bex-co/bex-security

Open-source AI security scanner for Codex, Claude Code, and ACP-compatible coding agents—kept current with OpenAI Codex Security.

40Stars on the repository
23Mods indexed here, across every type
3d agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

loop-worker

01

bex-co/bex-security

Skill Claude CodeCodex

Autonomously work a .pm workstream to completion — pick the next pending milestone, implement every task end to end, /ship it, then move to the next until none remain. Use when the user asks to "loop", drain, or work through a whole workstream's backlog (e.g. /loop-worker w1). Sequential, not interval-based; for a…

40 3d ago A 86 tokens original Apache-2.0

merge-upstream-main

02

bex-co/bex-security

Skill Claude CodeCodex

Merge the public openai/codex-security main branch into this fork's main branch and push the result to the fork remote. Use when asked to sync or merge upstream main for this repository.

40 3d ago A 44 tokens original Apache-2.0

pm-brainstorm

03

bex-co/bex-security

Skill Claude CodeCodex

Analyze and decompose a product topic into a text-only proposal for the repository's .pm board. Use when the user wants to pressure-test scope, size milestones, identify dependencies, or prepare exact PM board commands without writing board files.

40 3d ago A 52 tokens original Apache-2.0

pm

04

bex-co/bex-security

Skill Claude CodeCodex

Inspect and maintain the repository's .pm workstreams, inbox notes, milestones, and tasks. Use when the user asks for PM board status or requests a supported board mutation such as creating, promoting, adding, or completing work.

40 3d ago A 48 tokens copy · 94% Apache-2.0

release

05

bex-co/bex-security

Skill Claude CodeCodex

Bump, validate, publish, and announce a public @bex-co/bex-security release using upstreamVersion-bex.N. Use only when explicitly asked to cut or publish a Bex Security release.

40 3d ago A 43 tokens original Apache-2.0

ship

06

bex-co/bex-security

Skill Claude CodeCodex

Safely bring main up to date, commit intended pending changes, and push to origin/main. Use when the user explicitly asks to ship the current main branch or invokes the repository's ship workflow.

40 3d ago A 41 tokens copy · 94% Apache-2.0

assess-patch-risk

07

bex-co/bex-security

Skill Claude CodeCodex

Assess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility. Use for generated patch files, provider pull-request diffs, or commit ranges when reviewers need evidence about affected runtime paths, contracts, tests, and recoverability. This skill is read-only and does not generate…

40 3d ago A 77 tokens original Apache-2.0

bex-co/bex-security

Skill Claude CodeCodex

Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

40 3d ago A 60 tokens original Apache-2.0

deep-security-scan

09

bex-co/bex-security

Skill Claude CodeCodex

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the…

40 3d ago A 87 tokens original Apache-2.0

bex-co/bex-security

Skill Claude CodeCodex

Define, review, or update SECURITY.md guidance for a repository or component. Use when the user wants to clarify what Codex Security should review, what is out of scope, which security properties must hold, or whether existing guidance still matches the code.

40 3d ago A 54 tokens original Apache-2.0

finding-discovery

11

bex-co/bex-security

Skill Claude CodeCodex

Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

40 3d ago A 58 tokens copy · 92% Apache-2.0

fix-finding

12

bex-co/bex-security

Skill Claude CodeCodex

Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

40 3d ago A 42 tokens original Apache-2.0

bex-co/bex-security

Skill Claude CodeCodex

Develop evidence-backed structural and architectural security hardening proposals from vulnerability disclosures, supplied findings, incident or assessment documents, source code, or a completed Codex Security scan. Use when a user asks for systemic improvements, alternatives beyond per-finding patches…

40 3d ago A 105 tokens original Apache-2.0

security-diff-scan

14

bex-co/bex-security

Skill Claude CodeCodex

Review a pull request, commit, branch diff, or working-tree patch for security vulnerabilities.

40 3d ago A 24 tokens original Apache-2.0

security-scan

15

bex-co/bex-security

Skill Claude CodeCodex

Use for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR, commit, branch, or working-tree diffs, or for deep, multi-pass scans.

40 3d ago A 66 tokens original Apache-2.0

threat-model

16

bex-co/bex-security

Skill Claude CodeCodex

Use when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a repository threat model. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

40 3d ago A 68 tokens original Apache-2.0

track-findings

17

bex-co/bex-security

Skill Claude CodeCodex

Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use…

40 3d ago A 79 tokens original Apache-2.0

triage-finding

18

bex-co/bex-security

Skill Claude CodeCodex

Use when the user supplies or imports existing security findings, vulnerability reports, or security/vulnerability Jira/Linear tickets from scanners, advisories, GitHub, Atlassian Rovo, Linear, or similar backlog sources and wants static repo-impact triage. Do not use for discovery, duplicate-bug triage, validation…

40 3d ago B 73 tokens original Apache-2.0

validation

19

bex-co/bex-security

Skill Claude CodeCodex

Use when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

40 3d ago A 54 tokens original Apache-2.0

verify-fix

20

bex-co/bex-security

Skill Claude CodeCodex

Use when the user asks whether an existing security fix, patch, finding, or completed issue actually remediates the original vulnerability without modifying the repository. Do not use to validate candidate findings, implement patches, or run full repository scans.

40 3d ago A 51 tokens original Apache-2.0

bex-co/bex-security

Skill Claude CodeCodex

Turn vulnerability notes, disclosure reports, PoCs, source code, or Codex Security findings into self-contained, sceptically validated, natural-sounding vulnerability reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional.

40 3d ago A 54 tokens original Apache-2.0