code_audit
121Agent ✓ vendor
A static security-audit agent for MCP projects. Static analysis examines source code without running it, focusing on vulnerabilities that could be reached through network inputs.
29,647 tagged Security, measured the same way as everything else here.
Browse within: ai-security 14hooks 13agent-memory 9agentic 9agentic-workflow 9code-quality 9codex-cli 9gemini-cli-extension 8Guardrails 7Multi-Agent 7ai-governance 7gemini 7gemini-cli 7plugin 7
Agent ✓ vendor
A static security-audit agent for MCP projects. Static analysis examines source code without running it, focusing on vulnerabilities that could be reached through network inputs.
Agent ✓ vendor
A security-review agent that checks vulnerability reports for real, reproducible threats and filters out false positives. A false positive is an alleged problem that is not actually exploitable or harmful in the stated environment.
Skill Claude CodeCodex ✓ vendor
A guide for authorized security testing of AI products, agents, connectors, skills, plugins, code repositories, and related infrastructure. It uses harmless checks and collected evidence to identify and describe security risks.
Skill Claude CodeCodex ✓ vendor
The first security skill to install after setting up OpenClaw — powered by Tencent Zhuque Lab. Works like an antivirus for your AI environment: audits installed skills, scans skills before installation, and performs a full OpenClaw security health check to prevent data leaks and privacy risks. Backed by Tencent Zhuque…
Skill Claude CodeCodex ✓ vendor
A local static scanner that checks agent-skill files for security risks before they are installed or used. Static analysis examines files without running them.
Agent
Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.
Dicklesworthstone/destructive_command_guard
Instructions file CodexOpenCode
AGENTS.md instructions for Dicklesworthstone/destructive_command_guard, covering agents.md — dcg (destructive command guard), rule 0 - the fundamental override prerogative, rule number 1: no file deletion, git branch: only use main, never master and toolchain: rust & cargo.
Dicklesworthstone/destructive_command_guard
Skill Claude CodeCodex
Destructive Command Guard - High-performance Rust hook for Claude Code that blocks dangerous commands before execution. SIMD-accelerated, modular pack system, whitelist-first architecture. Essential safety layer for agent workflows.
FlorianBruniaux/claude-code-ultimate-guide
Agent
Use for thorough code review with quality, security, and performance checks.
Skill Claude CodeCodex
Review a Dograh pull request, branch diff, or pasted patch for repo-specific security and correctness risks that are not obvious from generic FastAPI, Next.js, or Python conventions. Use when the user asks to review a PR, audit a diff, check whether changes are safe to merge, review their own changes, or asks what to…
Skill Claude CodeCodex
Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.
Skill Claude CodeCodex
Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.
Skill Claude CodeCodex
Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns.
Command ✓ vendor
Inspect a macOS signing or entitlement failure and explain the minimum fix path.
Agent Claude Code
Code review agent - critically reviews changes for quality, security, and correctness.
Skill Claude CodeCodex
Detect and analyze abusive accounts on Pollinations. IP clustering, multi-signal scoring, ban recommendations. Use when investigating abuse, bot farms, or suspicious usage patterns.
mock-server/mockserver-monorepo
Skill Claude CodeCodex
Interact with Dependabot and Snyk pull requests for dependency upgrades and security fixes. Documents Dependabot commands, javax/jakarta compatibility checks, safe merge workflows, and troubleshooting. Use when managing dependency upgrade PRs or security fix PRs.
Instructions file CodexOpenCode
AGENTS.md instructions for Awarexone/Agentic-Bug-Hunter, covering bug bounty agent toolkit — plugin guide, what's here, commands (slash commands), agents (9 specialized agents) and rules (always active).
Instructions file
Claude Code instructions for Awarexone/Agentic-Bug-Hunter, covering claude bug bounty — plugin guide, what's here, commands (33 slash commands), agents (9 specialized agents) and rules (always active).
Agent
Autonomous hunt loop agent. Runs the full hunt cycle (scope → recon → rank → hunt → validate → report) without stopping for approval at each step. Configurable checkpoints (--paranoid, --normal, --yolo). Uses scopechecker.py for deterministic scope safety on every outbound request. Logs all requests to audit.jsonl.…
Agent
Autonomous credential-attack pipeline runner. Chains /wordlist-gen + /osint-employees + /breach-check (data-prep stages, runs without prompts) then HARD STOPS before /spray (live attack stage requires human go/no-go). Designed so the user only types the target once instead of orchestrating four separate commands.…
Agent
Fast meme coin and token security auditor. Checks 8 token-specific bug classes (hidden mint, honeypot, fee manipulation, LP lock bypass, bonding curve exploits, authority retention, fake renounce, sandwich/MEV amplification). Runs tokenscanner.py for automated red flag detection. Covers EVM (Solidity) and Solana…
Command
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 | /bypass-403 -l.
Command
Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 + okta (via TREVORspray). Default delay 30min/round + 60s jitter. Usage /spray --mode --users --passes.
At most 3 mods per repository are shown here — the rest are on their repository pages: