Plugin Claude Code
Plugin marketplace listing 1 plugin: patchman.
Plugin Claude Code
Plugin marketplace listing 1 plugin: patchman.
Plugin Claude Code
Defensive security audit mode for authorized code review and architecture assessment.
Cursor rule Cursor
Patchman defensive security review defaults.
Instructions file CodexOpenCode
Instructions for MuhammedZohaib/patchman: Patchman is a defensive security review repository.
Instructions file
Instructions for MuhammedZohaib/patchman, a project described as: Defensive AI security audit skill for Claude and Codex. Reviews codebases and web apps for OWASP Top 10, auth and authorization flaws, business logic bugs, tenant isolation gaps, insecure defaults, secret leaks, and ORM or N+1 query issues, then…
Command
Focused review of REST, GraphQL, RPC, and webhook surfaces.
Command
Converts raw findings into an engineering-ready report.
Command
Focused review of authentication, authorization, session, token, and reset flows.
Command
Focused review of business invariants, approval flows, sequencing assumptions, and abuse cases.
Command
Reviews a pull request diff for security regressions.
Command
Focused review of ORM usage, raw SQL, N+1 patterns, and tenant scoping in the data-access layer.
Command
Fast pass over a narrow area when time is constrained.
Command
Runs a full defensive review of a codebase, service, or focused path.
Command
Builds a lightweight threat model for a feature or service.
Skill Claude CodeCodex
Review an authorized API surface for access control, mass assignment, schema validation, rate limiting, SSRF, error leakage, webhook verification, and unsafe defaults. Use for REST, GraphQL, RPC, and webhook handlers.
Skill Claude CodeCodex
Perform a defensive review of authentication and authorization flows in an authorized codebase. Use for login, session, MFA, OAuth, password reset, cookie security, JWT validation, impersonation, privilege checks, and object-level access control.
Skill Claude CodeCodex
Review an authorized application for business-logic vulnerabilities, workflow abuse, approval bypasses, replay conditions, quota circumvention, plan enforcement bugs, and state-transition errors. Use for billing, invites, approvals, refunds, admin actions, and multi-step workflows.
Skill Claude CodeCodex
Review an authorized pull request diff for security regressions. Use when changes modify trust boundaries, auth logic, data-access scope, file handling, logging, headers, or secrets.
Skill Claude CodeCodex
Review an authorized codebase for ORM misuse, N+1 query patterns, authorization-after-fetch bugs, raw SQL risks, cache key collisions, and missing tenant scopes. Use for data-access layers and security-adjacent performance pitfalls.
Skill Claude CodeCodex
Perform a rapid defensive triage on an authorized code area when time is limited. Use to find the most plausible high-impact issues fast, then recommend the next best review target.
Skill Claude CodeCodex
Conduct authorized defensive security audits of codebases and web applications. Use for broad appsec review across OWASP, authz, business logic, SSRF, XSS, CSRF, injection, file upload, secrets, logging, and tenant isolation. Produces structured findings with severity, confidence, evidence, and safe remediation…