🛠️
DevOpsTypeScript

CICD Attacks

by CyberStrikeus

CICD Attacks is a DevOps skill for Claude Code, published by CyberStrikeus in CyberStrike.

1.7K stars269 forkson CyberStrikeus/CyberStrikeAdded 2026/08/12+4% in starsRepository updated 2026/08/12
aiai-agentai-securitybug-bountycybersecuritydevsecopsethical-hackinghackinghacking-toolllmmcpmcp-servermitre-attackoffensive-securityowasppenetration-testingpentestred-teamsecuritysecurity-tools
Install in seconds
Install CICD Attacks
Copy CICD Attacks into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/CyberStrikeus/CyberStrike/tree/main/.cyberstrike/skill/cicd-attacks ~/.claude/skills/cicd-attacks

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/CyberStrikeus/CyberStrike.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
.cyberstrike/skill/cicd-attacks/SKILL.md in CyberStrikeus/CyberStrike
Installs to
~/.claude/skills/cicd-attacks
Collection
One of 51 skills cataloged from this repository
Category
DevOps798 skills

What CICD Attacks does

CICD Attacks describes methods for extracting secrets, injecting pipeline steps, and modifying CI/CD workflows in GitHub, Jenkins, or GitLab. Use it when assessing pipeline exposure or validating CI/CD security controls.

CICD Attacks is cataloged under DevOps on DirSkills. CICD Attacks comes from a repository tagged ai, ai-agent, ai-security, bug-bounty and cybersecurity.

Documentation

README

CI/CD Pipeline Attack Methodology

CI/CD pipeline attacks target the software delivery infrastructure to extract secrets, inject malicious code, and establish persistence. After gaining access to GitHub, Jenkins, or GitLab, these tools extract stored credentials, inject pipeline steps for secret exfiltration, and manipulate workflow configurations.

Prerequisites

  1. CI/CD access — API token, personal access token, or service account credentials
  2. Python packagespip3 install requests
  3. API access — Valid token with appropriate scopes (repo, admin, workflow)

This is the opening of the README. Read the full README on GitHub.

Frequently asked about CICD Attacks

  • What else does CyberStrikeus publish alongside CICD Attacks?

    CICD Attacks is one of 51 skills that DirSkills catalogs from CyberStrikeus/CyberStrike, the repository it ships in. Its siblings there include AMI Age Compliance, AMI Encryption Check and AMI Naming Convention Compliance. Each one is a separate skill with its own page in this directory, installs the same way CICD Attacks does, and is maintained by CyberStrikeus in that same repository. The rest of the collection is listed on the CyberStrikeus/CyberStrike page.

  • How does CICD Attacks compare to other DevOps skills?

    CICD Attacks ranks #299 by stars among the 798 DevOps skills in this catalog. The most-starred ones next to it are Backend Patterns, API Connector Builder and Migration. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of CICD Attacks against them. Open each page to compare what they document and how they install.

More from CyberStrikeus/CyberStrike

CICD Attacks is one of 51 skills cataloged on DirSkills from CyberStrikeus/CyberStrike.

See all 51 skills