Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
Bundle skill for authorized API contract and trust-boundary review. Use when requests involve OpenAPI or Swagger specs, JSON APIs, schema drift, auth declarations, token handling, TLS assumptions, or dependency-driven API risk and Codex should coordinate the relevant review skills.
A cloud-security audit guide for checking the safety of AWS, Azure, and Google Cloud environments. It covers access rights, networks, data protection, compliance, and audit logs.
A container-security testing guide for Docker and Kubernetes, technologies used to package and run applications. It covers image contents, running-container settings, and Kubernetes permissions and network rules.
A security-testing guide for CSRF, or cross-site request forgery, where a malicious site tricks a logged-in browser into sending unwanted actions to another site.
Bundle skill for CTF binary triage and solve routing. Use when the prompt mentions ELF, nc services, memory corruption, WASM reversing, native binaries, or uncertain binary challenge direction and Codex should coordinate the core CTF binary skills before deeper specialization.
A general workflow for solving CTF challenges, which are security puzzles that award a hidden flag when solved. It first sorts a challenge into Web, Crypto, Pwn, Reverse, Forensics, or Misc categories.
Bundle skill for digital forensics and artifact-first triage. Use when requests involve PCAPs, stego, suspicious images, metadata, extracted files, or mixed forensic artifacts and Codex should coordinate the initial triage skills before deeper analysis.
A guide to testing IDOR, a web security flaw where changing a user-supplied identifier can expose someone else’s file or record. It covers checks for horizontal access between users and vertical access to administrator resources.
A workflow for reviewing JWTs and other login or session tokens in CTF challenges. JWTs are signed text tokens that can carry information such as a user role or expiration time.
A security-testing guide for LDAP injection, where unescaped user input changes a directory search or login query. LDAP is a system commonly used to store and look up users and permissions.
A methodology for testing the security of Android and iOS mobile applications. It covers the app itself, stored and transmitted data, authentication, permissions, sessions and network communications.
A guide for testing whether web APIs—the endpoints software uses to exchange data—handle identity, permissions, input, business rules, and errors safely.
A review process for OpenAPI or Swagger documents, which describe how JSON-based web APIs work. It checks authentication, permissions, input fields, errors and high-impact operations against the documented contract.
A first-pass guide for examining PCAP files, which are recorded network conversations, and network logs from capture-the-flag challenges.
★not rated 0 1mo agoA42 tokens
originalApache-2.0
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: