security first
by Roy Yuen
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
Skills for security audits, static analysis, vulnerability triage, and compliance checks. Ship safer software and meet regulatory requirements faster.
318 live security & compliance skills for GitHub Copilot.
by Roy Yuen
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
Expert AI guidance for ISO-compliant cleanroom design, HVAC filtration setup, and controlled environment installation.
A fast, free 3-point accessibility screen (text contrast, image alt text, form labels) to spot the most common ADA/WCAG problems before they cost you.
by Timoranjes
The security auditor for AI agents. Detect prompt injection, secret leaks, and unsafe tool access in SKILL.md files.
by Timoranjes
Audit frontend code for WCAG 2.2 AA compliance with prioritized remediation steps and deep semantic analysis.
by LocoLoboZ
Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
by Kaymue
Get SOC2 Type II-ready in 90 days. 17 policy templates, 64 control mappings, automated AWS/GCP/GitHub evidence collection.
by Kaymue
Audit prompts and MCP tools for prompt injection. 47 attack patterns, OWASP LLM Top 10, generates adversarial tests. CVSS-scored.
Evidence-first AI code review that discovers, verifies, prioritizes, and explains meaningful code problems.
by OnwireFlow
Makes your coding agent work like a senior developer: exact money with no rounding errors, configurable rules, real audit trails, honest testing and review. Any stack, any country.
by Echo Rose
Api Security Scanner - A Premium AI Agent Skill
by rayyer
Find accessibility barriers and WCAG 2.2 AA failures in web and mobile UI code — with file:line, the exact criterion, and a fix
An adversarial gate that audits cloud and infrastructure-as-code config — Terraform, Kubernetes, IAM, security groups, buckets — for the misconfigurations that cause real breaches, and returns a structured PASS/REVISE/BLOCK verdict with severities and exact fixes before anything reaches your environment.
by Samuel Rose
Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.
by Nex AI
Generate US construction pay applications, G702/G703 structures, lien waivers, and certified payroll drafts.
by Echo Rose
Container Security - A Premium AI Agent Skill
by LocoLoboZ
Professional-grade orchestration for ransomware triage, containment, recovery planning, and executive reporting.
Check your app, site, and ad copy for the AI disclosures US regulators and ad platforms now expect: undisclosed AI chatbots, unlabeled AI-generated media, AI-origin ad copy with no disclosure line, and sponsored content with no material-connection language. Read-only, every finding explained in plain English. US and ad-platform focused.
Audit AI-assisted medical and pharma content for compliance-readiness before it enters formal MLR review or journal submission. It checks claim substantiation and on-label scope, reference integrity (the acute AI risk: fabricated or misrepresented citations), fair balance and safety, AI-use disclosure, ICMJE authorship and GPP, COI and funding, data integrity and patient privacy, and adverse-event flags — then returns a PASS / REVISE / BLOCK verdict with the must-fix list. A readiness pre-check built for the regulated reality of medical communications — not a replacement for formal review.
by Liam Romanis
Detect and assess CVE-2026-31431 "Copy Fail" vulnerability on Linux systems and Kubernetes clusters.
by Timoranjes
Expert regex architect for building, auditing, and optimizing high-performance, ReDoS-safe patterns.
by Shandra
Turns dependency scan reports and security alerts into prioritized remediation plans with severity, exploitability, affected area, safe fix strategy, and verification checklists.
by LB Creations
Security review of Kandji agent configurations, library items, and automation for compliance and safety
by LB Creations
Secure, battle-tested patterns for user detection and credential prompting in Jamf and Kandji scripts
Each skill on this page is a SKILL.md file built for security & compliance work and confirmed to run in GitHub Copilot. Install one into .github/copilot/skills/ (repo) or VS Code workspace, start a new session, and GitHub Copilot follows the workflow the creator encoded instead of improvising from a short prompt.
Listings are ranked by installs, upvotes and reviews, so what surfaces first is what other GitHub Copilot users actually keep. Free and paid skills compete on the same page, and every listing shows its security scan result before you download anything.