AgentSecOps
Official@agentsecops
Offers a comprehensive suite of security assessment, vulnerability scanning, and compliance enforcement capabilities for enterprise infrastructure and software development lifecycles.
Agent Skills by AgentSecOps
Showing 29 vetted skills indexed across 1 GitHub repositories.
skill-name
Create standardized SKILL.md frontmatter units for Claude Code security workflows.
analysis-tshark
Analyze network traffic and protocol behavior with Tshark for security investigations.
webapp-sqlmap
Automate SQL injection testing and exploitation with SQLMap against authorized web applications.
webapp-nikto
Scan web servers for vulnerabilities and misconfigurations using Nikto.
network-netcat
Run netcat-based connectivity checks, banner grabs, and shell sessions.
recon-nmap
Perform authorized network reconnaissance with Nmap port scanning and service enumeration.
crack-hashcat
Crack password hashes with Hashcat across multiple algorithms and attack modes.
pentest-metasploit
Automate authorized penetration testing workflows with the Metasploit Framework.
detection-sigma
Create, validate, and translate Sigma rules for Splunk, Elasticsearch, and Sentinel backends.
ir-velociraptor
Analyze endpoint telemetry and artifacts for incident response with Velociraptor VQL workflows.
forensics-osquery
Collect endpoint forensic artifacts using SQL-based osquery queries.
reviewdog
Aggregate security and quality tool results into pull request comments.
sbom-syft
Generates SBOMs from container images, file systems, and archives via Syft.
sast-horusec
Run Horusec SAST scans to detect vulnerabilities and secrets in git history.
policy-opa
Evaluate and enforce Rego policies for Kubernetes, CI/CD, and IaC configurations.
iac-checkov
Scan Terraform, CloudFormation, Kubernetes, Dockerfiles, and ARM templates for misconfigurations and policy violations.
secrets-gitleaks
Scan repositories and CI/CD pipelines for hardcoded secrets using Gitleaks.
container-hadolint
Lint Dockerfiles for security best practices and CIS Docker Benchmark compliance.
container-grype
Scan container images and SBOMs for vulnerabilities with Grype.
sca-trivy
Scan container images, dependencies, and IaC files for vulnerabilities and misconfigurations.
dast-nuclei
Run template-driven Nuclei scans to detect CVEs and misconfigurations in web applications and APIs.
dast-zap
Automate OWASP ZAP dynamic security scans for web applications and APIs.
sast-bandit
Analyze Python code for security vulnerabilities and generate JSON reports.
api-mitmproxy
Intercept, inspect, modify, and replay API traffic with mitmproxy.
Frequently Asked Questions About AgentSecOps
FAQPage SchemaWhat specific security tasks can be performed using these capabilities?▼
These capabilities enable comprehensive security testing, including web application vulnerability scanning, network reconnaissance, container image analysis, hardcoded secret detection, and infrastructure-as-code policy enforcement. Users can perform deep-dive forensic investigations and generate standardized threat models based on STRIDE methodologies.
Which technical personas benefit most from these security modules?▼
Security engineers, DevSecOps practitioners, and site reliability engineers benefit from these modules. They are designed for professionals responsible for maintaining secure software delivery pipelines, conducting penetration testing, managing compliance posture, and performing incident response across cloud-native and on-premises environments.
What are the primary prerequisites for deploying these security modules?▼
Deployment requires a Linux-based environment with access to container runtimes and standard package managers. Users must ensure appropriate authorization for network scanning and penetration testing activities, as these modules interact directly with production infrastructure, web services, and endpoint telemetry systems.