RedHatProductSecurity

71 mods across 3 repositories, 97 stars between them.

database-security

49

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Enforce database security for schema design, access control, encryption, and operational hardening. Use when building, reviewing, or auditing database schemas, connection handling, credential management, or database deployment configuration.

51 1mo ago A 43 tokens original Apache-2.0

defense-in-depth

50

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Apply defense-in-depth by layering multiple independent security controls. Use when reviewing system architecture, evaluating whether a single control is the only barrier, or assessing blast radius of a component compromise.

51 1mo ago A 41 tokens original Apache-2.0

devcontainer-setup

51

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Creates devcontainers with language-specific tooling (Python/Node/Rust/Go) and persistent volumes. Use when adding devcontainer support to a project or setting up isolated development environments.

51 1mo ago E 41 tokens original Apache-2.0

differential-review

52

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.

51 1mo ago A 61 tokens original Apache-2.0

discovery-mechanism

53

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Enforce authorization server metadata discovery for MCP ecosystems. Use when configuring or reviewing authorization server endpoint publication and discovery metadata.

51 1mo ago A 29 tokens original Apache-2.0

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Enforce support for OAuth 2.0 and OIDC discovery mechanisms in MCP clients. Use when building, configuring, or reviewing MCP client authentication and authorization server discovery.

51 1mo ago A 40 tokens original Apache-2.0

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Enforce encrypted communication with external data sources. Use when designing, configuring, or reviewing network connections between AI systems and external databases, APIs, or data services.

51 1mo ago A 36 tokens original Apache-2.0

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Enforce MCP server integration with external centralized identity providers. Use when building, configuring, or reviewing MCP server authentication against external IdPs like Keycloak.

51 1mo ago A 36 tokens original Apache-2.0

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Apply when reviewing or writing code that accepts file uploads, processes user-supplied files, or serves stored files. Covers extension validation, content verification, filename security, storage isolation, and scanning.

51 1mo ago A 45 tokens original Apache-2.0

file-protection

59

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Protect LLM model files against unauthorized access and modification. Use when designing, deploying, or reviewing storage and access controls for AI model files and weights.

51 1mo ago A 34 tokens original Apache-2.0

fips-compliance

60

RedHatProductSecurity/prodsec-skills

Skill Claude CodeCodex

Enforce FIPS 140-2/140-3 compliance for RHEL, OpenShift, and Go workloads. Use when building, configuring, reviewing, or auditing systems that require FIPS-validated cryptographic modules, RHEL crypto-policy enforcement, FIPS-ready Go binaries, or FIPS-mode kernel and cluster configuration.

51 1mo ago A 71 tokens original Apache-2.0

RedHatProductSecurity/agentic-threat-modeling

Skill Claude CodeCodex

Core threat analysis engine. Takes a system context profile and applies one or more threat modeling frameworks (STRIDE, PASTA, LINDDUN, VAST, Attack Trees, OCTAVE) with automatic threat actor profiling.

2 21d ago A 52 tokens original Apache-2.0

RedHatProductSecurity/agentic-threat-modeling

Skill Claude CodeCodex

Discovers system context for threat modeling through code analysis and/or user interview. Produces a structured system profile covering components, data flows, trust boundaries, assets, and entry points.

2 21d ago A 42 tokens original Apache-2.0

threat-model

71

RedHatProductSecurity/agentic-threat-modeling

Skill Claude CodeCodex

Main dispatcher for threat modeling. Routes to discover, analyze, and report sub-skills based on user intent. Supports multiple frameworks (STRIDE, PASTA, LINDDUN, VAST, Attack Trees, OCTAVE) and automatic threat actor profiling.

2 21d ago A 57 tokens original Apache-2.0