Security hooks

29,647 tagged Security, measured the same way as everything else here.

Browse within: ai-security 14hooks 13agent-memory 9agentic 9agentic-workflow 9code-quality 9codex-cli 9gemini-cli-extension 8Guardrails 7Multi-Agent 7ai-governance 7gemini 7gemini-cli 7plugin 7

web3-audit

145

Awarexone/Agentic-Bug-Hunter

Command

Smart contract security audit — runs through 10 bug class checklist (accounting desync, access control, incomplete path, off-by-one, oracle errors, ERC4626, reentrancy, flash loan, signature replay, proxy/upgrade). Applies pre-dive kill signals first. Generates Foundry PoC template for confirmed findings. Usage…

4.7k +30 yesterday A 0 tokens original MIT

credential-attack

146

Awarexone/Agentic-Bug-Hunter

Skill Claude CodeCodex

Password spray methodology for bug bounty — when to do it vs web-vuln hunting, the wordlist-gen + breach-check + osint-employees + spray pipeline, mode selection (http-form / oauth / o365 / okta), rate-limit + lockout tactics, BBP legal guardrails, success detection, and the spray → authenticated /hunt chain pattern.…

4.7k +30 yesterday A 102 tokens original MIT

graphql-audit

147

Awarexone/Agentic-Bug-Hunter

Skill Claude CodeCodex

GraphQL security hunting — introspection abuse, field suggestion enumeration (clairvoyance), batching DoS, IDOR via aliasing, auth bypass, injection via arguments, subscription abuse, depth/complexity bombs, and WAF bypass. Covers graphw00f fingerprinting, gqlmap, graphql-cop, and inql. Use when a target exposes a…

4.7k +30 yesterday A 92 tokens original MIT

mobile-pentest

148

Awarexone/Agentic-Bug-Hunter

Skill Claude CodeCodex

Mobile app pentest for bug bounty (Android APK + iOS IPA) — runtime-first workflow: install app, proxy through Burp/mitmproxy, drive the UI, capture packets, then test the API exactly like a web target; escalate to decompile (apktool/jadx) and Frida/objection only when traffic is SSL-pinned, encrypted, or absent.…

4.7k +30 yesterday A 205 tokens original MIT

audit-flow

150

zebbern/claude-code-guide

Skill Claude CodeCodex

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document…

4.6k +1 yesterday A 84 tokens original MIT

contrib-pr-review

151

homeassistant-ai/ha-mcp

Skill Claude CodeCodex

Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.

4.6k +29 today A 39 tokens original MIT

firebase/firebase-tools

Skill Claude CodeCodex

Skill to resolve Docker vulnerabilities for the firebase-cli image. Use this skill when you need to check for vulnerabilities in the firebase-cli Docker image and address them.

4.5k +1 today A 38 tokens original MIT

intuitem/ciso-assistant-community

Skill Claude CodeCodex

Guide users through a basic risk assessment workflow in CISO Assistant, from asset identification to scenario creation. Use when: (1) User wants to start a risk assessment from scratch (2) User mentions "risk assessment", "identify risks", "threat scenarios", or "risk register" (3) User asks about qualitative vs…

4.4k +14 yesterday A 138 tokens

mapping-builder

154

intuitem/ciso-assistant-community

Skill Claude CodeCodex

Build a reviewed crosswalk (RequirementMappingSet YAML library + review xlsx/csv) between two CISO Assistant framework YAML files using Claude itself as the reasoning engine. Zero infrastructure — stdlib + pyyaml only, no embedders, no LM Studio, no Qdrant. Use when the user asks to map / crosswalk / generate a…

4.4k +14 yesterday A 164 tokens

intuitem/ciso-assistant-community

Skill Claude CodeCodex

Enrich a CISO Assistant framework YAML by linking each assessable requirement to reference control URNs from the central doc-pol library (CISO Assistant Key Reference Controls). Produces a reviewable xlsx and patches the framework YAML in place. Use when the user asks to "add reference controls to framework X", "link…

4.4k +14 yesterday A 102 tokens

paulirish/dotfiles

Skill Claude CodeCodex

Set up or debug npm Trusted Publishing (OIDC) from GitHub Actions. Handles permissions, metadata validation, and provenance.

4.4k 3d ago A 31 tokens

dmno-dev/varlock

Instructions file GitHub Copilot

Instructions for dmno-dev/varlock, covering copilot pr code review (security), security checklist (changed lines) and copilot instructions for varlock.

4.2k 3d ago A 474 tokens original MIT

varlock

158

dmno-dev/varlock

Skill Claude CodeCodex

Secure environment variable management with Varlock. Use when handling secrets, API keys, credentials, or any sensitive configuration. Ensures secrets are never exposed in terminal, logs, or LLM context. Provides guidance around integrating varlock into a project, reading/editing .env.schema and other .env files…

4.2k 3d ago A 109 tokens original MIT

oss-fuzz

159

apache/tika

Skill Claude CodeCodex ✓ vendor

Run Tika's OSS-Fuzz Jazzer targets locally against a working-tree checkout — build the image, build fuzzers from local source, fuzz a target, run a corpus as a regression pass, reproduce a crash, and add seeds. Use for "fuzz the OneNote parser", "run OneNoteParserFuzzer against these files", "reproduce an OSS-Fuzz…

4.0k +10 yesterday A 90 tokens original Apache-2.0

review-pr

160

mysticaltech/terraform-hcloud-kube-hetzner

Skill Claude CodeCodex

Use when reviewing a pull request - security-focused review following repo agent guidance for breaking changes, malicious patterns, and backward compatibility.

3.9k +1 2d ago A 27 tokens original MIT

Claude-BugHunter

162

elementalsouls/Claude-BugHunter

Plugin Claude Code

83-skill bug-hunting & external red-team bundle for Claude Code — 58 hunt- web/vuln-class + framework skills, enterprise platform attack chains (M365/Entra, Okta, SharePoint, vCenter, SSL-VPN, APK/iOS), recon/OSINT, reporting & validation gates, and Burp MCP integration. Skills auto-load by topic; 15 slash commands in.

3.9k 3d ago A tokens not measured original MIT

hunt

163

elementalsouls/Claude-BugHunter

Command

Active vulnerability hunting. Two-track dispatcher — asks Red Team vs WAPT, hands off to hunt-dispatch skill and sibling commands. Usage: /hunt target.com | /hunt .target.com | /hunt targets.txt [--vuln-class X] [--source-code P] [--chrome].

3.9k 3d ago A 63 tokens original MIT

recon

164

elementalsouls/Claude-BugHunter

Command

Run full recon pipeline on a target — subdomain enum (Chaos API + subfinder), live host discovery (dnsx + httpx), URL crawl (katana + waybackurls + gau), gf pattern classification, nuclei scan. Outputs to recon/ / directory. Usage: /recon target.com.

3.9k 3d ago A 65 tokens original MIT

token-scan

165

elementalsouls/Claude-BugHunter

Command

Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP lock bypass, authority retention, bonding curve exploits, fake renounce, sandwich amplification). Manual 8-class grep audit (with an optional automated scanner if present). Usage: /token-scan [--chain solana].

3.9k 3d ago A 79 tokens original MIT

apk-redteam-pipeline

166

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an authorized external…

3.9k 3d ago A 145 tokens original MIT

bugcrowd-reporting

167

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints…

3.9k 3d ago A 171 tokens original MIT

evidence-hygiene

168

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to mask, Preview annotation / Burp panel hiding / DevTools workflow), PII black-bar discipline (what to mask in other-user data — names, emails, phones, faces — vs what is safe to leave — usernames, trace…

3.9k 3d ago A 190 tokens original MIT