All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,878
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 601–624 of 26,878 skills
- Override UpstreamPromote a local `.apache-magpie-overrides/<skill>.md` into a PR against `apache/magpie`. Once it merges and the adopter upgrades, the override is redundant and the skill offers to remove it.Votes: 0GitHub stars: 108
- Isolated Setup VerifyCheck the secure agent setup against its checklist and report done, missing or partial for each item, with the evidence — paths, command output, versions. Covers Claude Code, Codex and Gemini CLI. Read-only.Votes: 0GitHub stars: 108
- Isolated Setup UpdateReport drift between the installed secure setup and the framework's current one — checkout, pinned tools, user-scope script copies, denial commands, MCP checkouts. Read-only: it surfaces diffs and the user decides.Votes: 0GitHub stars: 108
- Isolated Setup InstallWalk an adopter through the first-time install of the secure agent setup (sandbox, approval and clean-environment layers) for Claude Code, Codex or Gemini CLI. Interactive throughout; never runs sudo, edits a shell rc, or overwrites settings on its own.Votes: 0GitHub stars: 108
- Isolated Setup DoctorProbe the secure-agent setup for restrictions that block legitimate work — SSH agent reachability, port binding, containers, the scratch directory, the signing key, `gh` outside the sandbox, `prek` and `uv` inside it, the global git hook dir. Names the troubleshooting entry and settings fix for each. Read-only.Votes: 0GitHub stars: 108
- Tracker Stats DashboardGenerate a self-contained HTML dashboard of `<tracker>` repository statistics for security-team review.Votes: 0GitHub stars: 108
- Model VerifyCheck a published security model per repository: is it reachable via `AGENTS.md` → `SECURITY.md` at a named commit, and does it cover the minimum-bar sections? Proposes one fix per failing check (a PR for mechanical gaps, mail to `<governance-body>` for substantive ones).Votes: 0GitHub stars: 108
- Model UpdateRefresh a published security model from the project's decision history (tracker dispositions, advisories, canned responses). Proposes new known-non-finding entries (§1.15) and a model-gap list, regression-checked against past valid reports. Read-only on the tracker.Votes: 0GitHub stars: 108
- Model PrepareProduce a first security model for a project that has none: draft it with `<governance-body>` (draft-first, provenance-tagged), then land the model and its `AGENTS.md` → `SECURITY.md` chain as one PR per repository. Proposes; the maintainers decide.Votes: 0GitHub stars: 108
- Issue TriageClassify each `needs triage` tracker as VALID / DEFENSE-IN-DEPTH / INFO-ONLY / INVALID / PROBABLE-DUP / FIX-ALREADY-PUBLIC and, on confirmation, post a triage-proposal comment for the team. Read-only on tracker state. `--retriage` reopens a decided case after new activity.Votes: 0GitHub stars: 108
- Issue SyncSynchronize a security issue in <tracker> with the state of its GitHub discussion, the <security-list> mailing thread, and any <upstream> PRs that fix it. The skill gathers all relevant signals and proposes label / milestone / assignee / field / draft-email updates — applying only what the user has explicitly confirmed. Suggests the next step in the handling process and prints the CVE allocation link when a CVE is needed.Votes: 0GitHub stars: 108
- Issue InvalidateClose a tracker as invalid: label, closing comment, board archive, and — for `<security-list>` imports — a polite-but-firm reply draft to the reporter with the team's reasoning. No reporter outreach for trackers imported from a public PR.Votes: 0GitHub stars: 108
- Issue ImportImport new `<security-list>` reports into `<tracker>`: find threads not yet tracked, propose the imports (default: import unless rejected), create each tracker in `Needs triage`, and draft a receipt reply to the reporter. First step of the handling process.Votes: 0GitHub stars: 108
- Issue Import Via ForwarderSub-skill for reports relayed onto `<security-list>` by a broker (the ASF security team, a disclosure platform, a SOC) rather than sent by the reporter. Detects the relay, extracts the credit and the reporter-addressing rules through the adapters in `forwarders.enabled`, and hands the routing back. Never mutates the tracker.Votes: 0GitHub stars: 108
- Issue Import From ScanTriage a security scanner's multi-finding output (via a scan-format adapter; ASVS is the reference), bucket each finding, and apply only the operator's confirmed decisions. Publishes the report as a gist and can open a report-back PR.Votes: 0GitHub stars: 108
- Issue Import From PrOpen a tracker for a security-relevant fix that already exists as a public `<upstream>` PR, with no `<security-list>` report. The tracker lands in `Assessed` with scope, PR-state and remediation fields filled from the PR; pairs with `security-cve-allocate`.Votes: 0GitHub stars: 108
- Issue Import From MdOpen one or more `<tracker>` tracking issues from a markdown file containing a batch of security findings. Each finding becomes one tracker landing in the `Needs triage` board column. The file itself is the full report — there is no inbound reporter to reply to and no PR to inspect.Votes: 0GitHub stars: 108
- Issue FixFix a tracked security issue in a public `<upstream>` PR: sync the tracker, propose a plan, and on confirmation write the change, open the PR from the user's fork, and update the tracker. Public content never reveals the CVE or the security nature of the change.Votes: 0GitHub stars: 108
- Issue DeduplicateMerge two <tracker> tracking issues that describe the same root-cause vulnerability, preserving every reporter's credit, every mailing-list thread reference, and every independent attack-vector description. Updates the kept issue's body in place, closes the duplicate with the `duplicate` label, and regenerates the CVE JSON attachment so both finders land in `credits[]`.Votes: 0GitHub stars: 108
- Cve AllocateWalk a governance-authorised member through allocating a CVE for a tracker: allocate it through the `<cve-tool>` API when the tool supports it, else print the allocation link and title and take the allocated ID, then update the tracker (field, label, rollup, CVE JSON) and hand off to `security-issue-sync`.Votes: 0GitHub stars: 108
- Workflow Security AuditRead-only GitHub Actions workflow security audit for one repository, a repository set, or a whole GitHub org. Runs `zizmor` to surface injection vulnerabilities, excessive permissions, unpinned external actions, and self-hosted-runner fork-secret leaks. Produces a grouped, prioritised report; never edits workflows, opens PRs, or posts comments.Votes: 0GitHub stars: 108
- License Compliance AuditRead-only license compliance audit for one repository or checkout: LICENSE present, NOTICE complete when the declared license requires it, and source files carrying SPDX-License-Identifier headers consistent with that license. Produces a grouped report with proposed remedies for review; never modifies any file.Votes: 0GitHub stars: 108
- Flaky Test TriageRead-only flaky-test detection from GitHub Actions run history for one repository: parses run outcomes over a configurable window, computes per-job failure rates, and separates intermittent failures from deterministically broken ones. Produces a prioritised triage list without modifying tests, workflows, or tracker state.Votes: 0GitHub stars: 108
- Dependency License AuditRead-only license audit of a dependency tree. Detects the manager(s), resolves each dependency's license from ecosystem metadata, and classifies it against a configured policy (ASF A/B/X or allowlist), surfacing incompatible, forbidden, and unknown-license dependencies. Never modifies manifests or lock files.Votes: 0GitHub stars: 108