andypitcher/ponytail-sec

The smallest change that ruins an attacker's day.

8Stars on the repository
5Mods indexed here, across every type
4d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

dockerfile

01

andypitcher/ponytail-sec

Skill Claude CodeCodex

Part of ponytail-sec

Binary Dockerfile image-build hardening check. Use when reviewing Dockerfiles, container image builds, multi-stage builds, runtime users, pinned bases, or reproducible dependency installs. Minimal output only: OK or NOTOK: RULE, RULE.

8 4d ago A 51 tokens original MIT

k8s-securitycontext

02

andypitcher/ponytail-sec

Skill Claude CodeCodex

Part of ponytail-sec

Binary Kubernetes securityContext hardening check. Use when reviewing Pods, Deployments, StatefulSets, DaemonSets, Jobs, CronJobs, Helm templates, or Kubernetes manifests that define containers. Minimal output only: OK or NOTOK: RULE, RULE.

8 4d ago A 57 tokens original MIT

ponytail-sec-audit

03

andypitcher/ponytail-sec

Skill Claude CodeCodex

Part of ponytail-sec

Full project security audit. Scans the entire codebase across three passes: code that shouldn't exist, all dependencies assessed, all hardening findings. Produces a comprehensive numbered report with blast-radius narrative. Persists findings to .ponytail-sec/ for cross-scan tracking. For per-diff review use…

8 4d ago A 74 tokens original MIT

ponytail-sec

04

andypitcher/ponytail-sec

Skill Claude CodeCodex

Part of ponytail-sec

Security companion for active development. Scopes to the current diff or changed files. Three passes: YAGNI code review, new-dep assessment, and up to 3 material hardening findings. Lean by design — surfaces the one thing to fix before merging, not a backlog. Use ponytail-sec-audit for a full project scan.

8 4d ago A 74 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: