Industry collection

🛡️ Security Operations & GRC Workflows

Security operations and governance workflows for dependency risk, secrets, CI hardening, agent guardrails, approvals, policy evidence, threat hunting, red-team checks, and audit-ready releases.

Who this is for

  • Security engineers, SOC teams, compliance operators, DevSecOps leads, and AI governance owners.
  • Teams that need approval gates, policy evidence, supply-chain checks, agent guardrails, and threat-hunting workflows in one operating map.

Jobs covered

  • Scan dependency, container, CI, and repository surfaces for release-blocking risk.
  • Find secrets, unsafe agent configurations, prompt-injection paths, and MCP attack surfaces before adoption.
  • Route risky agent or external actions through approval gates with audit evidence.
  • Generate SBOM, signature, vulnerability, event-log, and policy artifacts for compliance review.

Workflow Stacks

  • Release security gate: Generate SBOM → scan dependencies and images → verify signatures → audit CI permissions → approve or block release
  • Agent governance review: Preflight prompts and tools → apply runtime guardrails → red-team behavior → route risky actions to approval → store policy evidence
  • SOC investigation packet: Collect event logs → map Sigma detections → review secrets and repo risk → summarize timeline → handoff remediation

Curated Skills (31)

Docker Image Vulnerability Triage

Prioritizes container image vulnerabilities for remediation rather than dumping raw scanner output.

Container security analystMedium install71.5k stars
Record system-level agent activity with AgentSight

Captures process, file, network, prompt, and report activity from agent runs so SecOps and GRC teams can audit what an agent actually did.

AI security engineer / GRC audit operatorHigh install469 stars
SkillWhat it does herePersonaInstallStars
Scan project dependencies for supply-chain vulnerabilities with MurphySecScans dependency trees for supply-chain risk before approval or release.AppSec engineerMedium1.7k
Run Claude Code security operations with SecOpsAgentKitPackages Claude Code security workflows for repeatable security operations instead of ad hoc review prompts.Security engineerMedium157
Govern agent skills, MCP servers, prompts, and tool calls with DefenseClawAudits agent skills, MCP servers, prompts, and tool calls as governed assets with review boundaries.AI governance leadHigh647
Add runtime guardrails to TypeScript agents with VoltAgentAdds runtime guardrails around TypeScript agent behavior before unsafe tool calls propagate.Agent platform engineerMedium8.6k
Pin CI workflow actions and images with RatchetPins workflow actions and images so CI supply-chain inputs stay reviewable and repeatable.DevSecOps engineerLow928
Route risky coding-agent work through human approval checkpoints with HumanLayerRoutes high-risk coding-agent actions through human approval checkpoints before external effects happen.Security operations leadMedium10.7k
Red-team agent workflows for jailbreaks, prompt injection, and policy failures with DeepTeamRuns adversarial checks against agent workflows for jailbreaks, prompt injection, and policy failures.AI red-team operatorMedium1.6k
Scan agent repos for repo-poisoning, unsafe AI config files, and MCP attack surfaces with MEDUSAFinds repo poisoning and unsafe AI configuration surfaces before agents trust the workspace.AI security engineerMedium256
Preflight agent specs for prompt-injection risk across prompt, tool, and architecture layers with Prompt HardenerChecks agent specs for prompt-injection risk across prompts, tools, and architecture before rollout.AI governance reviewerMedium50
Turn Windows event logs into Sigma-backed threat-hunting timelines with HayabusaTurns Windows event logs into Sigma-backed timelines for SOC triage and investigations.SOC analystMedium3.1k
Filter prompts and model outputs for injection, secrets, toxicity, and policy risks with LLM GuardScreens prompts and model outputs for injection, secrets, toxicity, and policy risks in agent pipelines.AI safety engineerMedium2.8k
Baseline and Review Repository Secret Findings with detect-secretsCreates a reviewable baseline for repository secret findings instead of burying alerts in noisy scans.Security reviewerLow4.5k
TruffleHog Credential Leak ScannerScans history and code for leaked credentials that need immediate triage.SecOps engineerLow25.3k
Audit GitHub Actions for privilege and supply-chain risks with zizmorAudits GitHub Actions workflows for privilege and supply-chain risk before CI becomes an attack path.DevSecOps engineerLow4.2k
Audit GitHub Actions workflows for insecure permissions and unpinned actionsReviews workflow permissions and unpinned actions as a pre-merge CI hardening step.Security reviewerLow4.1k
Catch agent-era CI/CD and permission misconfigurations before shipping with Ship SafeTargets agent-era CI/CD and permission misconfigurations that normal lint checks miss.Platform security engineerMedium521
Harden-Runner CI/CD Security Agent for GitHub ActionsAdds runtime hardening and egress awareness to GitHub Actions jobs.DevSecOps engineerMedium1.1k
Docker Image Vulnerability TriagePrioritizes container image vulnerabilities for remediation rather than dumping raw scanner output.Container security analystMedium71.5k
Trivy Security Scanner for Containers and IaCScans containers and IaC for vulnerabilities and misconfiguration before deploy.Cloud security engineerLow34.5k
Syft SBOM Generator for Containers and FilesystemsGenerates SBOM evidence for containers and filesystems used in release or audit workflows.Compliance operatorLow8.6k
Grype Container and SBOM Vulnerability ScannerMaps SBOM and container contents to vulnerabilities for release risk review.Supply-chain security analystLow12k
Sigstore Cosign Container Signature CheckerVerifies container signatures so release gates can prove artifact origin.Supply-chain security engineerMedium5.8k
Put approval gates and audit-ready policy checks between agents and external actions with DashClawAdds approval gates and policy evidence before agents take external actions.AI governance operatorMedium241
Verify agent policy coverage and risky-action guardrails before production rollout with Agent Governance ToolkitChecks policy coverage and risky-action guardrails before production agent rollout.AI governance leadMedium1.1k
Stress-test agent defenses with AgentDojoBenchmarks prompt-injection attacks and defenses before agents are trusted with real tools or data.AI security engineer / red-team operatorMedium619
Run agent-generated code in local microVM sandboxes with MicrosandboxRuns untrusted agent-generated code and tool calls in local microVM-backed sandboxes for safer review.AppSec engineer / agent platform operatorHigh6.5k
Evaluate model-generated code execution with SandboxFusionTests model-generated code execution behavior inside a controlled benchmark before teams trust automation outputs.AI security engineer / evaluation leadHigh1k
Gate agent inputs and outputs with Superagent safety checksAdds a safety gate for agent inputs and outputs before risky actions reach users or downstream systems.GRC automation owner / AI safety reviewerMedium6.6k
Emit policy receipts for hard-rule agent skills with PluribusCreates reviewable policy receipts for hard-rule workflows where compliance needs evidence, not just logs.Compliance engineer / policy operationsMedium0
Record system-level agent activity with AgentSightCaptures process, file, network, prompt, and report activity from agent runs so SecOps and GRC teams can audit what an agent actually did.AI security engineer / GRC audit operatorHigh469
Scan agent dependencies and container inputs with OWASP dep-scanScans dependencies, containers, SBOMs, licenses, and risk signals before agent-generated or agent-adopted code moves toward production.AppSec engineer / supply-chain risk reviewerMedium1.3k

Editorial Notes

  • This collection intentionally blends Security, CI/CD, Templates, and Runbooks because security operations span release gates, agent policy, and incident evidence.
  • Only one listed SOC seed is included because Hayabusa fills a distinct Windows event-log hunting job; stronger security-reviewed picks dominate the rest.
  • Do not frame these as autonomous security fixes; the value is evidence, gates, review, and controlled remediation.
  • Keep this workflow/persona based for SecOps, AppSec, SOC, and AI governance; do not make it a renamed Security & Verification category page.

Adjacent Collections