Security hooks

29,647 tagged Security, measured the same way as everything else here.

Browse within: ai-security 14hooks 13agent-memory 9agentic 9agentic-workflow 9code-quality 9codex-cli 9gemini-cli-extension 8Guardrails 7Multi-Agent 7ai-governance 7gemini 7gemini-cli 7plugin 7

code_audit

121

Tencent/AI-Infra-Guard

Agent ✓ vendor

A static security-audit agent for MCP projects. Static analysis examines source code without running it, focusing on vulnerabilities that could be reached through network inputs.

6.1k +24 yesterday A 0 tokens original Apache-2.0

vuln_review

122

Tencent/AI-Infra-Guard

Agent ✓ vendor

A security-review agent that checks vulnerability reports for real, reproducible threats and filters out false positives. A false positive is an alleged problem that is not actually exploitable or harmful in the stated environment.

6.1k +24 yesterday A 0 tokens original Apache-2.0

aig-agent-redteam

123

Tencent/AI-Infra-Guard

Skill Claude CodeCodex ✓ vendor

A guide for authorized security testing of AI products, agents, connectors, skills, plugins, code repositories, and related infrastructure. It uses harmless checks and collected evidence to identify and describe security risks.

6.1k +24 yesterday A 164 tokens original Apache-2.0

edgeone-clawscan

124

Tencent/AI-Infra-Guard

Skill Claude CodeCodex ✓ vendor

The first security skill to install after setting up OpenClaw — powered by Tencent Zhuque Lab. Works like an antivirus for your AI environment: audits installed skills, scans skills before installation, and performs a full OpenClaw security health check to prevent data leaks and privacy risks. Backed by Tencent Zhuque…

6.1k +24 yesterday A 236 tokens original Apache-2.0

edgeone skill scanner

125

Tencent/AI-Infra-Guard

Skill Claude CodeCodex ✓ vendor

A local static scanner that checks agent-skill files for security risks before they are installed or used. Static analysis examines files without running them.

6.1k +24 yesterday A 148 tokens original Apache-2.0

bt6-pr-auditor

126

elder-plinius/T3MP3ST

Agent

Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.

5.9k +98 9d ago A 32 tokens AGPL-3.0

Dicklesworthstone/destructive_command_guard

Instructions file CodexOpenCode

AGENTS.md instructions for Dicklesworthstone/destructive_command_guard, covering agents.md — dcg (destructive command guard), rule 0 - the fundamental override prerogative, rule number 1: no file deletion, git branch: only use main, never master and toolchain: rust & cargo.

5.9k +23 yesterday E 17,654 tokens

dcg

128

Dicklesworthstone/destructive_command_guard

Skill Claude CodeCodex

Destructive Command Guard - High-performance Rust hook for Claude Code that blocks dangerous commands before execution. SIMD-accelerated, modular pack system, whitelist-first architecture. Essential safety layer for agent workflows.

5.9k +23 yesterday F 42 tokens

review-pr

130

dograh-hq/dograh

Skill Claude CodeCodex

Review a Dograh pull request, branch diff, or pasted patch for repo-specific security and correctness risks that are not obvious from generic FastAPI, Next.js, or Python conventions. Use when the user asks to review a PR, audit a diff, check whether changes are safe to merge, review their own changes, or asks what to…

5.6k +22 today A 109 tokens original BSD-2-Clause

benchmark

131

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.

5.4k +48 3d ago A 18 tokens original Apache-2.0

defense-evasion

132

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.

5.4k +48 3d ago A 40 tokens original Apache-2.0

opsec

133

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns.

5.4k +48 3d ago A 30 tokens original Apache-2.0

fix-codesign-error

134

openai/plugins

Command ✓ vendor

Inspect a macOS signing or entitlement failure and explain the minimum fix path.

5.3k +48 5d ago A 0 tokens

reviewer

135

entireio/cli

Agent Claude Code

Code review agent - critically reviews changes for quality, security, and correctness.

5.0k +7 today A 17 tokens original MIT

abuse-detection

136

pollinations/pollinations

Skill Claude CodeCodex

Detect and analyze abusive accounts on Pollinations. IP clustering, multi-signal scoring, ban recommendations. Use when investigating abuse, bot farms, or suspicious usage patterns.

5.0k +4 today A 38 tokens original MIT

mock-server/mockserver-monorepo

Skill Claude CodeCodex

Interact with Dependabot and Snyk pull requests for dependency upgrades and security fixes. Documents Dependabot commands, javax/jakarta compatibility checks, safe merge workflows, and troubleshooting. Use when managing dependency upgrade PRs or security fix PRs.

5.0k +4 today A 56 tokens original Apache-2.0

Awarexone/Agentic-Bug-Hunter

Instructions file CodexOpenCode

AGENTS.md instructions for Awarexone/Agentic-Bug-Hunter, covering bug bounty agent toolkit — plugin guide, what's here, commands (slash commands), agents (9 specialized agents) and rules (always active).

4.7k +30 yesterday A 2,384 tokens original MIT

Awarexone/Agentic-Bug-Hunter

Instructions file

Claude Code instructions for Awarexone/Agentic-Bug-Hunter, covering claude bug bounty — plugin guide, what's here, commands (33 slash commands), agents (9 specialized agents) and rules (always active).

4.7k +30 yesterday A 3,467 tokens original MIT

autopilot

140

Awarexone/Agentic-Bug-Hunter

Agent

Autonomous hunt loop agent. Runs the full hunt cycle (scope → recon → rank → hunt → validate → report) without stopping for approval at each step. Configurable checkpoints (--paranoid, --normal, --yolo). Uses scopechecker.py for deterministic scope safety on every outbound request. Logs all requests to audit.jsonl.…

4.7k +30 yesterday A 84 tokens original MIT

credential-hunter

141

Awarexone/Agentic-Bug-Hunter

Agent

Autonomous credential-attack pipeline runner. Chains /wordlist-gen + /osint-employees + /breach-check (data-prep stages, runs without prompts) then HARD STOPS before /spray (live attack stage requires human go/no-go). Designed so the user only types the target once instead of orchestrating four separate commands.…

4.7k +30 yesterday A 91 tokens original MIT

token-auditor

142

Awarexone/Agentic-Bug-Hunter

Agent

Fast meme coin and token security auditor. Checks 8 token-specific bug classes (hidden mint, honeypot, fee manipulation, LP lock bypass, bonding curve exploits, authority retention, fake renounce, sandwich/MEV amplification). Runs tokenscanner.py for automated red flag detection. Covers EVM (Solidity) and Solana…

4.7k +30 yesterday A 97 tokens original MIT

bypass-403

143

Awarexone/Agentic-Bug-Hunter

Command

Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 | /bypass-403 -l.

4.7k +30 yesterday A 0 tokens original MIT

spray

144

Awarexone/Agentic-Bug-Hunter

Command

Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 + okta (via TREVORspray). Default delay 30min/round + 60s jitter. Usage /spray --mode --users --passes.

4.7k +30 yesterday A 0 tokens original MIT