Skill Claude CodeCodex

Use when / 当用户请求 UI/frontend/product surface/report/translation polish:dashboard/admin/SaaS、component/design system、responsive/mobile、accessibility/ARIA/contrast、loading/empty/error/hover/focus/keyboard states、browser smoke/screenshot/console cleanliness、anti-AI visual polish。正式 Office 文件用 office-doc-tools。手动触发:使用…

16 3mo ago A 90 tokens

ai-security

45

Kaademos/secure-sdlc-agents

Skill Claude CodeCodex

Use when building any feature that calls an LLM API, processes user input sent to a model, uses RAG or embeddings, deploys an AI agent with tool access, or makes AI-generated output visible to users or downstream systems.

13 1mo ago A 50 tokens original MIT

Kaademos/secure-sdlc-agents

Skill Claude CodeCodex

Use when a project requires a compliance framework mapping, when risks need formal documentation, when audit evidence must be collected, or when producing a compliance attestation before release. Applies to SOC 2, ISO 27001, GDPR, PCI DSS, NIST CSF, and DORA.

13 1mo ago A 64 tokens original MIT

Kaademos/secure-sdlc-agents

Skill Claude CodeCodex

Use when writing or reviewing code that handles user input, authentication, access control, cryptography, error handling, file uploads, or dependency management. Also activates when a pull request touches any security-sensitive component.

13 1mo ago A 46 tokens original MIT

adamsjack711-ux/pkgxray

Skill Claude CodeCodex

Audit supplied evidence for AI coding-agent extensions, Codex plugins, Claude Code extensions, and MCP servers using concrete supply-chain security indicators.

11 13d ago A 36 tokens original MIT