攻击面枚举专员
01Agent
A non-destructive security-reconnaissance agent that maps known assets to visible services, technologies, dependencies, entry points, and trust boundaries.
Agent
A non-destructive security-reconnaissance agent that maps known assets to visible services, technologies, dependencies, entry points, and trust boundaries.
Agent
A specialist agent for safely undoing changes made during an authorized security test. It creates a checklist for removing test resources and recording proof that cleanup was completed.
Agent
A specialist agent for planning an authorized security assessment before testing begins. It defines the targets, permitted actions, forbidden actions, success criteria, and evidence to collect.
Agent
A specialist agent for designing minimal, auditable proof of business impact or data access during an authorized security test. It emphasizes masking information and exposing as little real data as possible.
Agent
A specialist agent for collecting publicly available information about systems and organizations during an authorized security assessment. It maps exposed assets, technologies, interfaces, and possible leaked information.
Agent
A security-testing agent for examining movement between systems inside a private network after an initial foothold has been obtained.
Agent
A security-testing agent focused on reducing noise, operational risk, and unintended effects during authorized assessments.
Agent
A planning agent for authorized security testing that creates and revises structured work plans based on evidence from earlier steps.
Agent
A supervisor agent that coordinates specialist agents for authorized, non-destructive security testing. It assigns parts of a task to experts and combines their findings.
Agent
A coordinating agent for authorised, non-destructive security assessments. It plans the work, assigns separate tasks to specialist agents and combines their findings for delivery.
Agent
A security-assessment agent for authorised penetration tests, which are controlled checks for weaknesses in systems and applications. It validates vulnerabilities, analyses possible attack paths and documents their impact within a defined scope.
Agent
A security-assessment agent focused on persistence, meaning ways an attacker might retain or reuse access after an initial entry. It evaluates those possibilities at a high level and designs low-impact evidence checks and rollback controls.
Agent
A security-assessment agent that studies whether an existing account or session could gain higher permissions. It produces high-level, non-destructive validation plans without giving weaponised exploit instructions.
Agent
A report-writing and remediation agent that turns supplied security evidence into a structured findings report.
Agent
A reconnaissance agent for collecting information about specified systems and mapping their exposed assets and initial attack surface.
Agent
A vulnerability-triage agent for sorting possible security problems and planning safe ways to verify them. It requires a clear target and supporting evidence, and does not provide attack payloads.
Skill Claude CodeCodex
Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
Skill Claude CodeCodex
Bundle skill for authorized API contract and trust-boundary review. Use when requests involve OpenAPI or Swagger specs, JSON APIs, schema drift, auth declarations, token handling, TLS assumptions, or dependency-driven API risk and Codex should coordinate the relevant review skills.
Skill Claude CodeCodex
A security-testing skill for application programming interfaces, the endpoints software uses to exchange data and actions.
Skill Claude CodeCodex
A guide for reviewing login, logout, password recovery, multi-factor authentication, cookies, tokens, permissions, and cross-site request protections.
Skill Claude CodeCodex
A security-testing guide for business-logic flaws, which are mistakes in how an application’s rules and process steps are designed.
Skill Claude CodeCodex
A cloud-security audit guide for checking the safety of AWS, Azure, and Google Cloud environments. It covers access rights, networks, data protection, compliance, and audit logs.
Skill Claude CodeCodex
A container-security testing guide for Docker and Kubernetes, technologies used to package and run applications. It covers image contents, running-container settings, and Kubernetes permissions and network rules.
Skill Claude CodeCodex
A security-testing guide for CSRF, or cross-site request forgery, where a malicious site tricks a logged-in browser into sending unwanted actions to another site.