sbom-syft
Generate Software Bill of Materials (SBOM) for container images and filesystems using Syft. Supports 28+ ecosystems, multiple formats like CycloneDX and SPDX, and integration into CI/CD for supply chain security.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
113 skills found
Generate Software Bill of Materials (SBOM) for container images and filesystems using Syft. Supports 28+ ecosystems, multiple formats like CycloneDX and SPDX, and integration into CI/CD for supply chain security.
Automate regulatory compliance testing for GDPR, CCPA, HIPAA, SOC2, and PCI-DSS to ensure legal adherence, prepare for audits, and secure sensitive data.
Comprehensive secure coding guidelines for 15+ languages, covering OWASP Top 10, infrastructure security, and best practices to identify vulnerabilities in code, configurations, and cloud setups.
Scans Solana programs (native/Anchor) for 6 critical vulnerabilities, including arbitrary CPI, improper PDA validation, and missing ownership checks, providing detailed fix recommendations.
AI-powered secrets and credentials scanner. Detects hardcoded API keys, passwords, and sensitive data in your codebase with contextual analysis to reduce false positives.
Systematic security assessment using STRIDE threat modeling, OWASP top 10 review, and secure coding practices for code, architecture, and infrastructure.
Analyze source code for security vulnerabilities based on OWASP Top 10 guidelines and suggest remediation strategies.
Perform automated security audits, bug detection, and code quality assessments on local branch diffs using a structured, checklist-driven verification process.
Automated security validation, RLS enforcement, OWASP compliance, and vulnerability scanning for AI-assisted development workflows.
Security-first vetting protocol for AI agent skills. Detects red flags like credential theft, obfuscated code, and unauthorized data exfiltration before installation.
Run Semgrep static analysis scans on codebases using parallel subagents, multi-language detection, and Pro-enabled cross-file taint tracking.
Automated tool and MCP server discovery for Claude Code. Searches 17+ registries to find relevant skills, plugins, and tools before planning or when errors occur.