Create GitHub Copilot agent skills for static analysis & vulnerability management
- Dominant language
- HCL
- Stars
- 32
- Forks
- 9
- Avg merge
- 1h 3m
- Merged PRs (30d)
- 2
Description
These skills will empowers the coding agent to perform deep static analysis tailored to infrastructure-as-code (IaC) and automation scripts managing ArcGIS Enterprise deployments (such as Chef cookbooks, Terraform modules, and Python management scripts).
## Static Infrastructure Audit (arcgis-infra-audit)
This skill evaluates your Infrastructure-as-Code (Terraform modules, CloudFormation, Azure Bicep) against the AWS and Azure Well-Architected Frameworks, ensuring that the underlying cloud infrastructure supporting ArcGIS Enterprise is resilient, performant, and cost-effective.
## Static Vulnerability Audit (arcgis-secure-audit)
This skill acts as your specialized security gatekeeper, combining general software supply chain security with domain-specific hardening rules for Esri software stacks.
- CVE & Dependency Scanning: scans the deployment automation infrastructure against known CVE databases.
- Secrets & Credential Detection: prevents accidental hardcoding of administrator passwords, database connection strings, and SSL certificates.
- ArcGIS Security Best Practices: validate the IaC against the ArcGIS implementation guidance for authentication, authorization, encryption, and auditing.
Contributor guide
Research direction
The issue names no files, tests, or existing skill entry points. Start by locating where GitHub Copilot agent skills belong, then define completion against the listed IaC audits, CVE and dependency scanning, secret detection, and ArcGIS security checks.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, azure, github-actions, python, terraform
- Domain
- cloud, devops, infrastructure, security, tooling
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100