breachproof
49Skill Claude CodeCodex
Autonomous security audit and hardening that scans, exploits, fixes, and re-scans a codebase to zero findings, mapped to SOC 2.
1,196 tagged cybersecurity, measured the same way as everything else here.
Browse within: devsecops 476bug-bounty 400blue-team 369ai-security 324agent 293hacking 214generative-ai 202LangChain 200ctf 190ai-pentesting 170appsec 160autonomous-pentesting 157ai-hacking 154ctf-tools 151
Skill Claude CodeCodex
Autonomous security audit and hardening that scans, exploits, fixes, and re-scans a codebase to zero findings, mapped to SOC 2.
Skill Claude CodeCodex
Operate only in authorized scope: bug bounty targets explicitly in scope, owned systems, defensive reviews, or labs. Decline or pause on requests involving unauthorized access, stealth, persistence, service disruption, credential abuse, real data theft, or abuse of third-party systems.
Skill Claude CodeCodex
Expert Canadian GRC and cyber law advisor covering OSFI B-10/B-13/E-21/I-CRT, FSRA, AMF/Loi 25, BCFSA, CIRO, AER Reg 84/CSA Z246.1, PIPEDA, PHIPA, PIPA BC, PIPA AB, Bill C-26, and AIDA. Use this skill whenever the user mentions any Canadian financial regulator, provincial privacy law, Alberta energy security, Canadian…
Skill Claude CodeCodex
Comprehensive reference for the VirusTotal API v3, covering authentication, rate limits, endpoint usage, and the critical differences between Free (Public) and Premium (Enterprise) tiers. Use this skill whenever a user asks about VirusTotal, VT API, scanning files or URLs with VirusTotal, threat intelligence lookups…
Skill Claude CodeCodex
Authorized software reverse engineering, binary analysis, and program comprehension for legitimate purposes including security review, interoperability, migration, modernization, debugging, and documentation. USE WHEN: user needs to analyze software they own or have explicit authorization to inspect, including legacy…
JesusConwellpy/secagent-skills
Skill Claude CodeCodex needs its repo
Local LLM-Wiki knowledge system. Bootstrap a structured wiki, write entries using precise templates, full-text search, cross-agent knowledge sharing, cross-session inheritance.
YankielDBC2/saas-cybersecurity
Skill Claude CodeCodex
Audit and safely harden authorized SaaS web applications across frameworks and hosting providers. Use for OWASP-aligned reviews, runtime browser checks, HTTP headers, XSS/CSRF, access control, secrets, payments, uploads, privacy, abuse controls, supply-chain risk, link injection, or security remediation; do not use…
Skill Claude CodeCodex
Run a standardized XORCISE agent benchmark — pick a ready-made playbook (or build your own from existing missions), point it at any OpenHands-supported model(s), and get a polished eval-card HTML report of how each model performed across the missions. Warns you about cost before spending anything.
Skill Claude Code
Set up the development environment for the project. Use when starting work on the project, when dependencies are out of sync, or to fix environment setup failures.
Skill Claude CodeCodex
Audit professionnel complet d'un projet logiciel couvrant architecture, code mort, dette technique, dépendances, API, authentification, autorisation, sécurité applicative, CI/CD, performance, production et validation finale.
Skill Claude CodeCodex
Operate an already configured burp-mcp server for authorized web application security testing, penetration testing, vulnerability assessment, and Burp Suite automation: inspect Proxy HTTP/WebSocket history, scope, and site map; craft and replay requests in Repeater; run bounded parallel fuzzing, race condition jobs…
Asaiuta/reverse-workbench-skill
Skill Codex
Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
Skill Claude Code
Lightweight AI security guard that intercepts risky install/download commands (npm, npx, pip, cargo, git clone) to block known malicious packages and scan for suspicious code. Invoke ONLY when user runs install/download/clone commands.
Skill Claude CodeCodex
ClawHub dashboard helper.
Skill Claude CodeCodex
Use when performing strict read-only SSH inspections of Ubuntu/Linux servers for security review, EU cybersecurity compliance evidence, server readiness, operational disorder, waste, drift, CIS-style hardening gaps, runtime visibility, identity/access, network exposure, backups, observability, and unknowns. Requires…
Skill Claude CodeCodex
Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for…
Skill Claude CodeCodex needs its repo
7-layer AI security + ML detection for OpenClaw. Covers all 10 OWASP Agentic AI risks — prompt injection, tool misuse, memory poisoning, data exfiltration, and more — across ALL channels (Signal, Telegram, Discord, WhatsApp, web) simultaneously.
nidhish28guhan-netizen/hachiman-agent
Skill Claude CodeCodex needs its repo
Hachiman is a watchman that thinks like an attacker. On an authorized target it runs.
ck3938700-ship-it/anjian-agent
Skill Claude CodeCodex
Use AnJian MCP tools for an authorization-gated website security assessment and Chinese report.
Skill Claude CodeCodex
SBOMApp is a remote MCP server that provides Software Bill of Materials (SBOM) generation, vulnerability scanning, and dependency analysis capabilities to AI assistants. It enables any MCP-compatible AI client to analyze software projects for security risks, license compliance, and dependency health — directly from…
astroicers/security-weekly-mcp
Skill Claude CodeCodex
A workflow for maintaining a Taiwan-focused security glossary and producing weekly security reports. It supports Chinese-language term management, terminology checks, news collection, and report generation.
threadlinqs-cmd/intelthreadlinqs-mcp
Skill Claude CodeCodex
Operate the Threadlinqs Intelligence MCP server — 73 threat-intelligence tools covering threats, detection rules in Splunk SPL / Microsoft KQL / Sigma, IOCs, threat actors, CVE/CWE enrichment, MITRE ATT&CK coverage and prediction, C2 infrastructure, the correlation graph, and STIX 2.1 / ATT&CK Navigator export. Use…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: