devsecops skills

573 tagged devsecops, measured the same way as everything else here.

Browse within: cybersecurity 219ai-security 209appsec 93ai-hacking 58ai-pentesting 58DAST 57compliance 57bug-bounty 51CISO 48blue-team 48cowork 47data-exfiltration 47malware-detection 47Prompt Injection 42

audit

73

xChechi/xche-ai-app-security-pack

Skill Claude CodeCodex

Audit the selected code or recent changes against the xChe AI-App Security policy (OWASP / API / LLM / MCP). Reports prioritized findings with fixes.

5 2mo ago A 32 tokens original MIT

secure-coding

74

xChechi/xche-ai-app-security-pack

Skill Claude CodeCodex

Secure-by-default coding standards for AI-built apps. Apply these rules whenever writing or modifying application code that handles authentication, authorization, databases or SQL, HTTP APIs, user input, file uploads, secrets or config, sessions or cookies, or LLM/MCP integrations.

5 2mo ago A 53 tokens original MIT

speckit-clarify

75

dfirs1car1o/sicario-spec

Skill Claude CodeCodex

Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.

5 21d ago A 34 tokens copy · 86% MIT

speckit-implement

76

dfirs1car1o/sicario-spec

Skill Claude CodeCodex

Execute the implementation plan by processing and executing all tasks defined in tasks.md.

5 21d ago A 20 tokens copy · 84% MIT

speckit-plan

77

dfirs1car1o/sicario-spec

Skill Claude CodeCodex

Execute the implementation planning workflow using the plan template to generate design artifacts.

5 21d ago A 19 tokens copy · 84% MIT

safe-helper

78

AgentSafety/ClawCare

Skill Claude CodeCodex

A benign skill that provides helpful text utilities.

5 4mo ago A 12 tokens original Apache-2.0

violation-skill

79

AgentSafety/ClawCare

Skill Claude CodeCodex

A skill whose code violates the plugin-level policy manifest.

5 4mo ago A 16 tokens original Apache-2.0

envault

81

DinanathDash/Envault

Skill Claude CodeCodex

Official AI Agent Skill for Envault Secrets Management platform. Enforces strict zero-hardcode rules, Client-Side Encryption, and Human-in-the-Loop (HITL) approval workflows.

4 1mo ago A 41 tokens

DinanathDash/Envault

Skill Claude CodeCodex

Design engineering principles for making interfaces feel polished. Use when building UI components, reviewing frontend code, implementing animations, hover states, shadows, borders, typography, micro-interactions, enter/exit animations, or any visual detail work. Triggers on UI polish, design details, "make it feel…

4 1mo ago A 96 tokens

DinanathDash/Envault

Skill Claude CodeCodex

Guide for implementing smooth, native-feeling animations using React's View Transition API ( component, addTransitionType, and CSS view transition pseudo-elements). Use this skill whenever the user wants to add page transitions, animate route changes, create shared element animations, animate enter/exit of components…

4 1mo ago A 127 tokens

netresearch/enterprise-readiness-skill

Skill Claude CodeCodex

Use when evaluating projects for production or enterprise readiness, implementing supply chain security (SLSA, cosign, SBOMs, pnpm), hardening CI/CD pipelines, establishing quality gates (TYPO3: CI matrix PHP 8.2-8.5 x TYPO3 12.4/13.4/14.3 LTS), pursuing OpenSSF Best Practices Badge (Passing/Silver/Gold) or OSPS…

4 3d ago A 111 tokens

web-app-security

85

parousia8888/web-app-security-skill

Skill Claude CodeCodex

End-to-end security program for a web app — scope/authorization gate, frontend exposure reduction, API security (IDOR/BOLA, brute force, rate limiting, race conditions), LLM security (prompt injection, jailbreak, cost abuse), OAuth/OIDC identity, server-side code audit, database isolation, supply chain (SBOM/SCA/SRI)…

4 3d ago A 225 tokens original MIT

secure-auth

86

Wishmakingfairy/vibecheck

Skill Claude CodeCodex

This skill should be used when the user asks to "add authentication", "secure login", "implement rate limiting", "JWT best practices", "session security", or "OAuth setup". Teaches authentication hardening patterns.

4 5mo ago A 47 tokens original MIT

secure-keys

87

Wishmakingfairy/vibecheck

Skill Claude CodeCodex

This skill should be used when the user asks to "secure my API keys", "handle secrets safely", "fix exposed key", "environment variables setup", or "rotate compromised keys". Teaches secure secret management patterns per framework.

4 5mo ago A 50 tokens original MIT

security-scan

88

Wishmakingfairy/vibecheck

Skill Claude CodeCodex

This skill should be used when the user asks to "run a security scan", "check for vulnerabilities", "security audit", "ship secure", "vibecheck scan", or "pre-deploy security check". Runs 156 automated security checks across 15 categories and produces a categorized vulnerability report.

4 5mo ago A 64 tokens original MIT

ch015-va

89

ch015/code-pentester

Skill Claude CodeCodex

Run CH015 vulnerability assessment workflows for source-code security architecture review, 8-dimension analysis, compliance checks, self-verification, evidence verification, and VA reporting.

4 14d ago A 37 tokens original MIT

ch015-verifier

90

ch015/code-pentester

Skill Claude CodeCodex

Run CH015 adversarial verification workflows to independently validate security reports, recheck file-line evidence, find false positives, severity errors, missed findings, and dependencies.

4 14d ago A 37 tokens original MIT

ch015-feedback

91

ch015/code-pentester

Skill Claude CodeCodex

Run CH015 security design review workflows for PRDs and specs to produce security opinions or review findings mapped to standards and regulatory requirements.

4 14d ago A 30 tokens original MIT

HermeticOrmus/LibreSecOps-Claude-Code

Skill Claude CodeCodex

Threat hunting is the proactive, analyst-driven search for threats that have evaded automated detection. Unlike detection engineering (which builds rules that fire automatically), hunting is a human-led investigation that uses hypotheses, data analysis, and domain expertise to find adversary activity that does not…

4 3mo ago A 0 tokens original MIT

crypto-algorithms

93

HermeticOrmus/LibreSecOps-Claude-Code

Skill Claude CodeCodex

Skill "crypto-algorithms" from HermeticOrmus/LibreSecOps-Claude-Code, covering crypto algorithms, knowledge base, the algorithm decision tree, key size guidelines (2025+) and modes of operation (symmetric encryption).

4 3mo ago A 0 tokens original MIT

assay

95

chawdamrunal/assay

Skill Claude CodeCodex

Pre-install security advisor. Activate when the user mentions installing a Claude Code plugin, MCP server, or any third-party agent tool. Offer to run an Assay scan against the target before they install.

4 1mo ago A 43 tokens original Apache-2.0

jaskaranhundal/usap-skills

Skill Claude CodeCodex

USAP agent skill for Security Requirements Review. Use for proactive analysis of design documents — POA&M, PRDs, architecture docs, requirements specs — to extract security gaps before any alerts fire.

4 19d ago A 45 tokens original Apache-2.0