Skip to content

akoita/security

v0.5.4

Project-agnostic security skills for repository audits, diff review, deterministic scanning, supply chain, threat modeling, smart contracts, and AI systems.

security-supply-chain

Harden a project's software supply chain: audit CI/CD workflows, pin actions to commit SHAs, control package-manager and install-script risk, enforce lockfiles and release cooldowns, emit an SBOM, sign artifacts and produce build provenance, and work through the repository checklists and regulatory obligations that follow (OpenSSF Scorecard, OSPS Baseline, EU CRA, NIST SSDF, OWASP ASVS and SAMM). Use when reviewing workflows, dependency intake, release pipelines, or compliance readiness. Do not use for application code vulnerabilities (use security-audit for a repository audit or security-review for a diff), for running the general scanner toolchain (use security-scan), or for LLM, agent, and MCP risk (use security-ai).

Read SKILL.md at the source

Pinned to revision 6335fa80c2f6, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.