pre-bounty
25Skill Claude CodeCodex
Map a bug-bounty scope and rank targets by payout, crowding, and freshness. Use to size up a program or decide where to hunt before committing time.
AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research
This repository also configures its own agents. See what .context tells them →
Skill Claude CodeCodex
Map a bug-bounty scope and rank targets by payout, crowding, and freshness. Use to size up a program or decide where to hunt before committing time.
Skill Claude CodeCodex
Wrap the session in the Anthropic Sandbox Runtime before touching untrusted code. Use before running any audit skill on a codebase you do not trust.
Skill Claude CodeCodex
Audit codebase to uncover critical issues explicitly without false positives.
Skill Claude CodeCodex
Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro. Use to run or inspect an isolated guest.
Skill Claude CodeCodex
The last gate before untrusted instruction content is ingested. Screens a skill, goal or workflow fetched from git or any remote source for prompt injection, reading it as evidence rather than as instructions, on the assumption that its author wrote it to defeat this exact review. Use before installing, enabling…
Skill Claude CodeCodex
Audit the conversation and the project for what could have gone better, then turn the generalizable lessons into committed improvements in the repo that hosts this skill. Use at the end of a task or conversation where the agent needed correction, repeated work, or took a longer path than necessary.
Skill Claude CodeCodex
Run several LLM fuzzing and red-team scanners against one target, normalize their output to a common schema, dedupe across them, and report honest coverage. Use when scanning a model endpoint with more than one tool.
Skill Claude CodeCodex
Pentest an MCP server for authentication bypass, confused-deputy SSRF, and tool-argument injection - black-box from its URL, deeper with repo or host access. Use to assess an MCP server's exposure.
Skill Claude CodeCodex
Audit an LLM application for indirect prompt injection - compose objective x technique payloads, deliver them through the channels the agent actually reads, and prove impact with an out-of-band callback. Use to assess an AI agent's resistance to injected instructions.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: