balsm-health

63 mods across 1 repository, 2 stars between them.

balsm-health/Balsm-AI

Skill Claude CodeCodex

Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage.

2 19d ago A 52 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.

2 19d ago A 63 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised…

2 19d ago A 69 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Decide whether full DDD is worth it, then plan and route Domain-Driven Design work from strategic modeling to tactical implementation and evented architecture (CQRS, event sourcing, sagas, projections). Use for the up-front viability check and staged planning; for the in-depth DDD manual (bounded contexts, aggregates…

2 19d ago A 81 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Model software around the business domain using bounded contexts, aggregates, and ubiquitous language. Use when the user mentions "domain modeling", "bounded context", "aggregate root", "ubiquitous language", "anti-corruption layer", "context mapping", "domain events", "strategic design", "the code doesnt match the…

2 19d ago A 136 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts to access them with regular user credentials by manipulating…

2 19d ago A 108 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation. Use when assessing mobile app attack surface through custom URI schemes, Android App Links, iOS Universal Links, or…

2 19d ago A 95 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug information, or sensitive business data that the UI does not…

2 19d ago A 114 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.

2 19d ago A 34 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs.

2 19d ago A 33 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on…

2 19d ago A 104 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.

2 19d ago A 37 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.

2 19d ago A 41 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines…

2 19d ago A 108 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat…

2 19d ago A 82 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Overrides default LLM truncation behavior. Enforces complete code generation, bans placeholder patterns, and handles token-limit splits cleanly. Apply to any task requiring exhaustive, unabridged output.

2 19d ago A 44 tokens

gpt-taste

45

balsm-health/Balsm-AI

Skill Claude CodeCodex

Elite UX/UI & Advanced GSAP Motion Engineer. Enforces Python-driven true randomization for layout variance, strict AIDA page structure, wide editorial typography (bans 6-line wraps), gapless bento grids, strict GSAP ScrollTriggers (pinning, stacking, scrubbing), inline micro-images, and massive section spacing.

2 19d ago A 72 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Hardening Docker containers for production involves applying security best practices aligned with CIS Docker Benchmark v1.8.0 to minimize attack surface, prevent privilege escalation, and enforce leas.

2 19d ago A 43 tokens

balsm-health/Balsm-AI

Skill Claude CodeCodex

Teaches the AI to design like a high-end agency. Defines the exact fonts, spacing, shadows, card structures, and animations that make a website feel expensive. Blocks all the common defaults that make AI designs look cheap or generic.

2 19d ago A 53 tokens