Skip to main content
Ejecuta cualquier Skill en Manus
con un clic
endorlabs
Perfil de creador de GitHub

endorlabs

Vista por repositorio de 212 skills recopiladas en 4 repositorios de GitHub.

skills recopiladas
212
repositorios
4
actualizado
2026-07-20
explorador de repositorios

Repositorios y skills representativas

ai-sast-triage
Desarrolladores de software

Parse Endor AI SAST findings, use exploit reproduction and remediation guidance as patch context, fetch source at the pinned commit, and open change requests when requested.

2026-07-20
cicd-posture
Desarrolladores de software

Use this agent when the user wants a read-only CI/CD and supply chain posture assessment for an Endor namespace, GitHub organization, repository set, or current repository. The agent combines existing Endor SCPM, CI/CD, GitHub Actions, and supply-chain findings with read-only GitHub configuration evidence and optional local CI file inspection, then returns deterministic scores, critical overrides, evidence queries, and data gaps without mutating Endor, GitHub, or repository state.

2026-07-20
dependency-decision-helper
Desarrolladores de software

Use this agent when the user asks whether to add, upgrade, or use a specific package version. Examples: "Is lodash 4.17.20 safe?", "Should I use requests 2.28.0?", "Check log4j-core 2.14.1 before I add it." Returns a dependency verdict with evidence, conditions, alternatives, and any data gaps.

2026-07-20
endor-troubleshooter
Desarrolladores de software

Use this agent when the user needs help diagnosing and fixing Endor Labs errors, warnings, missing integrations, scan failures, slow scans, or unhealthy configuration. Endor Troubleshooter gathers the smallest useful read-only Endor evidence, classifies the issue across scan, integration, authentication, dependency resolution, container, reachability, policy, and workflow lanes, then returns low-friction repair guidance without mutating Endor, source-provider, or repository state.

2026-07-20
findings-browser
Desarrolladores de software

Use this agent when the user wants to browse, filter, summarize, or inspect existing Endor Labs findings. Findings Browser uses read-only Endor evidence to list matching findings, explain applied filters, surface pagination and truncation limits, and identify data gaps without starting new scans or performing remediation actions.

2026-07-20
malware-response
Analistas de seguridad de la información

Use this agent when a customer needs rapid read-only response to a software supply-chain malware incident. It gathers or ingests current malware intelligence, normalizes affected package and version evidence, and correlates that evidence against Endor Labs tenant package inventory across a namespace and child namespaces. It reports confirmed exposure, possible exposure, unaffected scope, indicators of compromise, remediation guidance, and future action contracts without mutating Endor Labs or source systems.

2026-07-20
package-risk-summary
Desarrolladores de software

Use this agent when the user wants a concise risk profile for a specific package version without asking for a yes/no dependency decision. Examples: "Summarize npm lodash 4.17.20 risk", "Give me the risk picture for log4j-core 2.14.1", "What should I know about this package version before I review it?" Returns an evidence-backed package risk summary with vulnerabilities, malware or typosquat signals, package scores, license notes, recommended next checks, and any data gaps.

2026-07-20
probe-droid
Desarrolladores de software

Use this agent when the user wants to assess GitHub repository onboarding gaps for Endor Labs monitored-branch coverage. Probe Droid compares github.com organization or repository inventory with Endor project, GitHub App, package, scan, scan profile, package manager integration, dependency resolution, and reachability evidence, then returns human-readable setup actions without mutating source, GitHub, or Endor state.

2026-07-20
Mostrando las 8 principales de 79 skills recopiladas en este repositorio.
probe-droid
Otras ocupaciones informáticas

Use this agent when the user wants to assess GitHub repository onboarding gaps for Endor Labs monitored-branch coverage. Probe Droid compares github.com organization or repository inventory with Endor project, GitHub App, package, scan, scan profile, package manager integration, dependency resolution, and reachability evidence, then returns human-readable setup actions without mutating source, GitHub, or Endor state.

2026-06-23
probe-droid
Otras ocupaciones informáticas

Use this agent when the user wants to assess GitHub repository onboarding gaps for Endor Labs monitored-branch coverage. Probe Droid compares github.com organization or repository inventory with Endor project, GitHub App, package, scan, scan profile, package manager integration, dependency resolution, and reachability evidence, then returns human-readable setup actions without mutating source, GitHub, or Endor state.

2026-06-23
probe-droid
Otras ocupaciones informáticas

Use this agent when the user wants to assess GitHub repository onboarding gaps for Endor Labs monitored-branch coverage. Probe Droid compares github.com organization or repository inventory with Endor project, GitHub App, package, scan, scan profile, package manager integration, dependency resolution, and reachability evidence, then returns human-readable setup actions without mutating source, GitHub, or Endor state.

2026-06-23
probe-droid
Otras ocupaciones informáticas

Use this agent when the user wants to assess GitHub repository onboarding gaps for Endor Labs monitored-branch coverage. Probe Droid compares github.com organization or repository inventory with Endor project, GitHub App, package, scan, scan profile, package manager integration, dependency resolution, and reachability evidence, then returns human-readable setup actions without mutating source, GitHub, or Endor state.

2026-06-23
ai-sast-triage
Analistas de seguridad de la información

Parse Endor AI SAST findings, use exploit reproduction and remediation guidance as patch context, fetch source at the pinned commit, and open change requests when requested.

2026-06-16
cicd-posture
Analistas de seguridad de la información

Use this agent when the user wants a read-only CI/CD and supply chain posture assessment for an Endor namespace, GitHub organization, repository set, or current repository. The agent combines existing Endor SCPM, CI/CD, GitHub Actions, and supply-chain findings with read-only GitHub configuration evidence and optional local CI file inspection, then returns deterministic scores, critical overrides, evidence queries, and data gaps without mutating Endor, GitHub, or repository state.

2026-06-16
dependency-decision-helper
Analistas de seguridad de la información

Use this agent when the user asks whether to add, upgrade, or use a specific package version. Examples: "Is lodash 4.17.20 safe?", "Should I use requests 2.28.0?", "Check log4j-core 2.14.1 before I add it." Returns a dependency verdict with evidence, conditions, alternatives, and any data gaps.

2026-06-16
endor-agent-kit-setup
Administradores de redes y sistemas informáticos

Use when setting up Endor Labs Agent Kit for Codex, checking readiness, installing or updating bundled Codex custom agents, verifying Endor auth, or diagnosing missing endorctl, gh, namespace, or toolchain prerequisites.

2026-06-16
Mostrando las 8 principales de 58 skills recopiladas en este repositorio.
endor-auth-setup
Desarrolladores de software

Use when probing, verifying, or refreshing Endor Labs SDK credentials before API workflows—env-key scan, Client whoami check, endorctl detection, and interactive browser token refresh into .env. Step zero for any tenant session. Not for SSO policy mapping or AuthenticationLog RCA.

2026-07-10
endor-custom-sast-rules
Analistas de seguridad de la información

Use when authoring, validating, or importing custom OpenGrep/Semgrep rule YAML into Endor Labs SemgrepRule resources—rule syntax, Endor metadata shape, local opengrep/semgrep checks, or namespace import. Not for finding triage (hand off to endor-retrieve-scan-results).

2026-07-10
endor-dependency-provenance
Desarrolladores de software

Use when resolving package-version lineage by manifest path and source ref/sha, or distinguishing direct vs transitive introduction paths—especially when the same package appears at multiple versions or via multiple manifest files.

2026-07-10
endor-fetch-and-search-call-graph
Desarrolladores de software

Fetch project call graph artifacts, decode zstd payloads into searchable node and edge files, and run safe direct-edge or multi-hop path searches on the customer PackageVersion plane. Use for static symbol paths (e.g. app code to a dependency API)—not for Finding/CVE reachability triage (hand off to endor-reachability-provenance), scan finding lists (endor-retrieve-scan-results), or natural-language function summaries (VectorStoreQuery; separate flow).

2026-07-10
endor-implement-sdk-resource
Desarrolladores de software

Use when extending the SDK client surface after OpenAPI changes—model sync, registry overlay, payload builders, and integration tests—when a new API resource appears, facade behavior diverges from the generated contract, or list/get/create needs validation. Not for hand-implementing every resource from scratch.

2026-07-10
endor-model-sync-drift
Desarrolladores de software

Use when triaging OpenAPI / model-sync upstream drift—CI or pre-push verify-upstream-only failures, or published endorctl newer than committed provenance. Covers regenerating registry_contract, stubs, and reference docs; reviewing generated diffs; optional local endorctl upgrades. Not for runtime SDK API errors (endor-troubleshoot-sdk).

2026-07-10
endor-namespace-relationship-map
Desarrolladores de software

Live API namespace consumer→producer project graph from PackageVersion + DependencyMetadata coordinates; optional focus-producer-project-uuid for breaking-change blast radius. Namespace-scoped, not single-project SBOM — use endor-project-retrieval-bundle for one repo.

2026-07-10
endor-project-retrieval-bundle
Desarrolladores de software

Use when building a deterministic single-project retrieval bundle via endor-agent-context: context_manifest.json, dependency explorer artifacts, optional session summaries, PV index + hydration, optional call-graph export. Not for namespace topology or breaking-change consumer discovery—hand off to endor-namespace-relationship-map.

2026-07-10
Mostrando las 8 principales de 47 skills recopiladas en este repositorio.
endor-ai-sast
Analistas de seguridad de la información

Fetch and display AI-powered SAST findings from the Endor Labs platform. Default path is summary-only (aggregated counts + clusters); full masked listing runs only when the user asks to drill down (speed and token use). Use when the user says "AI SAST results", "AI SAST findings", "AI static analysis", "endor ai sast", "show AI SAST", or wants pre-computed AI-driven code security findings. Do NOT use for running a new SAST scan (/endor-sast), viewing general findings (/endor-findings), or explaining a specific CVE (/endor-explain).

2026-05-07
endor-oss-request
Desarrolladores de software

Trigger ingestion and analysis of a specific open source package version via an Endor Labs OSS dependency request. Use when the user says "trigger OSS dependency request", "request ingestion of <pkg>", "ingest this package", "add this OSS version to Endor", or wants Endor Labs to analyze a package version that isn't yet in the platform. Do NOT use for scanning local code (/endor-scan) or checking an already-ingested package (/endor-check).

2026-04-22
endor-validate-policy
Analistas de seguridad de la información

Validate an Endor Labs policy against a project to test if it matches any findings. Use when the user says "validate policy", "test policy", "does this policy match", "endor validate", "check policy against project", or wants to verify that a policy (finding or exception) correctly targets findings in a specific project before enforcing it. Do NOT use for creating policies (/endor-policy) or viewing findings (/endor-findings).

2026-04-15
endor-help
Analistas de seguridad de la información

Quick reference for all available Endor Labs commands. Use when the user says "endor help", "what commands are available", "endor usage", "what can endor do", or wants to discover available security scanning capabilities. Do NOT use when the user already knows which specific command they want — route to that skill directly.

2026-04-14
endor-policy
Analistas de seguridad de la información

Create and manage Endor Labs security policies for automated enforcement. Use when the user says "create a policy", "block critical vulns", "endor policy", "security gate", "enforcement rules", "exception policy", or wants to define rules for blocking PRs, requiring reviews, or enforcing security standards. Do NOT use for one-time PR review (/endor-review) or viewing findings (/endor-findings).

2026-04-14
endor
Analistas de seguridad de la información

Main Endor Labs security router. Use when the user says "endor", "endor labs", or asks a general security question without specifying a particular endor command. Routes ambiguous requests like "check my security", "help with this dependency", or "what security tools are available" to the right specialized skill. Do NOT use when the user names a specific command like /endor-scan, /endor-check, /endor-fix, etc. — those skills handle themselves directly.

2026-04-14
endor-ghactions
Analistas de seguridad de la información

Scan a repository's GitHub Actions workflows for insecure patterns and vulnerable third-party action versions using Endor Labs. Use when the user says "scan GitHub Actions", "workflow security", "endor ghactions", "insecure CI workflow", "vulnerable action version", "harden my GHA workflows", or focuses on `.github/workflows` without asking for a full dependency or secrets scan. Do NOT use for combined supply chain reports (/endor-supply-chain), generic quick scans (/endor-scan), adding Endor to pipelines (/endor-cicd), or dependency-only checks (/endor-check).

2026-04-09
endor-supply-chain
Analistas de seguridad de la información

Assess supply chain risk for your repository by scanning dependencies, secrets, and GitHub Actions workflows using Endor Labs. Use when the user says "supply chain risk", "supply chain assessment", "assess my supply chain", "endor supply chain", "third-party risk", "software supply chain", or wants a combined view of dependency vulnerabilities, leaked secrets, and CI/CD pipeline risks. Do NOT use for GitHub Actions workflows only (/endor-ghactions), code-level SAST scanning (/endor-sast), single package checks (/endor-check), or full reachability analysis (/endor-scan-full).

2026-04-09
Mostrando las 8 principales de 28 skills recopiladas en este repositorio.
Mostrando 4 de 4 repositorios
Todos los repositorios cargados