tag

devsecops

19 indexed skills · max 10 per page

skills (19)

implementing-devsecops-security-scanning

mukul975/Anthropic-Cybersecurity-Skills · implementing-devsecops-security-scanning

0

Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Activates for requests involving DevSecOps pipeline setup, automated security scanning in CI/CD, SAST/DAST/SCA integration, or shift-left security implementation.

implementing-semgrep-for-custom-sast-rules

mukul975/Anthropic-Cybersecurity-Skills · implementing-semgrep-for-custom-sast-rules

0

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

detecting-aws-credential-exposure-with-trufflehog

mukul975/Anthropic-Cybersecurity-Skills · detecting-aws-credential-exposure-with-trufflehog

0

Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.

implementing-policy-as-code-with-open-policy-agent

mukul975/Anthropic-Cybersecurity-Skills · implementing-policy-as-code-with-open-policy-agent

0

This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in development, and integrating policy evaluation into deployment pipelines.

securing-github-actions-workflows

mukul975/Anthropic-Cybersecurity-Skills · securing-github-actions-workflows

0

This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes.

performing-container-image-hardening

mukul975/Anthropic-Cybersecurity-Skills · performing-container-image-hardening

0

This skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure production-ready images.

implementing-runtime-application-self-protection

mukul975/Anthropic-Cybersecurity-Skills · implementing-runtime-application-self-protection

0

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.

implementing-code-signing-for-artifacts

mukul975/Anthropic-Cybersecurity-Skills · implementing-code-signing-for-artifacts

0

This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment pipelines.

implementing-infrastructure-as-code-security-scanning

mukul975/Anthropic-Cybersecurity-Skills · implementing-infrastructure-as-code-security-scanning

0

This skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts before deployment, establishing policy-based governance, and integrating IaC scanning into CI/CD pipelines to prevent insecure cloud resource provisioning.

performing-container-security-scanning-with-trivy

mukul975/Anthropic-Cybersecurity-Skills · performing-container-security-scanning-with-trivy

0

Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.

prevpage 1 / 2next