application security skills

143 tagged application security, measured the same way as everything else here.

Browse within: antigravity 57authentication 57ai-security 41devsecops 23acp 21agent-client-protocol 21code-scanning 21DAST 19libre-x-claude-code 19bug-bounty 14agentic-appsec 12appsec 12pixee 12bugbounty 11

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an authorized external…

3.9k 2d ago A 145 tokens original MIT

bugcrowd-reporting

02

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints…

3.9k 2d ago A 171 tokens original MIT

hunt-aspnet

03

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure, load-balanced ViewState cross-node failures, SafeControl enumeration via reflection, customErrors mode=Off…

3.9k 2d ago A 98 tokens original MIT

arcjet/arcjet-js

Skill Claude CodeCodex

Integrate Arcjet security into a Vercel Eve agent using @arcjet/guard — add guard gates to tools and connections, screen inbound messages, and record agent lifecycle events correlated to the session. Use when asked to add Arcjet to an Eve agent, rate limit its tools, guard connection access, or screen inbound messages.

681 2d ago A 77 tokens original Apache-2.0

arcjet/arcjet-js

Skill Claude CodeCodex

Integrate Arcjet security into a Genkit JS agent using @arcjet/guard — wrap ai.defineTool, put guardMiddleware on generate({ use }) for unwrapped / MCP / filesystem tools, and read a caller-owned id from generate({ context }). Use when asked to add Arcjet to genkit, rate limit its tools, screen inbound messages, or…

681 2d ago A 89 tokens original Apache-2.0

arcjet/arcjet-js

Skill Claude CodeCodex

Integrate Arcjet security into a LangChain JS createAgent using @arcjet/guard — wrap tool() / StructuredTool, put guardMiddleware on createAgent({ middleware }) for MCP / unwrapped tools, and read configurable.threadid for correlation. Use when asked to add Arcjet to langchain createAgent, rate limit its tools, screen…

681 2d ago A 101 tokens original Apache-2.0

cyber-neo

07

Hainrixz/cyber-neo

Skill Claude CodeCodex

Comprehensive cybersecurity analysis for any local project. Scans for dependency vulnerabilities (SCA), code security patterns (SAST), leaked secrets, authentication/authorization flaws, cryptographic weaknesses, misconfigurations, supply chain risks, and CI/CD security. Covers all OWASP 2025 Top 10 and CWE Top 25.…

253 1mo ago A 123 tokens original MIT

deep-security-scan

08

bex-co/bex-security

Skill Claude CodeCodex

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the…

40 2d ago A 87 tokens original Apache-2.0

track-findings

09

bex-co/bex-security

Skill Claude CodeCodex

Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use…

40 2d ago A 79 tokens original Apache-2.0

bex-co/bex-security

Skill Claude CodeCodex

Turn vulnerability notes, disclosure reports, PoCs, source code, or Codex Security findings into self-contained, sceptically validated, natural-sounding vulnerability reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional.

40 2d ago A 54 tokens original Apache-2.0

add-resource-skill

11

pixee/pixee-cli

Skill Claude CodeCodex

Authors a new skills.sh-formatted skill for the pixee CLI under skills/pixee- /SKILL.md. Trigger on requests like "add a resource skill", "write a skill for pixee X", "author a pixee skill", or "publish a skill for the new Y subcommand". Captures pixee-specific conventions (one skill per sub-command with a shared…

31 7d ago A 132 tokens

audit-skills

12

pixee/pixee-cli

Skill Claude CodeCodex

Detects and closes drift between the latest released Pixee CLI surface and the published skills/pixee- skills on origin/main. Trigger after a new pixee release, on a /audit-skills request, or when the contributor asks 'are the skills up to date?', 'is there a missing pixee skill?', 'does the CLI match the skills?'…

31 7d ago A 157 tokens

pixee-scan

13

pixee/pixee-cli

Skill Claude CodeCodex

List, view, analyze, create, and delete Pixee scans with filters for repository, branch, detector tool, and analysis state.

31 7d ago A 32 tokens

opencode-pentester

14

humaidhahm/opencode-pentester

Skill Claude CodeCodex

Coordinate penetration testing and AI self-code audits via schema-enforced, event-driven engine. All attack categories, domains, tools, and checklists are stored in SQLite (findings.db) and loaded JIT by engine/router.py.

21 6d ago A 52 tokens

pentest

15

humaidhahm/opencode-pentester

Skill Claude CodeCodex

Coordinate penetration testing. Deploy executors, aggregate results, generate reports.

21 6d ago A 0 tokens

best-in-code

16

kingggg5/shipproof

Skill Claude CodeCodex

Run an adaptive, reusable software-delivery harness across AI models with project management, planning, research, design, frontend, backend, QA, durable scoped memory, capability fallbacks, bounded discovery, and human approval gates. Use when the user invokes Harness or asks for an end-to-end build, review, bug…

18 5d ago A 89 tokens original MIT

kingggg5/shipproof

Skill Claude CodeCodex

Audit a repository or service for release-blocking bugs, security, data/privacy, AI-agent, supply-chain, operability, and scale risks. Use for deep code audits, threat models, pre-production reviews, vulnerability triage, incidents, defensive investigation, release gates, or evidence-based 10k-to-1M-user readiness.

18 5d ago A 72 tokens original MIT

kingggg5/shipproof

Skill Claude CodeCodex

Design, write, refactor, or optimize production code so it is secure, correct, resource-bounded, observable, and maintainable. Use for full-stack features, APIs, databases, AI/RAG/MCP tools, CPU/RAM/latency work, 10k-to-1M-user planning, or authorized kernel, browser, parser, protocol, and defensive…

18 5d ago A 86 tokens original MIT

anti-ai-slop-design

19

prangishviliAbe/agent-skills

Skill Claude CodeCodex

Create, implement, or critique refined, human-quality digital product design while preventing generic AI-looking output. Use for websites, landing pages, SaaS products, dashboards, mobile apps, UI components, design systems, wireframes, Figma work, frontend styling, visual direction, brand-led interfaces, and image or…

4 14d ago A 140 tokens

premium-web-motion

20

prangishviliAbe/agent-skills

Skill Claude CodeCodex

Design, audit, and implement purposeful premium website motion without copying a brand's visual identity. Use for UI animation, microinteractions, hover and press feedback, page and view transitions, scroll storytelling, gesture and drag behavior, loading and skeleton choreography, motion-system and token design, and…

4 14d ago A 83 tokens

security

21

prangishviliAbe/agent-skills

Skill Claude CodeCodex

Perform evidence-based application security work — threat modeling, code auditing, exploitability analysis, secure implementation, incident triage, and remediation — across web apps, APIs, authentication, sessions, authorization, databases, file uploads, third-party integrations, AI agents and LLM tooling, WordPress…

4 14d ago A 125 tokens

HermeticOrmus/LibreSecOps-Claude-Code

Skill Claude CodeCodex

Threat hunting is the proactive, analyst-driven search for threats that have evaded automated detection. Unlike detection engineering (which builds rules that fire automatically), hunting is a human-led investigation that uses hypotheses, data analysis, and domain expertise to find adversary activity that does not…

4 3mo ago A 0 tokens original MIT