sbom-syft
Generate Software Bill of Materials (SBOM) for container images and filesystems using Syft. Supports 28+ ecosystems, multiple formats like CycloneDX and SPDX, and integration into CI/CD for supply chain security.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
154 skills found
Generate Software Bill of Materials (SBOM) for container images and filesystems using Syft. Supports 28+ ecosystems, multiple formats like CycloneDX and SPDX, and integration into CI/CD for supply chain security.
Analyze GitHub repository structure, documentation, dependencies, and contributor patterns for codebase health and development insights.
Automated security auditing for project dependencies. Scans package files (npm, pip, maven, etc.) for vulnerabilities, CVEs, and license issues, offering automated fix suggestions and integration for secure deployment workflows.
Map the attack surface of smart contract codebases by identifying and categorizing state-changing entry points.
Perform systematic security audits, vulnerability scanning, and risk assessments with OWASP-aligned methodology for robust code protection.
Analyze project structures, dependencies, and patterns using parallel agent execution to generate comprehensive context documentation for rapid codebase onboarding and AI-assisted development.
Manage and build packages for Open Build Service (OBS) projects, ensuring reproducible builds from source code.
Audit AI skills for security vulnerabilities including prompt injection, hidden instructions, tool misuse, and data exfiltration risks.
Analyze Kubernetes controller code to generate contract-compliant dependency graph artifacts for the Kamera coverage strategy.
A systematic code auditing framework for identifying technical debt, security vulnerabilities, dead code, and code quality issues in software projects.
DevOps and platform engineering patterns: Kubernetes, Terraform, GitOps, CI/CD, observability, incident response, and cloud-native ops.
Retrieve current, source-backed technical information using MCP tools to resolve queries about libraries, APIs, SDKs, and evolving tech ecosystems.