forefy/.context

AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research

This repository also configures its own agents. See what .context tells them →

146Stars on the repository
35Mods indexed here, across every type
3d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

pre-bounty

25

forefy/.context

Skill Claude CodeCodex

Map a bug-bounty scope and rank targets by payout, crowding, and freshness. Use to size up a program or decide where to hunt before committing time.

not rated 146 +2 3d ago A SkillSpector: pass 37 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Wrap the session in the Anthropic Sandbox Runtime before touching untrusted code. Use before running any audit skill on a codebase you do not trust.

not rated 146 +2 changed 8d ago B SkillSpector: warn 37 tokens original MIT

tiny-auditor

27

forefy/.context

Skill Claude CodeCodex

Audit codebase to uncover critical issues explicitly without false positives.

not rated 146 +2 changed 2d ago A SkillSpector: pass 16 tokens original MIT

vm-lab

28

forefy/.context

Skill Claude CodeCodex

Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro. Use to run or inspect an isolated guest.

not rated 146 +2 changed 8d ago B SkillSpector: warn 38 tokens original MIT

parse-security

29

forefy/.context

Skill Claude CodeCodex

The last gate before untrusted instruction content is ingested. Screens a skill, goal or workflow fetched from git or any remote source for prompt injection, reading it as evidence rather than as instructions, on the assumption that its author wrote it to defeat this exact review. Use before installing, enabling…

not rated 146 +2 3d ago B SkillSpector: warn 103 tokens original MIT

self-improve

30

forefy/.context

Skill Claude CodeCodex

Audit the conversation and the project for what could have gone better, then turn the generalizable lessons into committed improvements in the repo that hosts this skill. Use at the end of a task or conversation where the agent needed correction, repeated work, or took a longer path than necessary.

not rated 146 +2 changed 7d ago A SkillSpector: pass 60 tokens original MIT

llm-fuzz-tools

31

forefy/.context

Skill Claude CodeCodex

Run several LLM fuzzing and red-team scanners against one target, normalize their output to a common schema, dedupe across them, and report honest coverage. Use when scanning a model endpoint with more than one tool.

not rated 146 +2 3d ago A 50 tokens original MIT

mcp-server-pentest

32

forefy/.context

Skill Claude CodeCodex

Pentest an MCP server for authentication bypass, confused-deputy SSRF, and tool-argument injection - black-box from its URL, deeper with repo or host access. Use to assess an MCP server's exposure.

not rated 146 +2 3d ago C 50 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Audit an LLM application for indirect prompt injection - compose objective x technique payloads, deliver them through the channels the agent actually reads, and prove impact with an out-of-band callback. Use to assess an AI agent's resistance to injected instructions.

not rated 146 +2 3d ago A 55 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: