Skill Claude CodeCodex
A set of methods for penetration testing, which is an authorised attempt to find security weaknesses in a computer system or network.
Skill Claude CodeCodex
A set of methods for penetration testing, which is an authorised attempt to find security weaknesses in a computer system or network.
Skill Claude CodeCodex
Security testing playbook for Next.js covering App Router, Server Actions, RSC, and Edge runtime vulnerabilities.
Skill Claude CodeCodex
Canonical Nmap CLI syntax, two-pass scanning workflow, and sandbox-safe bounded scan patterns.
Skill Claude CodeCodex
NoSQL injection testing covering MongoDB operator injection, authentication bypass, blind extraction, GraphQL variable injection, and Redis/DynamoDB/Elasticsearch/Neo4j-specific attack surfaces.
Skill Claude CodeCodex
Exact Nuclei command structure, template selection, and bounded high-throughput execution controls.
Skill Claude CodeCodex
OAuth 2.0 and OIDC flow security testing covering redirect manipulation, token leakage, PKCE bypass, and client misconfiguration.
Skill Claude CodeCodex
Open redirect testing for phishing pivots, OAuth token theft, and allowlist bypass.
Skill Claude CodeCodex
Path traversal and file inclusion testing for local/remote file access and code execution.
Skill Claude CodeCodex
Orchestration layer that coordinates specialized subagents for security assessments.
Skill Claude CodeCodex
Client and server prototype pollution testing covering JavaScript object merge bugs, Node.js RCE chains, and filter bypasses.
Skill Claude CodeCodex
Run Python through execcommand in the SDK sandbox. Use the image-baked caidoapi module for Caido proxy automation from Python scripts.
Skill Claude CodeCodex
Time-boxed rapid assessment targeting high-impact vulnerabilities.
Skill Claude CodeCodex
Race condition testing for TOCTOU bugs, double-spend, and concurrent state manipulation.
Skill Claude CodeCodex
A set of methods for reviewing source code for security problems.
Skill Claude CodeCodex
A set of methods for automating security-related work. Security automation means using software to carry out security tasks with less manual effort.
Skill Claude CodeCodex
Exact Semgrep CLI structure, metrics-off scanning, scoped ruleset selection, and automation-safe output patterns.
Skill Claude CodeCodex
Practical source-aware SAST and AST playbook for semgrep, ast-grep, gitleaks, and trivy fs.
Skill Claude CodeCodex
Coordination playbook for source-aware white-box testing with static triage and dynamic validation.
Skill Claude CodeCodex
SQL injection testing covering union, blind, error-based, and ORM bypass techniques.
Skill Claude CodeCodex
Skill "sqlmap-tooling" from xAmirHamza77/PenKit51, covering sqlmap tooling, deep exploitation guide, sqlmap cli playbook, platform methodology and sqlmap tooling.
Skill Claude CodeCodex
SSRF testing for cloud metadata access, internal service discovery, and protocol smuggling.
Skill Claude CodeCodex
Server-side template injection across Jinja / Mako / Velocity / Freemarker / Thymeleaf / Twig / Handlebars / EJS / ERB with engine fingerprinting, sandbox escape, and RCE gadget chains.
Skill Claude CodeCodex
Balanced security assessment with systematic methodology and full attack surface coverage.
Skill Claude CodeCodex
Subdomain takeover testing for dangling DNS records and unclaimed cloud resources.