hardw00t

12 mods across 1 repository, 92 stars between them.

android-pentest

01

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze…

92 4mo ago A 87 tokens

api-security

02

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Router skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz…

92 4mo ago A 87 tokens

cloud-security

03

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Multi-cloud security assessment skill for AWS, Azure, and GCP. Use when performing cloud security audits, scanning for misconfigurations, testing IAM policies, auditing storage permissions, and identifying privilege escalation paths. Triggers on requests to audit cloud security, scan AWS/Azure/GCP, check cloud…

92 4mo ago A 85 tokens

container-security

04

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning Docker/OCI images, auditing K8s clusters, reviewing Dockerfiles…

92 4mo ago A 118 tokens

dast-automation

05

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these…

92 4mo ago A 81 tokens

iac-security

06

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s…

92 4mo ago A 105 tokens

ios-pentest

07

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Thin router for an iOS app security assessment. Full OWASP MASTG coverage (recon → static → dynamic → network → storage → crypto → auth → reporting). Detailed runbooks live under workflows/ and methodology/; load them only when needed.

92 4mo ago A 95 tokens

llm-security

08

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

LLM and AI application security testing skill for prompt injection (direct, indirect, multimodal), system-prompt extraction, RAG poisoning, memory poisoning, MCP server injection, skill-file injection, agentic tool misuse, computer-use UI injection, and excessive agency. Authorization required — this skill tests AI…

92 4mo ago A 118 tokens

network-pentest

09

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket…

92 4mo ago A 103 tokens

sast-orchestration

10

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output…

92 4mo ago A 138 tokens

sca-security

11

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems…

92 4mo ago A 137 tokens

threat-modeling

12

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to…

92 4mo ago A 117 tokens