EresusSecurity/appsec-skills

Production-ready AI AppSec skills for SAST, threat modeling, remediation, PR security review, and serialization abuse analysis.

6Stars on the repository
11Mods indexed here, across every type
4mo agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Language-specific vulnerability hotspot reference for manual code audit. Trigger when the user asks to: "what sinks should I look for in Java?", "Python security hotspots", "dangerous functions in Go", "JavaScript injection patterns", or when starting a manual audit of a specific language and needing a sink/source…

6 4mo ago B 70 tokens original Apache-2.0

eresus-deser-audit

02

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Deserialization vulnerability audit skill with gadget chain knowledge for all major languages. Trigger when the user asks to: "audit deserialization", "check for insecure deserialization", "find pickle vulnerabilities", "Marshal.load audit", "gadget chain analysis", "check for unsafe YAML loading", or when reviewing…

6 4mo ago B 84 tokens original Apache-2.0

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Elite manual security code review skill for deep, adversarial vulnerability hunting and exploit-chain discovery. Trigger when the user asks to: "do a deep security audit", "manual code review", "find exploit chains", "hunt for logic bugs", "red-team this codebase", "do an offensive security review", "review this like…

6 4mo ago A 145 tokens original Apache-2.0

eresus-php-audit

04

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Deep PHP-specific security audit skill covering injection, deserialization, file operations, auth bypass, POP chain discovery, and CMS-specific patterns. Trigger when auditing PHP code: "audit this PHP app", "find PHP security issues", "check Laravel/WordPress for vulnerabilities", "PHP SAST review", "check for PHP…

6 4mo ago A 92 tokens original Apache-2.0

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Security-focused pull request and diff review skill for finding newly introduced vulnerabilities, risky regressions, and missing security tests in changed code. Trigger when the user asks to: "review this PR for security", "check this diff for vulns", "do a security code review", "audit changed files", or wants…

6 4mo ago A 90 tokens original Apache-2.0

eresus-python-audit

06

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Deep Python-specific security audit skill with 50+ vulnerability class coverage across 7 categories. Trigger when auditing Python code: "audit this Python app", "find Python security issues", "check Flask/Django for vulnerabilities", "Python SAST review", "check for pickle vulnerabilities", "review this FastAPI code".…

6 4mo ago A 101 tokens original Apache-2.0

eresus-remediator

07

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Security remediation skill for fixing confirmed or likely SAST findings in source code. Trigger when the user asks to: "fix a vulnerability", "patch this security bug", "remediate SAST findings", "harden this endpoint", "make this auth flow safe", or wants code changes that remove a confirmed security issue while…

6 4mo ago A 84 tokens original Apache-2.0

eresus-sast-scanner

08

EresusSecurity/appsec-skills

Skill Claude CodeCodex

General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. Trigger when the user asks to: "analyze code for vulnerabilities", "review code security", "find security bugs", "do a SAST scan", "check for [vulnerability type] in code", "audit source code", or requests a security code…

6 4mo ago A 100 tokens original Apache-2.0

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Serialization and deserialization security review skill for object mappers, parser pipelines, message formats, and state transfer mechanisms. Trigger when the user asks to: "review serialization security", "check deserialization", "audit Jackson/Fastjson/YAML/XML parsing", "look for gadget-chain risk", "review session…

6 4mo ago A 100 tokens original Apache-2.0

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Threat modeling skill for new features, services, endpoints, or repositories. Trigger when the user asks to: "threat model this", "analyze attack surface", "find abuse cases", "map trust boundaries", "prioritize security review", or wants a structured security design review before or alongside coding. Complements…

6 4mo ago A 84 tokens original Apache-2.0

EresusSecurity/appsec-skills

Skill Claude CodeCodex

GHSA/CVE variant analysis workflow for finding similar vulnerability patterns across a codebase. Trigger when the user asks to: "find variants of this CVE", "GHSA variant analysis", "find similar bugs", "hunt for the same pattern", "are there other places with this vulnerability?", or when a known vulnerability is…

6 4mo ago A 85 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: