Security-focused resources for secrets, scanning, vulnerabilities, auth, and incident workflows.
Use these checks to narrow the directory before reviewing individual source files, permissions, and installation instructions.
Define whether you need inventory, detection, investigation, or remediation. Favor resources with explainable findings, severity context, scoped targets, and a way to reproduce results.
Confirm supported languages, scanners, cloud or identity providers, vulnerability feeds, policy formats, and whether analysis is local or sends artifacts to a third party.
Common verified inventory signals: Clients: Codex, ChatGPT, and Cursor. Runtimes: Elixir and Python. Install methods: docker, git clone, and npx.
Run with least privilege in isolated environments, protect findings and exploit details, distinguish detection from proof, and require authorization before active testing or remediation.
A starting set selected from profiles that pass SkillIndex’s current public index-eligibility checks. Review each profile’s source and setup details before use.