Detecting Supply Chain Attacks In CI CD

mukul975/detecting-supply-chain-attacks-in-ci-cd · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 1.6 KB
  • 📁scripts
  • ⚙️agent.py 7.4 KB
  • 📄LICENSE 11.0 KB

Related

  1. Securing Github Actions Workflows · mukul975 bundle
    Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation by pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, preventing script injection, and implementing workflow change controls.
    24.6k
    repo stars
  2. Agentic Actions Auditor · trailofbits bundle
    Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations, detecting attack vectors where attacker-controlled input reaches AI agents in CI/CD pipelines.
    6k
    repo stars
  3. Implementing Supply Chain Security With In Toto · mukul975 bundle
    Verify container image integrity across CI/CD pipelines using the in-toto framework to generate and check cryptographically signed attestations.
    24.6k
    repo stars
  4. Opensource Pipeline · affaan-m
    Fork, sanitize, and package private projects for safe public release through a three-stage pipeline.
    226k
    repo stars
  5. Secrets · tinh2
    Audits codebases for leaked secrets and hardcoded credentials, generates .env templates, configures secrets management with AWS Secrets Manager, Vault, Doppler, or GCP Secret Manager, sets up credential rotation, and integrates secrets into CI/CD pipelines via OIDC federation.
    13
    repo stars
  6. Scanning Docker Images With Trivy · mukul975 bundle
    Scan Docker images for vulnerabilities, misconfigurations, secrets, and license violations using Trivy, with CI/CD integration and policy enforcement.
    24.6k
    repo stars

Frequently asked questions

How do I install the Detecting Supply Chain Attacks In CI CD skill?

Run npx skillmds add mukul975/detecting-supply-chain-attacks-in-ci-cd in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the Detecting Supply Chain Attacks In CI CD skill do?

Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. It is listed under DevOps & Infra, Security, CI/CD, Secure Coding on SkillMD.

Is Detecting Supply Chain Attacks In CI CD safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with Detecting Supply Chain Attacks In CI CD?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is Detecting Supply Chain Attacks In CI CD free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published Detecting Supply Chain Attacks In CI CD?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.