DevOps & Security skills

Browse reusable Agent Skills, each with a clear purpose and practical guidance.

token-storage-security

Use when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based token theft.

73.22k repo starsObserved in 1 repos
DevOps & Security

x-content-type

Use when auditing HTTP response headers on any web server or CDN for security hardening.

73.22k repo starsObserved in 1 repos
DevOps & Security

x-frame-options

Use when reviewing HTTP response headers for clickjacking protection on any web application with authenticated user actions.

73.22k repo starsObserved in 1 repos
DevOps & Security

azp-logs

Download Azure Pipelines CI logs for analysis

69.69k repo starsObserved in 2 repos
DevOps & Security

appveyor-automation

Automate Appveyor tasks via Rube MCP (Composio). Always search tools first for current schemas.

67.81k repo starsObserved in 1 repos
DevOps & Security

publish

Publish oh-my-opencode to npm by triggering the GitHub Actions publish workflow and verifying its artifacts. Ship-only: never runs pre-publish-review or re-reviews merged code unless the user explicitly asks. Argument: <patch|minor|major>. Triggers: publish, release, deploy, npm publish.

65.89k repo starsObserved in 3 repos
DevOps & Security

publish-ui

Prepare, validate, and publish standalone @cline/ui npm releases. Use when bumping the UI package version, publishing latest or next through ui-publish.yml, checking UI release readiness, or completing the one-time npm trusted-publishing bootstrap.

64.88k repo starsObserved in 2 repos
DevOps & Security

browser-auth-flow

Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md

64.55k repo starsObserved in 1 repos
DevOps & Security

cost-session

Per-message cost breakdown within a single session. The drill-down companion to cost-anomaly — when an outlier session is flagged, this surfaces the specific expensive messages so operators can see whether the cost came from output tokens, cache writes, or model escalations.

64.55k repo starsObserved in 1 repos
DevOps & Security

dependency-check

Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.

64.55k repo starsObserved in 1 repos
DevOps & Security