bx33661/oh-my-vul

Evidence-first vulnerability research workspace and Skills for Claude Code and Codex.

This repository also configures its own agents. See what oh-my-vul tells them →

4Stars on the repository
18Mods indexed here, across every type
20d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

omv-audit

01

bx33661/oh-my-vul

Skill Claude CodeCodex

Deep-audits a candidate finding from an Evidence.v1 file. Use when the user has an omv-find result they want to investigate further, wants to prove or disprove a vulnerability, needs to fill Evidence.v1 fields for omv-report, or invokes /omv-audit. Reads .omv/findings/ .yaml and produces a confirmed or blocked finding…

not rated 4 20d ago A 88 tokens original MIT

omv-critic

02

bx33661/oh-my-vul

Skill Claude CodeCodex

Performs adversarial pre-submission review of an Evidence.v1 finding plus optional ThreatMap.v1 and Verification.v1 sidecars. Use before /omv-report when the user wants likely CNA rejection reasons, report argument quality review, a rejectrisk rating, or a recommendation of which researchergoal (VulDB, CVE, GHSA…

not rated 4 20d ago A 83 tokens original MIT

omv-dedup

03

bx33661/oh-my-vul

Skill Claude CodeCodex

Checks whether an Evidence.v1 finding is likely already disclosed. Use when the user asks to deduplicate a finding, check CNA duplicate risk, search NVD/GHSA/OSV/ecosystem advisory databases or public discussion (issues, PRs, commits, blogs), or invokes /omv-dedup. Produces deterministic queries, grades novelty risk…

not rated 4 20d ago A 91 tokens original MIT

omv-disclose

04

bx33661/oh-my-vul

Skill Claude CodeCodex

Helps prepare responsible disclosure communications and timelines from an Evidence.v1 finding. Use when the user asks to contact a vendor, create initial/follow-up/deadline disclosure email templates, plan a 90-day timeline, record disclosure fields, or invokes /omv-disclose.

not rated 4 20d ago A 61 tokens original MIT

omv-find

05

bx33661/oh-my-vul

Skill Claude CodeCodex

Finds and ranks open-source packages worth auditing for passive CVE/VulDB research. Use when the user asks for vulnerability research targets, CVE hunting candidates, packages to audit, projects to fuzz, or /omv-find. Supports npm, Python, Go, Rust, Java, Ruby, PHP, C#, Swift, Dart, Elixir, Perl, R, and Lua, with…

not rated 4 20d ago A 122 tokens original MIT

omv-radar

06

bx33661/oh-my-vul

Skill Claude CodeCodex

Variant-driven diffusion hunting for oh-my-vul. Use when the user has a confirmed or publicly disclosed vulnerability pattern and wants to find the same bug class in sibling packages, forks, or downstream consumers; also when they ask for watchlist maintenance, radar brief, or /omv-radar. Reads seeds from findings and…

not rated 4 20d ago A 87 tokens original MIT

omv-report

07

bx33661/oh-my-vul

Skill Claude CodeCodex

Generate a complete, ready-to-submit VulDB vulnerability report and CVE request. Covers all major package ecosystems: npm, pip, Go, Cargo (Rust), RubyGems, Maven, Gradle, NuGet, Composer (PHP), CocoaPods, Swift Package Manager, pub (Dart/Flutter), Hex (Elixir), CPAN (Perl), CRAN (R), LuaRocks. Use this skill whenever…

not rated 4 20d ago A 185 tokens original MIT

omv-repro

08

bx33661/oh-my-vul

Skill Claude CodeCodex

Guides a researcher through local reproduction of a vulnerability finding. Use when the user has an omv-audit result with evidence.reproducer filled but evidence.observedresult still unknown, wants to confirm a finding by running it locally, or invokes /omv-repro. Reads .omv/findings/ .yaml and guides step-by-step…

not rated 4 20d ago A 91 tokens original MIT

omv

09

bx33661/oh-my-vul

Skill Claude CodeCodex

Skill "omv" from bx33661/oh-my-vul, covering omv, commands, skills in this collection, registry and state directory.

not rated 4 20d ago A 79 tokens original MIT

using-omv

10

bx33661/oh-my-vul

Skill Claude CodeCodex

Bootstrap discipline for oh-my-vul research. Use at the start of any vulnerability research conversation, when the user asks to audit/find/report a package, dig for CVEs, or run omv skills — and before claiming a finding is confirmed, ready to submit, or “done”. Establishes mandatory process, hard gates, and…

not rated 4 20d ago A 86 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: