Detecting supply chain attacks in CI/CD - **name_fr:** Détection d'attaques supply chain dans CI/CD - **tl_en:** Audit GitHub Actions workflows and CI/CD configs for supply chain attack vectors - **tl_fr:** Auditer les workflows GitHub Actions et configs CI/CD contre les vecteurs d'attaque supply chain - **creator:** @mukul975 - **type:** Agent skill - **url:** https://github.com/mukul975/anthropic-cybersecurity-skills - **cat:** Security - **kws:** supply chain, ci/cd, github actions, dependency confusion, script injection, devsecops, audit - **license:** Apache-2.0 **Description EN:** Curated by Skill Harbor — a skill for scanning GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors: unpinned actions, script injection via workflow expressions, dependency confusion, and secrets exposure — using PyGithub and YAML parsing for the automated audit. Use when hardening CI/CD pipelines or investigating a possibly compromised build system. By @mukul975, listed here with credit to its creator. Honest caveats: read-only auditing — it finds problems, it doesn't fix them (pair it with the companion securing-github-actions-workflows skill for the remediation); needs Python 3.8+ with PyGithub, and read access to the repos or workflow files you audit. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — un skill pour analyser les workflows GitHub Actions et les configurations de pipelines CI/CD à la recherche de vecteurs d'attaque supply chain : actions non épinglées, injection de scripts via les expressions de workflows, confusion de dépendances et exposition de secrets — avec PyGithub et l'analyse YAML pour l'audit automatisé. À utiliser pour durcir des pipelines CI/CD ou enquêter sur un système de build possiblement compromis. Crédit : @mukul975. Bémols honnêtes : audit en lecture seule — il trouve les problèmes, il ne les corrige pas (combinez avec le skill compagnon securing-github-actions-workflows pour la remédiation) ; nécessite Python 3.8+ avec PyGithub et un accès en lecture aux dépôts ou fichiers de workflows soumis à l'audit. Non vérifié. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: Python 3.8+ with PyGithub and YAML parsing dependencies installed; read access to the repositories or workflow files to audit Install "Detecting supply chain attacks in CI/CD" for me. Give my agent the skill for auditing GitHub Actions workflows and CI/CD configs against supply chain attack vectors — unpinned actions, script injection, dependency confusion, secrets exposure Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-supply-chain-attacks-in-ci-cd/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install the Python dependencies, point the agent at the workflows to audit). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : Python 3.8+ avec PyGithub et les dépendances d'analyse YAML installées ; accès en lecture aux dépôts ou fichiers de workflows à auditer Installe-moi « Détection d'attaques supply chain dans CI/CD ». Donne à mon agent le skill d'audit des workflows GitHub Actions et configs CI/CD contre les vecteurs d'attaque supply chain — actions non épinglées, injection de scripts, confusion de dépendances, exposition de secrets Dépôt : https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-supply-chain-attacks-in-ci-cd/SKILL.md 1. Récupère le fichier SKILL.md du skill mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md et les scripts pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. installer les dépendances Python, indiquer à l'agent les workflows à auditer). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
Audit GitHub Actions workflows and CI/CD configs for supply chain attack vectors - **tl_fr:** Auditer les workflows GitHub Actions et configs CI/CD contre les vecteurs d'attaque supply chain - **creator:** @mukul975 - **type:** Agent skill - **url:** https://github.com/mukul975/anthropic-cybersecurity-skills - **cat:** Security - **kws:** supply chain, ci/cd, github actions, dependency confusion, script injection, devsecops, audit - **license:** Apache-2.0 **Description EN:** Curated by Skill Harbor — a skill for scanning GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors: unpinned actions, script injection via workflow expressions, dependency confusion, and secrets exposure — using PyGithub and YAML parsing for the automated audit. Use when hardening CI/CD pipelines or investigating a possibly compromised build system. By @mukul975, listed here with credit to its creator. Honest caveats: read-only auditing — it finds problems, it doesn't fix them (pair it with the companion securing-github-actions-workflows skill for the remediation); needs Python 3.8+ with PyGithub, and read access to the repos or workflow files you audit. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — un skill pour analyser les workflows GitHub Actions et les configurations de pipelines CI/CD à la recherche de vecteurs d'attaque supply chain : actions non épinglées, injection de scripts via les expressions de workflows, confusion de dépendances et exposition de secrets — avec PyGithub et l'analyse YAML pour l'audit automatisé. À utiliser pour durcir des pipelines CI/CD ou enquêter sur un système de build possiblement compromis. Crédit : @mukul975. Bémols honnêtes : audit en lecture seule — il trouve les problèmes, il ne les corrige pas (combinez avec le skill compagnon securing-github-actions-workflows pour la remédiation) ; nécessite Python 3.8+ avec PyGithub et un accès en lecture aux dépôts ou fichiers de workflows soumis à l'audit. Non vérifié. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: Python 3.8+ with PyGithub and YAML parsing dependencies installed; read access to the repositories or workflow files to audit Install "Detecting supply chain attacks in CI/CD" for me. Give my agent the skill for auditing GitHub Actions workflows and CI/CD configs against supply chain attack vectors — unpinned actions, script injection, dependency confusion, secrets exposure Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-supply-chain-attacks-in-ci-cd/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install the Python dependencies, point the agent at the workflows to audit). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : Python 3.8+ avec PyGithub et les dépendances d'analyse YAML installées ; accès en lecture aux dépôts ou fichiers de workflows à auditer Installe-moi « Détection d'attaques supply chain dans CI/CD ». Donne à mon agent le skill d'audit des workflows GitHub Actions et configs CI/CD contre les vecteurs d'attaque supply chain — actions non épinglées, injection de scripts, confusion de dépendances, exposition de secrets Dépôt : https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-supply-chain-attacks-in-ci-cd/SKILL.md 1. Récupère le fichier SKILL.md du skill mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md et les scripts pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. installer les dépendances Python, indiquer à l'agent les workflows à auditer). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- What
- Audit GitHub Actions workflows and CI/CD configs for supply chain attack vectors - **tl_fr:** Auditer les workflows GitHub Actions et configs CI/CD contre les vecteurs d'attaque supply chain - **creator:** @mukul975 - **type:** Agent skill - **url:** https://github.com/mukul975/anthropic-cybersecurity-skills - **cat:** Security - **kws:** supply chain, ci/cd, github actions, dependency confusion, script injection, devsecops, audit - **license:** Apache-2.0 **Description EN:** Curated by Skill Harbor — a skill for scanning GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors: unpinned actions, script injection via workflow expressions, dependency confusion, and secrets exposure — using PyGithub and YAML parsing for the automated audit. Use when hardening CI/CD pipelines or investigating a possibly compromised build system. By @mukul975, listed here with credit to its creator. Honest caveats: read-only auditing — it finds problems, it doesn't fix them (pair it with the companion securing-github-actions-workflows skill for the remediation); needs Python 3.8+ with PyGithub, and read access to the repos or workflow files you audit. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — un skill pour analyser les workflows GitHub Actions et les configurations de pipelines CI/CD à la recherche de vecteurs d'attaque supply chain : actions non épinglées, injection de scripts via les expressions de workflows, confusion de dépendances et exposition de secrets — avec PyGithub et l'analyse YAML pour l'audit automatisé. À utiliser pour durcir des pipelines CI/CD ou enquêter sur un système de build possiblement compromis. Crédit : @mukul975. Bémols honnêtes : audit en lecture seule — il trouve les problèmes, il ne les corrige pas (combinez avec le skill compagnon securing-github-actions-workflows pour la remédiation) ; nécessite Python 3.8+ avec PyGithub et un accès en lecture aux dépôts ou fichiers de workflows soumis à l'audit. Non vérifié. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: Python 3.8+ with PyGithub and YAML parsing dependencies installed; read access to the repositories or workflow files to audit Install "Detecting supply chain attacks in CI/CD" for me. Give my agent the skill for auditing GitHub Actions workflows and CI/CD configs against supply chain attack vectors — unpinned actions, script injection, dependency confusion, secrets exposure Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-supply-chain-attacks-in-ci-cd/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install the Python dependencies, point the agent at the workflows to audit). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : Python 3.8+ avec PyGithub et les dépendances d'analyse YAML installées ; accès en lecture aux dépôts ou fichiers de workflows à auditer Installe-moi « Détection d'attaques supply chain dans CI/CD ». Donne à mon agent le skill d'audit des workflows GitHub Actions et configs CI/CD contre les vecteurs d'attaque supply chain — actions non épinglées, injection de scripts, confusion de dépendances, exposition de secrets Dépôt : https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-supply-chain-attacks-in-ci-cd/SKILL.md 1. Récupère le fichier SKILL.md du skill mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md et les scripts pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. installer les dépendances Python, indiquer à l'agent les workflows à auditer). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- Cost
- Free
- Needs
- Python 3.8+ with PyGithub and YAML parsing dependencies installed; read access to the repositories or workflow files to audit
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — a skill for scanning GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors: unpinned actions, script injection via workflow expressions, dependency confusion, and secrets exposure — using PyGithub and YAML parsing for the automated audit. Use when hardening CI/CD pipelines or investigating a possibly compromised build system. By @mukul975, listed here with credit to its creator. Honest caveats: read-only auditing — it finds problems, it doesn't fix them (pair it with the companion securing-github-actions-workflows skill for the remediation); needs Python 3.8+ with PyGithub, and read access to the repos or workflow files you audit. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: Python 3.8+ with PyGithub and YAML parsing dependencies installed; read access to the repositories or workflow files to audit Install "Detecting supply chain attacks in CI/CD" for me. Give my agent the skill for auditing GitHub Actions workflows and CI/CD configs against supply chain attack vectors — unpinned actions, script injection, dependency confusion, secrets exposure Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-supply-chain-attacks-in-ci-cd/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-detecting-supply-chain-attacks-in-ci-cd". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install the Python dependencies, point the agent at the workflows to audit). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.