Security skills for AI coding agents — incident response for supply chain attacks, credential rotation, IOC detection. Works with Claude Code, Codex, Cursor, or as standalone scripts and runbooks.
Security skills for AI coding agents. When your dependencies get compromised, these skills are the incident response playbook your agent follows.

March 19, 2026 — Trivy. Attackers compromise 76 of 77 tags on aquasecurity/trivy-action. Every GitHub Actions workflow using a tag reference runs attacker-controlled code. CI secrets — cloud credentials, deploy keys, package registry tokens — are exfiltrated via dead-drop repos.
March 23, 2026 — KICS. Using credentials stolen from the Trivy attack, attackers pivot to Checkmarx KICS, overwriting 35 tags on checkmarx/kics-github-action. The cascade continues.
March 24, 2026 — LiteLLM. Credentials stolen from the KICS compromise are used to publish backdoored versions of LiteLLM on PyPI (1.82.7, 1.82.8). The malware drops a .pth file in site-packages/ — Python executes it on every interpreter startup, before your code even imports. SSH keys, AWS credentials, .env files, everything is swept and exfiltrated. Most affected developers never directly installed LiteLLM — it was pulled in transitively by CrewAI, DSPy, and Browser-Use.
March 31, 2026 — Axios. The npm maintainer account jasonsaayman is compromised. Malicious versions axios@1.14.1 and axios@0.30.4 are published, injecting a typosquatted dependency plain-crypto-js that deploys platform-specific backdoors: a disguised binary on macOS (/Library/Caches/com.apple.act.mond), a renamed PowerShell on Windows (wt.exe), a Python script on Linux (/tmp/ld.py). The payload self-deletes its installer and swaps package.json to cover its tracks. Axios has 80 million weekly downloads.
One compromised account cascaded across three ecosystems in ten days. GitHub Actions → PyPI → npm. Each attack used credentials stolen from the previous one.
AI coding agents run pip install, npm install, and GitHub Actions
Mine your Claude Code and Codex logs into a local you.md agent profile.
Local-first AI coding agent for VS Code & Cursor. Ollama, LM Studio & your inference fleet. Cursor-grade agent UX — offline, private, zero token cost.
A self-improving skill for AI coding agents (Claude Code, Cursor, AGENTS.md): recognize a hard-won golden path in a session and harvest it into a reusable skill/rule for next time.
Second brain for Forward Deployed Engineers. Engagement memory + 35 skills across 6 domains, all behind one @fde... Works with any AI coding agent.
Game-development Agent Skills for AI coding agents: install once and a master router loads the right skill for your engine and task. 66 original, version-pinned skills (plus a master router) in the portable SKILL.md format that runs across Claude Code, Cursor, Codex, Copilot, Gemini CLI and more, for Godot, Unity, Unreal, web and beyond.
Honey (I Shrunk the AI) by GreenPT: a cross-tool coding skill that cuts AI coding-agent token usage and LLM API costs — write less code, less prose, and denser agent-to-agent handoffs (−53%, lossless in benchmarks) with no loss of quality. Works with Claude Code, Cursor, GitHub Copilot, Codex, Gemini CLI, Windsurf, Cline & Kiro.
Workflows from the Neura Market marketplace related to this Cursor resource