Skill Claude CodeCodex
Guides installation, Taro config, styling, and usage of taro-ui (At components) for WeChat/Alipay/H5/RN. Use when building Taro apps with taro-ui, picking components, theming, i18n, or modifying packages/taro-ui source.
Skill Claude CodeCodex
Guides installation, Taro config, styling, and usage of taro-ui (At components) for WeChat/Alipay/H5/RN. Use when building Taro apps with taro-ui, picking components, theming, i18n, or modifying packages/taro-ui source.
Skill Claude CodeCodex
A skill-management module for storing, organising, sharing, and managing reusable skills, including their descriptions, content, tags, and files.
Skill Claude CodeCodex
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
Skill Claude CodeCodex
Use when you have a written implementation plan to execute in a separate session with review checkpoints.
Skill Claude CodeCodex
A security checker for OpenClaw installations, including their configuration, permissions, containers, network access, and logs.
Skill Claude CodeCodex
A security scanner for OpenClaw, an AI agent system that can run commands, read files, and make network requests. It checks logs, files, commands, and network activity for signs of attacks, including prompt injection, where hostile text tricks an agent into taking unsafe actions.
Skill Claude CodeCodex
Comprehensive PDF manipulation toolkit for extracting text and tables, creating new PDFs, merging/splitting documents, and handling forms. When Claude needs to fill in a PDF form or programmatically process, generate, or analyze PDF documents at scale.
Skill Claude CodeCodex
AI/LLM application security testing — prompt injection, jailbreaking, data exfiltration, and insecure output handling per OWASP LLM Top 10.
Skill Claude CodeCodex
Deep OWASP API Security Top 10 testing for REST, GraphQL, gRPC, and WebSocket APIs — BFLA, mass assignment, rate limiting, and unsafe consumption.
Skill Claude CodeCodex
Business logic vulnerability testing — workflow bypass, payment manipulation, state machine abuse, and function limit circumvention per WSTG-BUSL.
Skill Claude CodeCodex
Advanced client-side attacks — CORS misconfiguration, WebSocket security, clickjacking, postMessage abuse, CSS injection, and browser storage vulnerabilities.
Skill Claude CodeCodex
Cloud security posture management and container security assessment for AWS, Azure, GCP, and Kubernetes.
Skill Claude CodeCodex
Security header auditing, TLS configuration testing, HTTP method analysis, CSP bypass assessment, and deployment hardening verification.
Skill Claude CodeCodex
Binary exploitation (Pwn) and reverse engineering tools for CTF challenges and software analysis.
Skill Claude CodeCodex
Cryptography tools for solving CTF challenges involving ciphers, hashing, and weak encryption.
Skill Claude CodeCodex
Digital forensics, steganography, and packet analysis for CTF challenges and investigation.
Skill Claude CodeCodex
Professional web application and API security testing workflows using OWASP Top 10 methodologies.
Skill Claude CodeCodex
Proof-driven exploitation with 4-level evidence system, bypass exhaustion protocol, mandatory evidence checklists, and strict EXPLOITED/POTENTIAL/FALSEPOSITIVE classification.
Skill Claude CodeCodex
HTTP request smuggling, desync attacks, cache poisoning, and protocol-level vulnerability testing.
Skill Claude CodeCodex
OWASP Mobile Top 10 security testing for Android and iOS — local storage, certificate pinning bypass, IPC abuse, and binary protections.
Skill Claude CodeCodex
Internal network penetration testing, Active Directory enumeration, and lateral movement simulation.
Skill Claude CodeCodex
Open Source Intelligence gathering and attack surface management for external reconnaissance.
Skill Claude CodeCodex
Concurrency exploitation — race conditions, TOCTOU vulnerabilities, and parallel request abuse in web applications.
Skill Claude CodeCodex
White-box attack surface mapping — correlate external scans, browser exploration, and source code into structured endpoint inventory, role architecture, and authorization vulnerability candidates.