Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Devsecops Pro

ASecurity

Embed security into DevOps — pipeline security gates, guardrails, and culture that ships fast and safe.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsrustgoexpressrailsdevopsci/cdsecurity

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill devsecops-pro --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Devsecops Pro?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Devsecops Pro
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-devsecops-pro/badge)](https://www.skillsdirectory.com/skills/aicodedecode-devsecops-pro)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: devsecops-pro
description: Embed security into DevOps — pipeline security gates, guardrails, and culture that ships fast and safe.
category: security
---

## Overview

DevSecOps makes security part of how software is built and shipped, not a gate at the end: automated checks in the pipeline, secure defaults in platforms, and developers empowered with fast feedback. The goal is not "more security process" but security at the speed of delivery — where the secure path is the easy path.

This skill covers the practice: pipeline security architecture, choosing the right checks at the right stages, platform guardrails, and the cultural work that makes it stick.

Measure developer friction as carefully as security findings: a pipeline that adds 40 minutes and cryptic failures will be routed around. The best DevSecOps programs obsess over signal quality and speed — fast, accurate, actionable feedback that developers trust.

## When to use

- Designing secure CI/CD pipelines from scratch or maturing existing ones.
- Selecting and tuning SAST/SCA/secrets/DAST/IaC checks per pipeline stage.
- Building platform guardrails (golden paths, policy as code).
- Reducing security review bottlenecks without reducing assurance.
- Measuring DevSecOps maturity and developer experience.

## Core concepts

- **Shift left with guardrails.** Catch issues early (pre-commit, PR) where fixes are cheap — but keep early checks fast and high-signal, or developers disable them.
- **Pipeline stage mapping.** Pre-commit: secrets, lint; PR: SAST, SCA, IaC scan; build: image scan, signing; deploy: admission policy, DAST; runtime: monitoring. Right check, right stage.
- **Policy as code.** Admission and deployment policies versioned, tested, and enforced automatically — security requirements expressed as executable rules, not wiki pages.
- **Golden paths.** Paved-road pipelines and templates with security built in (scanning, signing, hardened bases) — teams get secure defaults by choosing the standard path.
- **Secrets in CI/CD.** Pipeline secrets vaulted with short-lived, scoped credentials (OIDC federation to cloud, not static tokens); masked in logs; rotated automatically.
- **Pipeline as attack surface.** CI/CD systems run with broad credentials and execute untrusted code — harden runners (ephemeral, isolated), protect pipeline definitions (CODEOWNERS, required reviews), and audit pipeline permissions.
- **Risk-based gating.** Block the pipeline only on high-confidence, high-severity findings; warn-and-track the rest. Every false-positive block teaches developers to bypass the gate.
- **Security champions.** Embedded developers with extra training and a direct line to security — they scale the security team and translate both directions.

- **Pipeline artifact attestation.** Attest what each pipeline stage did (tests run, scans passed, approvals given) so deployments are verifiable, not just trusted.
- **Dependency firewalling.** Proxy package registries and block known-malicious packages at install time — the pipeline pulling compromised packages is a supply-chain incident.

## Practical workflow

1. **Map the pipeline:** inventory every stage, runner, secret, and third-party action/integration. You cannot secure what you have not mapped — and pipelines accumulate cruft fast.
2. **Establish the golden path:** a standard pipeline template with scanning, signing, and policy checks built in. New services start here by default.
3. **Tune checks per stage:** enable fast high-signal checks at PR time; deeper scans at build; runtime verification post-deploy. Measure and optimize check duration relentlessly.
4. **Harden the platform:** ephemeral isolated runners, OIDC-based cloud auth, pipeline-definition change control, least-privilege pipeline identities, and audit logging of all pipeline activity.
5. **Build the feedback loop:** findings routed to developers with context and fix guidance (not raw scanner dumps); SLA by severity; security office hours, not just tickets.
6. **Measure both sides:** security metrics (findings per release, MTTR, gate-block rate) and developer metrics (pipeline duration, false-positive block rate, satisfaction). Optimize the pair.

### Quick wins

- Replace static cloud credentials in CI with OIDC federation this quarter
- Pin all third-party pipeline actions to SHAs and review their permissions
- Measure security-check duration per pipeline; optimize the slowest

### Sustaining the practice

- Review gate-block accuracy monthly; tune rules with high false-positive blocks
- Audit pipeline permissions and third-party actions quarterly
- Refresh golden-path templates as stacks and threats evolve
- Run the security-champions program with real investment (time, training, recognition)

### Metrics that prove it works

- Security findings per release trending down; MTTR by severity
- Pipeline duration impact of security checks (target: minimal)
- False-positive block rate (target: near zero — blocks must be trustworthy)
- % of services on the golden-path pipeline

## Common pitfalls

- **Security as a tollbooth.** Slow, noisy gates get bypassed with executive air cover. Speed and signal quality are security requirements.
- **Untrusted pipeline code.** Third-party actions and plugins with broad permissions are supply-chain risk. Pin versions, review permissions, prefer first-party.
- **Static pipeline credentials.** Long-lived cloud keys in CI variables leak constantly. OIDC federation eliminates the secret entirely.
- **Blocking on low-confidence findings.** Every false block erodes trust in all blocks. Gate only on what you would defend in an argument with the team.
- **No pipeline audit trail.** When a bad deploy happens, you need to know what ran, with whose credentials, from which commit. Log it all.
- **Shadow pipelines.** Teams running their own CI outside the standard platform bypass every control. Discover and migrate, with empathy for why they left.
- **Security team as gatekeepers, not enablers.** The cultural failure mode: developers see security as the team that says no. Champions and office hours fix this.
- **Measuring scans instead of outcomes.** "We run 5 scanners" is input. Findings fixed before production and incidents prevented are output.
- **Pipeline admin sprawl.** Everyone with repo admin can modify pipeline definitions. Restrict pipeline-change permissions like production access.
- **Security checks only on main.** Scanning only the default branch misses PR-time prevention. Shift the fast checks left to every pull request.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →