devsecops skills

573 tagged devsecops, measured the same way as everything else here.

Browse within: cybersecurity 219ai-security 209appsec 93ai-hacking 58ai-pentesting 58DAST 57compliance 57bug-bounty 51CISO 48blue-team 48cowork 47data-exfiltration 47malware-detection 47Prompt Injection 42

playwright-cli

49

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Automate browser interactions, test web pages and work with Playwright tests.

11 2mo ago A 19 tokens original Apache-2.0

nuclei

50

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Nuclei CLI parameter reference and usage patterns - YAML-template vulnerability scanning, target input modes, template filters, output formats, rate limits, ProjectDiscovery dashboard upload, and common scan commands.

11 2mo ago A 42 tokens original Apache-2.0

final-report

51

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Final engagement report generation — executive summary, technical report, findings aggregation, attack path narrative, detection gap matrix, remediation roadmap.

11 2mo ago A 28 tokens original Apache-2.0

aryaminus/controlkeel

Skill Claude CodeCodex

Verify AI agent code for dangerous patterns including infinite loops, unbounded retries, tool hallucinations, and context overflow. Use before deploying agent workflows or when reviewing agent code.

11 2d ago A 39 tokens

cloudflare-agent

53

aryaminus/controlkeel

Skill Claude CodeCodex

Enable ControlKeel governance for Cloudflare Agents with policy gates, budget enforcement, PII detection, and secure execution.

11 2d ago A 28 tokens

continuity

54

aryaminus/controlkeel

Skill Claude CodeCodex

Learn, record, audit, and apply codebase patterns consistently across a repo by comparing current code to canonical local examples stored in CK memory. Use when asked to preserve continuity, learn a pattern, check drift, fix inconsistent implementations, or enforce local conventions.

11 2d ago A 54 tokens

jwt_tool

55

tr4m0ryp/shor

Skill Claude CodeCodex

Skill "jwt_tool" from tr4m0ryp/shor, covering jwttool — jwt analysis & attacks, when to reach for it, key flags / modes, safe invocation and form field (oidc-style).

9 1mo ago A 52 tokens

authz-recipe

56

tr4m0ryp/shor

Skill Claude CodeCodex

Broken Access Control is OWASP #1, but there is no drop-in CLI (Autorize / AuthMatrix are Burp extensions). This is the procedure that carries the whole category: an authorization-matrix + A/B session-replay method driving curl, the playwright skill (per-identity sessions), and ffuf (ID enumeration). Live →…

9 1mo ago A 62 tokens

tr4m0ryp/shor

Skill Claude CodeCodex

A small recipe over the already-cloned repo. It runs git log --grep for security/CVE/fix patterns, maps the touched files into ranked hot files, and emits historicalsignal.json. It optionally folds in two signals you may have ALREADY produced this phase — osv-scanner JSON (dependency CVEs) and gitleaks JSON (history…

9 1mo ago A 86 tokens

github-hardening

58

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when updating or reviewing GitHub-side hardening guidance for derived repositories, including required settings, rulesets, scanning, review protections, and workflow permissions. Use terraform-hardening instead for Terraform-backed changes under config/infra. Do not use for ordinary in-repo implementation changes…

9 7d ago A 70 tokens

repo-adaptation

59

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when adapting or customizing this repository to meet the needs of the source code under src/, including language and framework needs, dependencies, runtime behavior, Docker, Makefile targets, and customization surfaces. Do not use for routine bug fixes, small refactors, pure workflow validation…

9 7d ago A 74 tokens

terraform-hardening

60

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when changing or reviewing the Terraform-backed GitHub repository hardening workspace under config/infra, including provider pins, rulesets, default branch protection, required checks, secret scanning, Dependabot security updates, token handling, plan/apply behavior, and infra documentation. Do not use for…

9 7d ago A 89 tokens

Algorithm

61

CarbeneAI/Forge

Skill Claude CodeCodex

Structured 7-phase execution engine for systematic problem-solving with effort classification and rigorous methodology. USE WHEN user mentions algorithm, systematic approach, structured execution, step-by-step methodology, rigorous framework, OR wants disciplined problem-solving process.

9 1mo ago A 46 tokens original MIT

AnnualReports

62

CarbeneAI/Forge

Skill Claude CodeCodex

Comprehensive catalog of 570+ annual security reports and threat intelligence sources for CISO consulting, threat landscape analysis, and security research. USE WHEN user mentions annual reports, threat landscape, security reports, industry reports, DBIR, Verizon, Mandiant, CrowdStrike, threat briefing, threat…

9 1mo ago A 79 tokens original MIT

ArtGenerator

63

CarbeneAI/Forge

Skill Claude CodeCodex

AI image generation for blog posts, presentations, and content creation. USE WHEN user mentions generate image, create artwork, blog image, header image, presentation visual, AI art, Replicate, DALL-E, Midjourney, OR wants visual content for publications and marketing materials.

9 1mo ago A 59 tokens original MIT

immunogen

64

Mocinjay/immunogen

Skill Claude CodeCodex

Scan an AI-built ("vibe-coded") repo for launch-blocking issues — leaked secrets, exposed API keys, broken auth, missing row-level security, unsafe payment wiring, vulnerable dependencies, and risky AI-layer surface (skills/MCP servers/agent prompts). Returns a 0-100 Ship Score with a banded verdict and ranked…

9 1mo ago A 117 tokens original MIT

prodcheck-review

65

FarzamHabibi/pre-production-checklist

Skill Claude CodeCodex

Review this codebase against the prodcheck pre-production checklists — security, performance, scale, integrations and post-launch readiness. Use when asked to check whether a project is ready to ship, to audit an area before launch, or to work through a specific checklist. Produces evidence with file:line citations…

9 2d ago A 70 tokens

explain

66

cfgaudit/cfgaudit

Skill Claude CodeCodex

Explain a cfgaudit rule (what it checks, why, and how to fix it).

7 5d ago A 22 tokens original Apache-2.0

init

67

cfgaudit/cfgaudit

Skill Claude CodeCodex

Scaffold a project-aware .claude/settings.json deny list with cfgaudit.

7 5d ago A 18 tokens original Apache-2.0

scan

68

cfgaudit/cfgaudit

Skill Claude CodeCodex

Run cfgaudit to scan this project's AI-agent configuration files for security issues.

7 5d ago A 17 tokens original Apache-2.0

betterdoc

69

samartomar/ai-harness

Skill Claude CodeCodex

Create, edit, and review ai-harness public documentation with BetterDoc's claim-first, evidence-aware workflow. Use for README and website copy, quickstarts, reference docs, architecture and ADRs, security and assurance docs, runbooks, migration guides, changelogs, release notes, PR summaries, or any other public…

6 5d ago A 111 tokens original Apache-2.0

decision-partner

70

samartomar/ai-harness

Skill Claude CodeCodex

Structured decision-closing sessions for the ai-harness / aih product. Use whenever the user says "decision session" or "close decisions", asks "should we do A or B" about aih's product, governance, packaging, or roadmap direction, wants open questions triaged into decidable-now vs parked-on-evidence, wants a past…

6 5d ago A 183 tokens original Apache-2.0

bugbounty-pr-scan

71

samartomar/ai-harness

Skill Claude CodeCodex

Scan open PRs and generated ECC/agent artifacts for high-coverage review risks before they are accepted. Use when a PR adds or changes agent bootloaders, Codex or Claude skills, MCP config, generated workflow commands, auto-learning instincts, repository review runbooks, or multi-agent review configuration; also use…

6 5d ago A 86 tokens original Apache-2.0

tbd

72

jlevy/supply-chain-hardening

Skill Claude CodeCodex

Git-native issue tracking (beads), coding guidelines, knowledge injection, and spec-driven planning for AI agents. Drop-in replacement for bd/Beads with simpler architecture. Use for: tracking issues/beads with dependencies, creating bugs/features/tasks, planning specs, implementing features from specs, code reviews…

5 25d ago A 223 tokens original MIT