SkillMD SkillMD
Skills
All skills Official skills Leaderboard Saved
Categories
Coding & Dev Tools9772AI & ML5011DevOps & Infra2864Integrations & APIs2327Productivity2190Security1976 All categories →
Plugins Docs
menu-rounded
Skills Categories Plugins Docs My skills Saved
light-dark-mode
Profile My skills Saved Collections Edit profile Submit a skill
All Skills 25,791 ✦ Verified
Categories
AI & ML 5,011 Coding & Dev Tools 9,772 Data & Analytics 1,725 Design & Media 983 DevOps & Infra 2,864
CI/CD 307 Cloud Platforms 427 Containers & Kubernetes 165 Deployment & Release 376 Infrastructure as Code 94 Monitoring & Observability 234
Docs & Writing 1,294 Finance & Business 347 Integrations & APIs 2,327 Marketing & Growth 1,430 Product & Planning 1,037 Productivity 2,190 Research & Search 928 Security 1,976 Web & Frontend 1,639

Results for “syft”

5 skills
mukul975
scanning-container-images-with-grype
Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.
24.6k · bundle
More results
mukul975
integrating-sast-into-github-actions-pipeline
Integrates Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines, configuring automated code scanning, tuning rules, uploading SARIF results, and establishing quality gates that block merges on high-severity vulnerabilities.
24.6k · bundle
kk20300113-png
ship
Ship workflow: detect + merge base branch, run tests, review diff, bump VERSION, update CHANGELOG, commit, push, create PR. Use when asked to "ship", "deploy", "push to main", "create a PR", "merge and push", or "get it deployed". Proactively invoke this skill (do NOT push/PR directly) when the user says code is ready, asks about deploying, wants to push code up, or asks to create a PR. (gstack)
0 · bundle
mukul975
implementing-semgrep-for-custom-sast-rules
Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.
24.6k · bundle
mukul975
generating-and-analyzing-sboms
Generate CycloneDX and SPDX SBOMs from container images and filesystems, scan them for vulnerabilities with Grype, and sign attestations with Cosign for supply-chain trust.
24.6k · bundle
SKILLMD.com

The open registry of AI Agent Skills: safety-reviewed SKILL.md files for Claude, Cursor, Codex & 60+ agents.

$ npm i skillmds

Explore

All Skills Categories Agents Plugins New & Latest Leaderboard

Support

About Contact npm Terms Privacy

Learn

Docs Blog Stats FAQ Submit a Skill
© 2026 SkillMD.com Skills attributed to their authors under their original licenses.
SKILLMD