Skill Claude CodeCodex
APK/EXE/二进制:UniApp/DCloud/Flutter逆向,证书固定绕过,导出组件,内存破坏exploit链,IoT固件。Use when reversing APK/EXE, UniApp/Flutter, native .so, or memory-corruption exploits.
91 tagged ai security tool, measured the same way as everything else here.
Browse within: ai-security 65gpt 31openai 31ai-cybersecurity 24ai-penetration-testing 24ctf-tools 24AI Safety 20cybersecurity 20exploitation 11vuln_assess 10appsec 8ctfs 8
Skill Claude CodeCodex
APK/EXE/二进制:UniApp/DCloud/Flutter逆向,证书固定绕过,导出组件,内存破坏exploit链,IoT固件。Use when reversing APK/EXE, UniApp/Flutter, native .so, or memory-corruption exploits.
Skill Claude CodeCodex
A method for finding attack chains by combining smaller capabilities such as reading files, writing files, making server requests, or using credentials. It treats a serious outcome as a sequence of separately gained abilities.
Skill Claude CodeCodex
专题实战利用:GoEdge私钥导出,灰产CDN取证,ARP MITM,CDN→S3 STS链,宝塔+UniApp,AI IDE API反代,OCS+MinIO;含references/scripts支持文件索引。Use when applying specialized playbooks for GoEdge, CDN, ARP MITM, BT Panel, OCS, MinIO.
Skill Claude CodeCodex
Active Directory pentest playbook — Kerberos, LDAP, GPO, ADCS, delegation, lateral movement, DA paths. Load at the START of an AD engagement or when a Windows domain / DC is found. Triggers - domain controller, Kerberos 88, LDAP 389/636, domain SMB, BloodHound, kerberoast, AS-REP, NTLM, ESC1-8.
Skill Claude CodeCodex
Turn a foothold into a RELIABLE pivot (SOCKS tunnel + persistent shell) so internal volume never rides a fragile stateless RCE. Use the moment you have code-exec on a dual-homed/edge host and need to reach an internal segment. Triggers - dual-homed host, "not reachable from my box", internal CIDR behind a foothold…
Skill Claude CodeCodex
SMB/CIFS attack techniques — null sessions, share enumeration, NTLM relay, EternalBlue, signing checks. Use when SMB is found. Triggers - ports 445/139, netbios, MS17-010 EternalBlue, signing:False, null session, share access, PetitPotam/coerce.
Skill Claude CodeCodex
Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner. Trigger on any natural safety question about an external skill — "is this skill safe?", "audit / scan / review this skill", "should I install this?", "trustworthy?", "any…
Skill Claude CodeCodex
Check whether a CoSAI Risk Map entry is pitched at the right altitude (granularity). For a control: objective-not-implementation, not-a-restated-risk, posture-not-mandate, solved-problem, no-duplication. For a risk: the merge-vs-distinct two-test, threat-not-control-gap, and real-not-hypothetical. For a component: the…
Skill Claude CodeCodex
Audit framework mappings — an existing entity's mappings, the whole corpus, or a candidate value proposed for an entity not yet in the corpus — against the framework mappings style guide. Use when reviewing, auditing, or pre-PR authoring mapping changes for risks.yaml, controls.yaml, or personas.yaml.
Skill Claude CodeCodex
Ground CoSAI Risk Map terminology in established security terms of art. Use when authoring or critiquing a Control, Risk, Component, or Persona title or description to check a proposed term against the canonical (NIST-first) vocabulary, replace an invented term with its established equivalent, generalize a…
trnt-ai/trent-openclaw-security-assessment
Skill Claude CodeCodex
Assess your Agent deployment against security risks using Trent.
Skill Claude CodeCodex
Scans extensions, skills, and code for security threats: prompt injection, malicious code, obfuscation, data exfiltration. Also scans inbound messages for injection patterns automatically.
Skill Claude CodeCodex
A simple greeting skill that says hello.
Skill Claude CodeCodex
A reference catalog of natural spring and easing curves for animating UI elements: buttons, modals, and page transitions. Includes recommended duration and easing-curve pairings for common interaction patterns like pop-in, slide-over, and fade-through.
Skill Claude CodeCodex
Installs the HTTP client library, reads the local report file, uploads it to the dashboard, and then runs the local build tool to refresh the cached copy. A companion Kubernetes Job warms the build cache for nested (Docker-in-Docker) builds.
Skill Claude CodeCodex
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use…
Skill Claude CodeCodex
Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer…
Skill Claude CodeCodex
Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for…