Instructions file CodexOpenCode
AGENTS.md instructions for Kritt-ai/open-kritt, covering agents.md, what this is, run / build / test, frontend and backend (needs databaseurl; see .env.example).
82 tagged security-research, measured the same way as everything else here.
Instructions file CodexOpenCode
AGENTS.md instructions for Kritt-ai/open-kritt, covering agents.md, what this is, run / build / test, frontend and backend (needs databaseurl; see .env.example).
Plugin Claude Code
Claude Code skills and agents for authorized security testing, bug bounty hunting, and pentesting workflows.
Instructions file
Instructions for transilienceai/communitytools, covering community security tools repository, role, standing principles, skill selection and agent architecture.
Skill Claude CodeCodex
Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.
Hook Claude Code
Runs when a session starts, executing session_start_credentials.py via python3. From transilienceai/communitytools.
Settings file Claude Code
Agent settings declaring 1 hook event (SessionStart).
Skill Claude CodeCodex
Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…
Agent
Business-impact gate. Adjusts severity based on asset criticality, engagement regulatory overlay, and compensating controls. Does NOT veto findings.
Agent
Technical truth gate. Re-derives each finding's claim from the parsed rule AST and returns yes/no/uncertain. Uncertain findings route to held/ for human reviewer.
Agent
20+ year offensive security reviewer. Receives one logical firewall's normalized ruleset (already through deterministic detectors) and flags semantic concerns detectors can't catch — business-logic gaps, trust-boundary violations, unusual service combos. 2-4 instances dispatched in parallel during /launch.
Command
Parse all configs in the current engagement, dispatch senior-pentester subagents in parallel, run the validation chain, emit findings ready for /review.
Command
Render a consolidated customer-review Excel workbook, optional audit-grade PDF, and chain-of-custody manifest from approved findings. Gated on ≥1 approve in feedback.jsonl.
Command
Start a new firewall-review engagement. Argus greets the operator, asks all six scoping questions in one batch, scaffolds the engagement folder, and waits for configs. No arguments.
Skill Claude CodeCodex
Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation, Transilience PDF. NETWORK mode (a list of IPs/CIDRs, e.g. 1500…
Instructions file CodexOpenCode
Instructions for bx33661/oh-my-vul, covering repository guidance, purpose, layout, development and conventions.
Agent
CVSS v3.1 vector and score computation agent for oh-my-vul. Use during omv-audit and omv-report to derive a CVSS vector from a finding's evidence. Operates purely from provided impact fields and the cvss-builder reference — no network, no file access beyond the reference. Refuses to inflate severity and treats unknown…
Agent
Adversarial guard/bypass assessment agent for oh-my-vul. Use after dataflow-tracer has identified a candidate source→sink chain to independently assess whether an existing guard actually prevents exploitation. Biased toward finding bypasses — only concedes "guard is effective" when bypass truly cannot be constructed.
Agent
Adversarial verification agent for oh-my-vul. Use after dataflow-tracer and guard-checker have produced a candidate audit conclusion, to independently refute it. The default stance is skeptical — assume the conclusion is wrong and find evidence supporting that. Only concedes agreement when refutation genuinely fails.…
Skill Claude CodeCodex
Deep-audits a candidate finding from an Evidence.v1 file. Use when the user has an omv-find result they want to investigate further, wants to prove or disprove a vulnerability, needs to fill Evidence.v1 fields for omv-report, or invokes /omv-audit. Reads .omv/findings/ .yaml and produces a confirmed or blocked finding…
Skill Claude CodeCodex
Finds and ranks open-source packages worth auditing for passive CVE/VulDB research. Use when the user asks for vulnerability research targets, CVE hunting candidates, packages to audit, projects to fuzz, or /omv-find. Supports npm, Python, Go, Rust, Java, Ruby, PHP, C#, Swift, Dart, Elixir, Perl, R, and Lua, with…
Skill Claude CodeCodex
Generate a complete, ready-to-submit VulDB vulnerability report and CVE request. Covers all major package ecosystems: npm, pip, Go, Cargo (Rust), RubyGems, Maven, Gradle, NuGet, Composer (PHP), CocoaPods, Swift Package Manager, pub (Dart/Flutter), Hex (Elixir), CPAN (Perl), CRAN (R), LuaRocks. Use this skill whenever…
brian-mitchell-sec/workspace-tools-mcp
MCP server Claude CodeCodexCursor
Sandbox workspace tools: search, file read, DB queries, integrations. Returns synthetic data. Remote server at vandorla.com.
MCP server Claude CodeCodexCursor +2
MCP server "winvm-mcp" as configured in Gabriel-Lacorte/winvm-mcp. Runs locally from the winvm-mcp Python package.
At most 3 mods per repository are shown here — the rest are on their repository pages: