This repository is a curated collection of skills, plugins, and automation pipelines designed for Claude Code — Anthropic's CLI for AI-assisted software engineering. It was built by the engineering and security engineering teams at Phoenix Security and released as open source so that security professionals, DevSecOps engineers, AppSec teams
Cyber threat intelligence search across 595 curated security domains in 4 authority tiers, for CVEs, threat actors, malware families, exploits and breach reports. Ships a skill that needs no API key, a Node CLI, an MCP server, and a /cti-search command. Optional push to NotebookLM.
★not rated 70▲
+1 yesterdayA
tokens not measured
originalMIT
Documentation and research tooling. project-documenter generates and self-heals a full documentation pack across 6 modes. notebooklm queries Google NotebookLM for citation-backed, source-grounded answers. phoenix-research-pipeline runs web and YouTube research and pushes sources into NotebookLM.
★not rated 70▲
+1 yesterdayA
tokens not measured
originalMIT
Security-first specification pipeline. prd-generator writes a full PRD with a threat model from a plain-language feature description. The 12 phoenix- roles run the same pipeline stage by stage: context curation, scope, constraints, RFC 2119 requirements, ambiguity hunting, threat model, API contracts, verification mat.
★not rated 70▲
+1 yesterdayA
tokens not measured
originalMIT
Two adversarial review gates. plan-readiness-review asks whether a PRD, spec or RFC is implementable without inventing anything. production-readiness-review asks whether the code is actually built, wired, tested and safe to deploy, backed by a deterministic repo scanner.
★not rated 70▲
+1 yesterdayA
tokens not measured
originalMIT
Generate opengrep/semgrep SAST rules for 30+ languages, including pattern and taint-mode rules. The research variant first researches a CVE or CWE with web search, then writes targeted detection rules from the findings.
★not rated 70▲
+1 yesterdayA
tokens not measured
originalMIT
AppSec review suite: multi-language security-reviewer (8-point check, 7 language packs, OWASP/ASVS + endpoint checklists), whole-repo security-assessment, diff-scoped 0day-scanner, STRIDE/DREAD threat-modeling, and two threat-model-driven tiers (tm-quick-security-assessment, tm-security-review). Ships 4 slash commands.
★not rated 70▲
+1 yesterdayA
tokens not measured
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: