cicd▌
20 indexed skills · max 10 per page
gitlab-cicd-pipeline
aj-geddes/useful-ai-prompts · Productivity
Create comprehensive GitLab CI/CD pipelines that automate building, testing, and deployment using GitLab Runner infrastructure and container execution.
cicd-expert
martinholovsky/claude-skills-generator · Productivity
Secure, efficient CI/CD pipelines with multi-stage automation, security gates, and GitOps deployment patterns. \n \n Expertise across GitHub Actions, GitLab CI, and Jenkins with reusable workflows, matrix builds, and intelligent caching strategies for performance optimization \n Embedded security throughout pipelines: SAST/DAST/SCA scanning, secrets management, artifact signing with Cosign, and supply chain integrity verification \n Deployment automation patterns including blue/green, canary, ro
offensive-cicd-pipeline
SnailSploit/Claude-Red · cicd
### offensive-cicd-pipeline - Comprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issu - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-cicd-secrets
SnailSploit/Claude-Red · cicd
### offensive-cicd-secrets - Comprehensive secrets extraction methodology targeting CI/CD environments across all major platforms. Covers environment variable extraction - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
implementing-policy-as-code-with-open-policy-agent
mukul975/Anthropic-Cybersecurity-Skills · implementing-policy-as-code-with-open-policy-agent
This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in development, and integrating policy evaluation into deployment pipelines.
implementing-fuzz-testing-in-cicd-with-aflplusplus
mukul975/Anthropic-Cybersecurity-Skills · implementing-fuzz-testing-in-cicd-with-aflplusplus
Integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications.
securing-github-actions-workflows
mukul975/Anthropic-Cybersecurity-Skills · securing-github-actions-workflows
This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes.
performing-container-image-hardening
mukul975/Anthropic-Cybersecurity-Skills · performing-container-image-hardening
This skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure production-ready images.
implementing-code-signing-for-artifacts
mukul975/Anthropic-Cybersecurity-Skills · implementing-code-signing-for-artifacts
This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment pipelines.
implementing-infrastructure-as-code-security-scanning
mukul975/Anthropic-Cybersecurity-Skills · implementing-infrastructure-as-code-security-scanning
This skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts before deployment, establishing policy-based governance, and integrating IaC scanning into CI/CD pipelines to prevent insecure cloud resource provisioning.