Skip to main content
Run any Skill in Manus
with one click
GitHub repository

secdevai

secdevai contains 9 collected skills from RedHatProductSecurity, with repository-level occupation coverage and site-owned skill detail pages.

skills collected
9
Stars
8
updated
2026-04-23
Forks
8
Occupation coverage
1 occupation categories · 100% classified
repository explorer

Skills in this repository

secdevai-tool
information-security-analysts

Run external security analysis tools (Bandit, Gosec, Scorecard, Semgrep) inside read-only containers via podman/docker. Use when the user wants to execute specific security tools, combine their output with AI analysis, or run all available tools at once.

2026-04-23
secdevai-review
information-security-analysts

Perform AI-powered security code review using OWASP Top 10, CWE/SANS Top 25, and WSTG patterns. Use when reviewing source code, specific files, git commits, or entire codebases for security vulnerabilities. Supports web and non-web code (C/C++, Go, Rust, etc.), multi-language analysis, severity classification, and automated finding validation via subagent.

2026-04-22
secdevai
information-security-analysts

AI-powered secure development assistant. Dispatches to review, fix, tool, and export subcommands. Use when the user invokes /secdevai with no subcommand or needs an overview of available security commands.

2026-04-22
secdevai-validate
information-security-analysts

Validate security findings for exploitability, severity accuracy, and CVSS scoring. Use when secdevai-review dispatches findings for validation, or when the user invokes /secdevai validate to re-validate prior results. Rejects false positives, calibrates severity to Red Hat classification, and produces per-finding CVSS v3.1 analysis.

2026-04-22
secdevai-dast
information-security-analysts

Dynamic Application Security Testing (DAST) using RapiDAST and ZAP. Use when the user wants to scan a running web app or API for security vulnerabilities, run a DAST scan, test a service endpoint, use RapiDAST or ZAP, or says "/secdevai dast" or "/secdevai-dast". Auto-detects Dockerfile/Compose for containerized targets, finds OpenAPI specs, guides the full scan workflow from target setup through SARIF result export, and — uniquely — traces each DAST finding back to the exact source file and line that is the root cause.

2026-04-22
secdevai-export
information-security-analysts

Export security review results to Markdown and SARIF report formats. Use when the user wants to save, export, or generate reports from security review findings produced by /secdevai review, /secdevai fix, or /secdevai tool.

2026-04-22
secdevai-help
information-security-analysts

Display all available SecDevAI commands, usage examples, aliases, and configuration options. Use when the user asks for help, needs a command reference, or wants to see the typical security review workflow.

2026-04-20
secdevai-oci-image-security
information-security-analysts

Analyze OCI container images for security vulnerabilities, misconfigurations, supply chain risks, and hardening gaps. Use when reviewing container images from Red Hat, Quay.io, Docker Hub, or any OCI-compliant registry. Covers CVE analysis, config security, EOL component detection, credential exposure, and TLS/crypto misconfigurations.

2026-03-10
secdevai-fix
information-security-analysts

Apply suggested security fixes from a prior review. Use when the user wants to remediate security findings with before/after code diffs, severity filtering, and explicit approval before modifying code.

2026-02-09