agentsclimarketplace

Devsecops

Skill Mattakushi432/Claude-Code-Skills-Custom-DevTools-Pack/plugins/devtools-pack/skills/devsecops

When to activate: DevSecOps, SAST, DAST, shift-left, security pipeline, container scanning, dependency audit, policy as codeFrom its SKILL.md

Install
npx -y skills add Mattakushi432/Claude-Code-Skills-Custom-DevTools-Pack --skill devsecops

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

5.0 KB, ~1.3k tokens by cl100k_base, as published. Nobody here has run it

DevSecOps Patterns

CI Security Pipeline

# GitHub Actions security pipeline
name: Security

on: [push, pull_request]

jobs:
  sast:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      # Semgrep SAST
      - uses: semgrep/semgrep-action@v1
        with:
          config: >-
            p/owasp-top-ten
            p/python
            p/secrets

      # Bandit (Python)
      - run: pip install bandit && bandit -r src/ -ll -f json -o bandit.json
      - uses: actions/upload-artifact@v4
        with: { name: bandit-report, path: bandit.json }

  dependency-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: pip-audit -r requirements.txt --format json > pip-audit.json
      - run: npm audit --json > npm-audit.json || true
      - uses: snyk/actions/python@master
        env: { SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} }

  secret-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with: { fetch-depth: 0 }
      - uses: gitleaks/gitleaks-action@v2
        env: { GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} }

  container-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: docker build -t myapp:${{ github.sha }} .
      - uses: aquasecurity/trivy-action@master
        with:
          image-ref: myapp:${{ github.sha }}
          severity: HIGH,CRITICAL
          exit-code: '1'

  dast:
    runs-on: ubuntu-latest
    needs: [sast]
    steps:
      - uses: actions/checkout@v4
      - name: Start app
        run: docker-compose up -d
      - uses: zaproxy/[email protected]
        with:
          target: 'http://localhost:8000'

SAST Tools Comparison

# Semgrep — fast, rule-based, language-agnostic
semgrep --config auto src/
semgrep --config p/owasp-top-ten .
semgrep --config p/secrets .

# Bandit — Python focused
bandit -r . -ll                    # medium+ severity
bandit -r . -t B101,B102,B105     # specific checks

# CodeQL — deep semantic analysis (GitHub Actions built-in)
# .github/codeql/codeql-config.yml
# queries: +security-extended,+security-and-quality

# ESLint security plugin (Node.js)
# eslint-plugin-security, eslint-plugin-no-secrets

Dependency Management

# Python
pip-audit                          # audit installed packages against PyPI advisory db
safety check                       # check against Safety DB
pip install pip-audit && pip-audit -r requirements.txt

# Node.js
npm audit fix                      # auto-fix where possible
npx better-npm-audit check -l high # fail on high severity only

# Go
govulncheck ./...                  # official Go vulnerability checker

# Rust
cargo audit                        # check against RustSec Advisory DB

# Renovate / Dependabot — automated PRs for dependency updates
# .github/dependabot.yml
# package-ecosystem: pip
# schedule: interval: weekly

Policy as Code (OPA/Rego)

# Deny privileged containers
package main

deny[msg] {
  input.kind == "Pod"
  container := input.spec.containers[_]
  container.securityContext.privileged == true
  msg := sprintf("Container %s must not run as privileged", [container.name])
}

# Require non-root user
deny[msg] {
  input.kind == "Deployment"
  container := input.spec.template.spec.containers[_]
  not container.securityContext.runAsNonRoot
  msg := sprintf("Container %s must set runAsNonRoot=true", [container.name])
}
# Conftest — test K8s manifests against OPA policies
conftest test deployment.yaml --policy policy/

# Kyverno — admission controller with policy enforcement
kubectl apply -f kyverno-policy.yaml

Security Gates

# Quality gate — block merge on security findings
SECURITY_THRESHOLDS = {
    "critical": 0,    # zero tolerance
    "high": 0,        # zero tolerance
    "medium": 5,      # allow up to 5
    "low": None       # no limit
}

def check_security_gate(findings: list[dict]) -> bool:
    counts = Counter(f["severity"].lower() for f in findings)
    for severity, limit in SECURITY_THRESHOLDS.items():
        if limit is not None and counts.get(severity, 0) > limit:
            print(f"FAIL: {counts[severity]} {severity} findings (limit: {limit})")
            return False
    return True

Pre-commit Hooks

# .pre-commit-config.yaml
repos:
  - repo: https://github.com/gitleaks/gitleaks
    rev: v8.18.0
    hooks:
      - id: gitleaks

  - repo: https://github.com/PyCQA/bandit
    rev: 1.7.5
    hooks:
      - id: bandit
        args: ["-ll", "--skip", "B101"]

  - repo: https://github.com/Yelp/detect-secrets
    rev: v1.4.0
    hooks:
      - id: detect-secrets
        args: ['--baseline', '.secrets.baseline']

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.