sbom-syft
Generate Software Bill of Materials (SBOM) for container images and filesystems using Syft. Supports 28+ ecosystems, multiple formats like CycloneDX and SPDX, and integration into CI/CD for supply chain security.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
96 skills found
Generate Software Bill of Materials (SBOM) for container images and filesystems using Syft. Supports 28+ ecosystems, multiple formats like CycloneDX and SPDX, and integration into CI/CD for supply chain security.
Bootstrap CISO Assistant environments by guiding users through organizational structure setup, framework selection, and initial risk assessment configuration using MCP tools.
Analyze C++ code for real-time safety violations including heap allocations, locks, blocking calls, and non-deterministic operations in high-performance audio threads.
Detects indirect prompt injection and goal hijacking in AI agents by evaluating how they process external content like RAG, documents, and web data.
Perform deep security analysis on codebases using CodeQL for interprocedural data flow, taint tracking, and automated vulnerability detection across multiple languages.
Defense-in-depth protection for Claude Code. Manage security hooks to block dangerous commands, enforce file access controls, and protect sensitive paths across global or project-specific scopes.
Production-grade Bash scripting assistant enforcing safety, maintainability, and ShellCheck compliance. Includes automated headers, pattern enforcement, and risk-aware file modification checkpoints.
Intelligent pattern selection for Fabric CLI, automatically choosing from 242+ specialized prompts for threat modeling, data analysis, summarization, and content creation.
Run Semgrep static analysis scans on codebases using parallel subagents, multi-language detection, and Pro-enabled cross-file taint tracking.
Expert Swift code review for macOS/iOS. Detects memory leaks, threading bugs, concurrency issues, and accessibility gaps using parallel analysis agents.
Create, test, and validate custom Semgrep rules for security vulnerabilities and code pattern detection.
Expert Kokoro TTS implementation skill for real-time, secure, and offline voice synthesis in JARVIS-style assistants. Features streaming output, prosody control, and performance-optimized audio generation.