MuhammedZohaib/patchman

Defensive AI security audit skill for Claude and Codex. Reviews codebases and web apps for OWASP Top 10, auth and authorization flaws, business logic bugs, tenant isolation gaps, insecure defaults, secret leaks, and ORM or N+1 query issues, then produces clear remediation guidance.

3Stars on the repository
21Mods indexed here, across every type
4mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

api-review

01

MuhammedZohaib/patchman

Skill Claude CodeCodex

Review an authorized API surface for access control, mass assignment, schema validation, rate limiting, SSRF, error leakage, webhook verification, and unsafe defaults. Use for REST, GraphQL, RPC, and webhook handlers.

3 4mo ago A 47 tokens original MIT

auth-review

02

MuhammedZohaib/patchman

Skill Claude CodeCodex

Perform a defensive review of authentication and authorization flows in an authorized codebase. Use for login, session, MFA, OAuth, password reset, cookie security, JWT validation, impersonation, privilege checks, and object-level access control.

3 4mo ago A 49 tokens original MIT

MuhammedZohaib/patchman

Skill Claude CodeCodex

Review an authorized application for business-logic vulnerabilities, workflow abuse, approval bypasses, replay conditions, quota circumvention, plan enforcement bugs, and state-transition errors. Use for billing, invites, approvals, refunds, admin actions, and multi-step workflows.

3 4mo ago A 56 tokens original MIT

pr-diff-review

04

MuhammedZohaib/patchman

Skill Claude CodeCodex

Review an authorized pull request diff for security regressions. Use when changes modify trust boundaries, auth logic, data-access scope, file handling, logging, headers, or secrets.

3 4mo ago A 40 tokens original MIT

query-review

05

MuhammedZohaib/patchman

Skill Claude CodeCodex

Review an authorized codebase for ORM misuse, N+1 query patterns, authorization-after-fetch bugs, raw SQL risks, cache key collisions, and missing tenant scopes. Use for data-access layers and security-adjacent performance pitfalls.

3 4mo ago A 49 tokens original MIT

quick-triage

06

MuhammedZohaib/patchman

Skill Claude CodeCodex

Perform a rapid defensive triage on an authorized code area when time is limited. Use to find the most plausible high-impact issues fast, then recommend the next best review target.

3 4mo ago A 40 tokens original MIT

security-audit

07

MuhammedZohaib/patchman

Skill Claude CodeCodex

Conduct authorized defensive security audits of codebases and web applications. Use for broad appsec review across OWASP, authz, business logic, SSRF, XSS, CSRF, injection, file upload, secrets, logging, and tenant isolation. Produces structured findings with severity, confidence, evidence, and safe remediation…

3 4mo ago A 70 tokens original MIT