policy as code skills

89 tagged policy as code, measured the same way as everything else here.

Browse within: AI Safety 61agent-governance 60credentials 60python 60agent-infrastructure 13devtools 13open-source 5

iac-checkov

01

AgentSecOps/SecOpsAgentKit

Skill Claude CodeCodex

Infrastructure as Code (IaC) security scanning using Checkov with 750+ built-in policies for Terraform, CloudFormation, Kubernetes, Dockerfile, and ARM templates. Use when: (1) Scanning IaC files for security misconfigurations and compliance violations, (2) Validating cloud infrastructure against CIS, PCI-DSS, HIPAA…

201 4mo ago A 123 tokens

design-guide

02

LF-Decentralized-Trust-labs/gitmesh

Skill Claude CodeCodex

GitMesh Agents UI design system. Invoke this skill when creating new components, modifying existing ones, adding pages or features to the frontend, styling UI elements, or when you need to understand the design language. Covers component creation, design tokens, typography, status/priority systems, composition…

145 3d ago A 83 tokens original Apache-2.0

ship

04

LF-Decentralized-Trust-labs/gitmesh

Skill Claude CodeCodexGemini CLI

GitMesh: Policy-as-Code Engine for Open Source AI Agent Orchestration.

145 3d ago A 0 tokens original Apache-2.0

design-impeccable

07

KeyArgo/custodian-kernel

Skill Claude CodeCodex

Anti-pattern detector and design rules for AI coding agents. Catches the specific mistakes AI makes when generating UI: gray text on color, nested cards, broken buttons, missing states. Use before shipping any frontend.

118 10d ago A 48 tokens original MIT

gnt-check-action

08

gnt-ai/gnt

Skill Claude CodeCodex

Check a side-effectful action against this organization's approved gnt rules before taking it, and stop on a blocked or needshuman verdict.

27 7d ago A 33 tokens original Apache-2.0

assay-golden-path

09

Rul1an/assay

Skill Claude CodeCodex

Drive Assay's install-to-evidence golden path and interpret its stdout and exit codes. Use when an agent must operate or diagnose Assay; do not use it to infer provider execution, external side effects, or a clean result from missing output.

9 yesterday A 56 tokens original MIT

guard-x402-payments

13

razel369/intentfence

Skill Claude CodeCodex

Guard an autonomous agent's x402 payment with the live IntentFence service before it signs. Use when an agent receives a PAYMENT-REQUIRED challenge, is about to pay an x402 endpoint, needs to enforce a USDC price ceiling or payee allowlist, or needs signed evidence that an exact Base USDC quote was checked. Also use…

2 1mo ago A 89 tokens original Apache-2.0

razel369/intentfence

Skill Claude CodeCodex

Inspect a public x402 endpoint before an agent pays it. Use when an agent discovers an unfamiliar x402 URL, needs to confirm that a live route returns a valid PAYMENT-REQUIRED challenge, wants to enforce a maximum Base USDC price or recipient allowlist, or needs signed readiness evidence without paying the target…

2 1mo ago A 70 tokens original Apache-2.0

screen-base-wallets

15

razel369/intentfence

Skill Claude CodeCodex

Screen a Base recipient before an autonomous USDC transfer or x402 payment. Use when an agent is about to pay a new Base address, send USDC, approve a Base merchant, evaluate counterparty risk, or enforce a pre-transaction AML, sanctions, phishing, mixer, or malicious-address policy. The check is fail-closed, costs…

2 1mo ago A 91 tokens original Apache-2.0

council-review

16

joymin5655/Agent

Skill Claude CodeCodex

Multi-vendor code review council — runs the Claude code-reviewer agent alongside external second opinions (codex, gemini) in parallel, then synthesizes with citation verification, source tagging, and disagreement surfacing. Optionally seats grok (--with-grok) and/or an OpenRouter free-tier advisor (--with-free) as…

2 7d ago A 143 tokens original MIT

harness-audit

17

joymin5655/Agent

Skill Claude CodeCodex

Agent-driven, read-only self-audit of the harness — run the machine integrity layer once as a dry-run, present a per-check pass/fail table, cite the P1-1 doc-reality result, and for any failure give root-cause + fix + backlog follow-up. Consumes the machine gates; it does not reimplement them. NOT for auditing a…

2 7d ago A 105 tokens original MIT

supervise

18

joymin5655/Agent

Skill Claude CodeCodex

Dispatch a multi-wave plan to specialist agents with audit + risk-area abort. Supports --auto-push, --auto-merge, --goal-mode for budgeted runs, --verify-blocking for a hard completion-claim gate. NOT for writing the plan itself (that is /spec), and NOT for a single small edit with no waves — just make the edit.

2 7d ago A 77 tokens original MIT