tag

supply-chain

19 indexed skills · max 10 per page

skills (19)

implementing-gcp-binary-authorization

mukul975/Anthropic-Cybersecurity-Skills · implementing-gcp-binary-authorization

0

Implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.

implementing-sigstore-for-software-signing

mukul975/Anthropic-Cybersecurity-Skills · implementing-sigstore-for-software-signing

0

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software artifacts. The practitioner configures OIDC-based identity binding, verifies signing events against the Rekor transparency log, and integrates signing workflows into CI/CD pipelines. Activates for requests involving software supply chain signing, keyless container signing, Sigstore deployment, or artifact provenance verification.

hunting-for-supply-chain-compromise

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-supply-chain-compromise

0

Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.

analyzing-sbom-for-supply-chain-vulnerabilities

mukul975/Anthropic-Cybersecurity-Skills · analyzing-sbom-for-supply-chain-vulnerabilities

0

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports. Activates for requests involving SBOM analysis, software composition analysis, supply chain security assessment, dependency vulnerability scanning, CycloneDX/SPDX parsing, or CVE correlation.

securing-serverless-functions

mukul975/Anthropic-Cybersecurity-Skills · securing-serverless-functions

0

This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability scanning, secrets management integration, input validation, function URL authentication, and runtime monitoring to protect against injection attacks, credential theft, and supply chain compromises.

securing-helm-chart-deployments

mukul975/Anthropic-Cybersecurity-Skills · securing-helm-chart-deployments

0

Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.

securing-github-actions-workflows

mukul975/Anthropic-Cybersecurity-Skills · securing-github-actions-workflows

0

This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes.

securing-container-registry-images

mukul975/Anthropic-Cybersecurity-Skills · securing-container-registry-images

0

Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that prevent deploying unscanned or unsigned images.

scanning-container-images-with-grype

mukul975/Anthropic-Cybersecurity-Skills · scanning-container-images-with-grype

0

Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.

implementing-image-provenance-verification-with-cosign

mukul975/Anthropic-Cybersecurity-Skills · implementing-image-provenance-verification-with-cosign

0

Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.

prevpage 1 / 2next