本文へ移動
cccskills
無料GitHub で公開

devsecops

DevSecOps skill for securing CI/CD pipelines, infrastructure as code, containers, Kubernetes, cloud deployments, secrets handling, dependency management, SAST/DAST/SCA, release gates, supply-chain controls, SBOMs, policy-as-code, and secure SDLC workflows. Use for pipeline hardening, deployment risk reviews, security automation, and remediation planning.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md1.6 KB
  • agents/openai.yaml185 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

DevSecOps

Operating Rules

  • Inspect the repo, pipeline files, deployment manifests, and current security tooling before recommending changes.
  • Prefer incremental controls that developers can keep using over heavyweight gates that will be bypassed.
  • Treat credentials, artifacts, build provenance, and deployment permissions as first-class risks.
  • Separate blocking release criteria from advisory findings.

Workflow

  1. Map the path from commit to production: source, build, test, artifact, deploy, runtime.
  2. Identify trust boundaries, identities, secrets, third-party actions/images, and artifact storage.
  3. Add or improve controls: least privilege, pinned dependencies, scanning, signing, SBOM, policy checks, and audit logging.
  4. Tune severity and false-positive handling so the pipeline remains usable.
  5. Verify with local checks, CI dry runs, or policy evaluation where available.

Baseline Controls

  • Pin third-party CI actions and container base images.
  • Use short-lived credentials or OIDC federation instead of long-lived secrets.
  • Run SAST/SCA/container/IaC checks with documented exception handling.
  • Generate SBOMs and preserve build provenance for release artifacts.
  • Enforce least-privilege deploy roles per environment.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

AI and LLM red-teaming skill for evaluating prompt injection, jailbreak, data exfiltration, tool abuse, agent hijack, RAG poisoning, model denial of service, and unsafe tool-use chains in Gemini, Claude, GPT, and open-weight models. Use to build evaluation harnesses, attack corpora, defensive guardrails, and red-team reports for AI systems you own or are authorized to test.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

API security automation skill for REST, GraphQL, gRPC, and WebSocket APIs. Covers OpenAPI/AsyncAPI ingestion, authenticated fuzzing, OWASP API Top 10 (BOLA, BFLA, mass assignment, SSRF), schema diffing, GraphQL introspection abuse, JWT and OAuth misuse, rate-limit and replay testing. Use to automate API assessments with safe, scoped, evidence-backed findings.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Assembly programming and low-level debugging skill for reading, writing, explaining, optimizing, and reviewing assembly across x86, x86-64, ARM, AArch64, RISC-V, calling conventions, ABI boundaries, inline assembly, disassembly, stack frames, registers, and binary-level behavior. Use for .s/.asm files, compiler output, reverse-engineering snippets, low-level performance, and crash analysis.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Bug bounty workflow skill for program scope mapping, recon-to-report automation, deduplication against prior submissions, and high-signal reporting on HackerOne, Bugcrowd, Intigriti, YesWeHack, and self-hosted programs. Use to organize bounty work end to end while staying inside program rules.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Assistant-behavior design skill for approximating a Claude-like analytical, careful, conversational style without claiming to be Claude or Anthropic. Use when the user asks to duplicate, emulate, adapt, or recreate a Claude-style "mythos" or persona for prompts, agent specs, writing style, reasoning discipline, safety posture, or UX behavior.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Cloud security posture skill for AWS, Azure, GCP, and multi-cloud. Covers IAM least-privilege, key and secret hygiene, network exposure, data protection, logging coverage, IaC scanning (Terraform, CloudFormation, Bicep, Pulumi), CSPM remediation, and landing-zone hardening. Use for misconfig discovery, IaC review, and automated drift-and-fix workflows on cloud accounts you own.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Garyson26 のスキルをすべて見る

このスキルの問題を報告する