Skip to content
OpenSmartRoute

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

143.8K
listings
1
installs
0
reviews
38.7K
publishers
44 results
Skill

bumblebee

Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

by sickn33skills.sh
(0)
0Free
Skill

skill-audit

Pre-install security scanner for AI agent skills. 7.5% of 14,706 skills are malicious. Audit before you trust.

by sickn33skills.sh
(0)
0Free
Skill

skill-security-audit

Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions.

by sickn33skills.sh
(0)
0Free
Skill

logistics-expert

Expert-level supply chain management, logistics optimization, warehouse systems, and fleet management. Use when the user mentions supply chain, warehouse, fleet, or optimization, or when the task invo

by personamanagmentlayerskills.sh
(0)
0Free
Skill

supply-chain-expert

Build comprehensive supply chain solutions including demand planning, inventory management, supplier coordination, and logistics optimization. Use when the user mentions supply chain, demand planning

by personamanagmentlayerskills.sh
(0)
0Free
Skill

supply-chain-security-expert

Secure the path from dependency to deployed artefact: SBOMs, dependency scanning, build provenance, artefact signing and CI/CD integrity. Use when the user mentions supply chain security, SBOM, Cyclon

by personamanagmentlayerskills.sh
(0)
0Free
Skill

nis2-directive-specialist

NIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities, covering the 10 minimum security measures. Use for NIS2 compliance assessments, entity scope analysis, supply chain secur

by borgheiskills.sh
(0)
0Free
Skill

dependency-audit

Audit a project's dependency supply chain — known CVEs in installed packages, secrets about to be committed, and lockfile/provenance integrity — and wire the checks into CI as a merge gate. Use when a

by shipshitdevskills.sh
(0)
0Free
Skill

content-security-scan

Automated security scanner for external skill/agent content fetched from GitHub or web sources. Runs a 7-step PASS/FAIL security gate against fetched markdown/text content.

by oimiragieoskills.sh
(0)
0Free
Skill

analyzing-sbom-for-supply-chain-vulnerabilities

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds

by mukul975skills.sh
(0)
0Free
Skill

analyzing-supply-chain-malware-artifacts

Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.

by mukul975skills.sh
(0)
0Free
Skill

auditing-mcp-servers-for-tool-poisoning

Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and descript

by mukul975skills.sh
(0)
0Free
Skill

detecting-typosquatting-packages-in-npm-pypi

Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify

by mukul975skills.sh
(0)
0Free
Skill

exploiting-broken-link-hijacking

Discovers and exploits broken link hijacking by spidering a site (Burp Suite Spider, Scrapy, curl scraping), extracting referenced external scripts/domains, and checking DNS/CNAME records and domain r

by mukul975skills.sh
(0)
0Free
Skill

hunting-for-supply-chain-compromise

Runs a hypothesis-driven threat hunt for supply-chain compromise (T1195) by querying SIEM/EDR logs for trojanized software updates, compromised dependencies, unauthorized code modifications, and tampe

by mukul975skills.sh
(0)
0Free
Skill

implementing-aqua-security-for-container-scanning

Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.

by mukul975skills.sh
(0)
0Free
Skill

implementing-code-signing-for-artifacts

Implements code signing for build artifacts (binaries, packages, containers) using GPG, Sigstore, and platform-specific signing tools, establishing trust chains and verifying signatures in deployment

by mukul975skills.sh
(0)
0Free
Skill

implementing-container-image-minimal-base-with-distroless

Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using multi-stage

by mukul975skills.sh
(0)
0Free
Skill

implementing-gcp-binary-authorization

Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted, verified

by mukul975skills.sh
(0)
0Free
Skill

implementing-image-provenance-verification-with-cosign

Signs and verifies container image provenance with Sigstore Cosign, covering key-based and keyless OIDC signing (Fulcio, Rekor transparency log), SLSA attestations, and enforcing signature verificatio

by mukul975skills.sh
(0)
0Free
Skill

implementing-sigstore-for-software-signing

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic p

by mukul975skills.sh
(0)
0Free
Skill

performing-container-security-scanning-with-trivy

Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed secret

by mukul975skills.sh
(0)
0Free
Skill

performing-supply-chain-attack-simulation

Simulates and detects software supply chain attacks: typosquatting detection via Levenshtein distance against popular PyPI package names, dependency confusion testing against private registries, SHA-2

by mukul975skills.sh
(0)
0Free
Skill

scanning-container-images-with-grype

Scans container images, filesystems, and SBOMs for known CVEs with Anchore Grype, matching Syft-generated SBOM packages against NVD, GitHub Advisories, and OS-specific feeds with configurable severity

by mukul975skills.sh
(0)
0Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.