AgentSecOps/SecOpsAgentKit

DirSkills catalogs 25 skills from this repository, across 4 categories: AI Engineering, Automation, DevOps, Quality.

204 stars39 forksView on GitHub
πŸ”
45m ago

Api Spectral

Api Spectral lints OpenAPI, AsyncAPI, and Arazzo specifications for security issues and design flaws. Use it to enforce API governance, OWASP API Security Top 10 checks, and custom rules in CI/CD pipelines.
Quality
20439
πŸ›‘οΈ
45m ago

Bandit Python SAST

Bandit Python SAST scans Python code for security vulnerabilities and anti-patterns using Bandit. Use it to find hardcoded secrets, injection risks, weak crypto, and other issues, then generate severity-based reports for remediation and CI/CD checks.
Quality
20439
πŸ›‘οΈ
45m ago

Black Duck SCA

Black Duck SCA scans dependencies for vulnerabilities, license compliance risks, and supply chain threats. Use it to assess open source components, map findings to CVE/CWE/OWASP, and integrate checks into CI/CD.
DevOps
20439
πŸ›‘οΈ
45m ago

Checkov IaC Security

Checkov IaC Security scans Terraform, CloudFormation, Kubernetes, Dockerfiles, and ARM templates for misconfigurations, secrets, and compliance issues. Use it to validate infrastructure before deployment and generate audit reports.
DevOps
20439
πŸ›‘οΈ
45m ago

Container Vulnerability Scanning

Container Vulnerability Scanning uses Grype to scan images, filesystems, and SBOMs for known vulnerabilities. Use it in CI/CD or security reviews to prioritize fixes with CVSS, EPSS, and CISA KEV data.
Quality
20439
πŸ›‘οΈ
45m ago

DefectDojo Vulnerability Management

DefectDojo Vulnerability Management aggregates scanner findings into DefectDojo for deduplication, SLA tracking, and compliance reporting. Use it to manage vulnerability backlogs and remediation across products, teams, and pipelines.
DevOps
20439
πŸ•΅οΈ
45m ago

Ffuf

Ffuf is a fast web fuzzer for DAST tasks like directory enumeration, parameter fuzzing, and virtual host discovery. Use it to find hidden endpoints, test auth forms, and scan for exposed backup or sensitive files.
Quality
20439
🐳
45m ago

Hadolint Dockerfile Linting

Hadolint Dockerfile Linting scans Dockerfiles for security misconfigurations, anti-patterns, and CIS Docker Benchmark issues. Use it in development or CI to catch unsafe instructions and get remediation guidance before images are built.
DevOps
20439
πŸ”
45m ago

Hashcat Password Recovery

Hashcat Password Recovery supports authorized password auditing, forensic recovery, and security research on password hashes. Use it to identify hash types, run cracking attacks, and report password policy weaknesses.
Quality
20439
πŸ›‘οΈ
45m ago

LinPEAS Privilege Escalation

LinPEAS Privilege Escalation automates Linux post-exploitation enumeration to find SUID/SGID binaries, sudo misconfigurations, writable service files, credentials, and kernel exposure. Use it after initial access on an authorized Linux target to identify escalation paths.
Automation
20439
πŸ›‘οΈ
45m ago

Metasploit Penetration Testing

Metasploit Penetration Testing provides structured workflows for authorized vulnerability validation, exploit development, and post-exploitation in controlled environments. Use it when testing defenses, confirming impact, or running scoped penetration tests.
Quality
20439
πŸ›‘οΈ
45m ago

Mitmproxy API Security Testing

Mitmproxy API Security Testing intercepts, modifies, and replays HTTP(S) traffic for API security testing. Use it to inspect app traffic, debug mobile or thick clients, and automate checks with Python scripts.
Quality
20439
πŸ•ΈοΈ
45m ago

Netcat Network Utility

Netcat Network Utility reads and writes data across TCP/UDP connections for connectivity checks, banner grabbing, file transfers, and shell setups. Use it for authorized network testing and basic service enumeration.
Automation
20439
πŸ›‘οΈ
45m ago

Nuclei DAST

Nuclei DAST scans web apps, APIs, and infrastructure with template-based checks for CVEs, OWASP issues, and misconfigurations. Use it for fast vulnerability scanning, CI/CD security checks, and custom templates.
Quality
20439
πŸ›‘οΈ
45m ago

OT Security Assessment

OT Security Assessment follows a two-stage process to discover OT/ICS devices and protocols, then assess vulnerabilities using online sources and Metasploit. Use it for authorized industrial network assessments, protocol enumeration, and IEC 62443-aligned checks.
Quality
20439
πŸ›‘οΈ
45m ago

OWASP ZAP DAST

OWASP ZAP DAST runs passive and active security scans against web applications and APIs. Use it to find runtime issues like XSS, SQL injection, auth flaws, and other OWASP Top 10 risks, including in CI/CD pipelines.
Quality
20439
πŸ”Ž
45m ago

Osquery Forensics

Osquery Forensics uses SQL queries to inspect processes, network connections, files, users, and persistence on Linux, macOS, and Windows. Use it for incident response, threat hunting, and collecting forensic evidence from endpoints.
Quality
20439
πŸ›‘οΈ
45m ago

Policy OPA

Policy OPA enforces security and compliance rules with Open Policy Agent and Rego. Use it to validate Kubernetes admission policies, audit configuration drift, and add policy checks to CI/CD pipelines.
DevOps
20439
πŸ›‘οΈ
45m ago

SecOps Agent Kit

SecOps Agent Kit provides workflows, scripts, and templates for security operations tasks in Claude Code. Use when scanning, validating, remediating, or documenting security findings in SDLC and CI/CD contexts.
AI Engineering
20439
πŸ”
45m ago

Secrets Detection With Gitleaks

Secrets Detection With Gitleaks scans git repositories and codebases for hardcoded passwords, API keys, tokens, and credentials. Use it to audit code, add pre-commit protection, and integrate secret checks into CI/CD or history cleanup workflows.
DevOps
20439
πŸ›‘οΈ
45m ago

Semgrep SAST

Semgrep SAST scans code for security vulnerabilities, maps findings to OWASP Top 10 and CWE, and supports secure code review. Use it for PR checks, custom rules, and CI/CD security gates.
Quality
20439
πŸ›‘οΈ
45m ago

Sigma Detection Engineering

Sigma Detection Engineering creates, validates, and converts Sigma rules for security monitoring across multiple SIEM platforms. Use it for detection-as-code, threat hunting queries, and MITRE ATT&CK mapping.
Quality
20439
πŸ›°οΈ
45m ago

TShark Network Analysis

TShark Network Analysis captures and inspects network packets from the command line for security investigations, forensic work, and protocol troubleshooting. Use it to filter traffic, analyze captures, and extract network artifacts.
Automation
20439
πŸ›‘οΈ
45m ago

Trivy Scanning

Trivy Scanning finds CVEs, secrets, IaC misconfigurations, and license risks in containers, filesystems, and dependencies. Use it to scan projects, generate SBOMs, and integrate vulnerability checks into CI/CD.
Quality
20439
πŸ•΅οΈ
45m ago

Velociraptor Incident Response

Velociraptor Incident Response uses VQL to collect endpoint evidence, hunt threats, and analyze forensic artifacts across multiple hosts. Use it for incident response, live triage, and custom artifact collection.
Automation
20439