Skill Claude CodeCodex
A security review skill for applications that use large language models, such as chatbots, copilots, agents, and retrieval-based knowledge systems.
Skill Claude CodeCodex
A security review skill for applications that use large language models, such as chatbots, copilots, agents, and retrieval-based knowledge systems.
Skill Claude CodeCodex
An Android application security audit workflow for examining APK files, including preinstalled and system apps, for unsafe components and access paths.
Skill Claude CodeCodex
A security testing method for web and service interfaces such as REST, GraphQL, gRPC, and WebSocket APIs. It checks how requests, permissions, documentation, older versions, gateways, and resource limits behave.
Skill Claude CodeCodex
An Android app analysis process that turns an APK—the installable file for an Android app—into readable code, resources, native libraries, and web assets. It also identifies app-protection shells and attempts to restore the hidden contents.
Skill Claude CodeCodex
A security-testing skill for login systems, sessions, permissions, account recovery, tokens, and multi-tenant applications, where separate customers share one system.
Skill Claude CodeCodex
A security review method for business workflows such as payments, refunds, transfers, stock, coupons, and subscriptions. It maps allowed state changes and checks whether those rules can be bypassed or repeated.
Skill Claude CodeCodex
A security-testing guide for cloud infrastructure, containers, operations tools, software delivery systems, third-party integrations, and exposed configuration data.
Skill Claude CodeCodex
A security guide for finding unsafe deserialization, XML external entity (XXE), and prototype-pollution flaws in applications and data parsers.
Skill Claude CodeCodex
扩展名:.php5/.phtml/.phar/.htaccess/.user.ini 双扩展:shell.php.jpg / shell.jpg.php %00截断:shell.php%00.jpg 内容:GIF89a头、图片马.
Skill Claude CodeCodex
A guide for testing injection flaws, where attacker-controlled input is interpreted as database queries, shell commands, templates, or expressions.
Skill Claude CodeCodex
A security-auditing skill for WeChat, Alipay, Douyin, and Baidu mini programs, including their cloud functions and cloud data services. It covers recovering package contents, finding interfaces and secrets, and checking login, payment, access-control, and rendering risks.
Skill Claude CodeCodex
A security-analysis workflow for mapping a web application's assets and examining its JavaScript, mobile apps, and exposed interfaces.
Skill Claude CodeCodex
A security-reporting guide for turning a confirmed vulnerability into a submission-ready DOCX report for security response or bug-bounty platforms.
Skill Claude CodeCodex
A source-code security auditing method written in Chinese. It traces data from where it enters an application through its processing steps to dangerous operations, across languages such as PHP, Java, Python, Node.js, and Go.
Skill Claude CodeCodex
A security guide for testing server-side request forgery (SSRF), where a server can be tricked into requesting attacker-chosen URLs.
Skill Claude CodeCodex
A security-testing guide for examining how web application firewalls (WAFs) and request filters block potentially dangerous requests.
Skill Claude CodeCodex
A specialized skill for analyzing Windows program files such as EXE, DLL, and driver files, including .NET applications. It covers examining how a program works and looking for security weaknesses.
Skill Claude CodeCodex
A security skill for finding web vulnerabilities in user input, browser code, cross-origin settings, and rendered AI or Markdown content. XSS means injected content runs as someone else’s browser code; CSRF tricks a browser into making an unwanted request.
Instructions file CodexOpenCode
A set of instructions for a security-testing agent focused on finding and documenting software vulnerabilities. It covers areas such as business logic, access control, APIs, mobile apps, and third-party dependencies, with an emphasis on authorized testing.