agentsclimarketplace

Devsecops

Skill Mattakushi432/Claude-Code-Skills-Custom-DevTools-Pack/plugins/devtools-pack/skills/devsecops

A curated pack of custom Claude Code skills for developers — installable as a Claude Code plugin marketplace.

Install
npx -y skills add Mattakushi432/Claude-Code-Skills-Custom-DevTools-Pack --skill devsecops

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

When to activate: DevSecOps, SAST, DAST, shift-left, security pipeline, container scanning, dependency audit, policy as code

SKILL.md

5.0 KB, as published. Nobody here has run it

DevSecOps Patterns

CI Security Pipeline

# GitHub Actions security pipeline
name: Security

on: [push, pull_request]

jobs:
  sast:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      # Semgrep SAST
      - uses: semgrep/semgrep-action@v1
        with:
          config: >-
            p/owasp-top-ten
            p/python
            p/secrets

      # Bandit (Python)
      - run: pip install bandit && bandit -r src/ -ll -f json -o bandit.json
      - uses: actions/upload-artifact@v4
        with: { name: bandit-report, path: bandit.json }

  dependency-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: pip-audit -r requirements.txt --format json > pip-audit.json
      - run: npm audit --json > npm-audit.json || true
      - uses: snyk/actions/python@master
        env: { SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} }

  secret-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with: { fetch-depth: 0 }
      - uses: gitleaks/gitleaks-action@v2
        env: { GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} }

  container-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: docker build -t myapp:${{ github.sha }} .
      - uses: aquasecurity/trivy-action@master
        with:
          image-ref: myapp:${{ github.sha }}
          severity: HIGH,CRITICAL
          exit-code: '1'

  dast:
    runs-on: ubuntu-latest
    needs: [sast]
    steps:
      - uses: actions/checkout@v4
      - name: Start app
        run: docker-compose up -d
      - uses: zaproxy/[email protected]
        with:
          target: 'http://localhost:8000'

SAST Tools Comparison

# Semgrep — fast, rule-based, language-agnostic
semgrep --config auto src/
semgrep --config p/owasp-top-ten .
semgrep --config p/secrets .

# Bandit — Python focused
bandit -r . -ll                    # medium+ severity
bandit -r . -t B101,B102,B105     # specific checks

# CodeQL — deep semantic analysis (GitHub Actions built-in)
# .github/codeql/codeql-config.yml
# queries: +security-extended,+security-and-quality

# ESLint security plugin (Node.js)
# eslint-plugin-security, eslint-plugin-no-secrets

Dependency Management

# Python
pip-audit                          # audit installed packages against PyPI advisory db
safety check                       # check against Safety DB
pip install pip-audit && pip-audit -r requirements.txt

# Node.js
npm audit fix                      # auto-fix where possible
npx better-npm-audit check -l high # fail on high severity only

# Go
govulncheck ./...                  # official Go vulnerability checker

# Rust
cargo audit                        # check against RustSec Advisory DB

# Renovate / Dependabot — automated PRs for dependency updates
# .github/dependabot.yml
# package-ecosystem: pip
# schedule: interval: weekly

Policy as Code (OPA/Rego)

# Deny privileged containers
package main

deny[msg] {
  input.kind == "Pod"
  container := input.spec.containers[_]
  container.securityContext.privileged == true
  msg := sprintf("Container %s must not run as privileged", [container.name])
}

# Require non-root user
deny[msg] {
  input.kind == "Deployment"
  container := input.spec.template.spec.containers[_]
  not container.securityContext.runAsNonRoot
  msg := sprintf("Container %s must set runAsNonRoot=true", [container.name])
}
# Conftest — test K8s manifests against OPA policies
conftest test deployment.yaml --policy policy/

# Kyverno — admission controller with policy enforcement
kubectl apply -f kyverno-policy.yaml

Security Gates

# Quality gate — block merge on security findings
SECURITY_THRESHOLDS = {
    "critical": 0,    # zero tolerance
    "high": 0,        # zero tolerance
    "medium": 5,      # allow up to 5
    "low": None       # no limit
}

def check_security_gate(findings: list[dict]) -> bool:
    counts = Counter(f["severity"].lower() for f in findings)
    for severity, limit in SECURITY_THRESHOLDS.items():
        if limit is not None and counts.get(severity, 0) > limit:
            print(f"FAIL: {counts[severity]} {severity} findings (limit: {limit})")
            return False
    return True

Pre-commit Hooks

# .pre-commit-config.yaml
repos:
  - repo: https://github.com/gitleaks/gitleaks
    rev: v8.18.0
    hooks:
      - id: gitleaks

  - repo: https://github.com/PyCQA/bandit
    rev: 1.7.5
    hooks:
      - id: bandit
        args: ["-ll", "--skip", "B101"]

  - repo: https://github.com/Yelp/detect-secrets
    rev: v1.4.0
    hooks:
      - id: detect-secrets
        args: ['--baseline', '.secrets.baseline']

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.