audit
73xChechi/xche-ai-app-security-pack
Skill Claude CodeCodex
Audit the selected code or recent changes against the xChe AI-App Security policy (OWASP / API / LLM / MCP). Reports prioritized findings with fixes.
573 tagged devsecops, measured the same way as everything else here.
Browse within: cybersecurity 219ai-security 209appsec 93ai-hacking 58ai-pentesting 58DAST 57compliance 57bug-bounty 51CISO 48blue-team 48cowork 47data-exfiltration 47malware-detection 47Prompt Injection 42
xChechi/xche-ai-app-security-pack
Skill Claude CodeCodex
Audit the selected code or recent changes against the xChe AI-App Security policy (OWASP / API / LLM / MCP). Reports prioritized findings with fixes.
xChechi/xche-ai-app-security-pack
Skill Claude CodeCodex
Secure-by-default coding standards for AI-built apps. Apply these rules whenever writing or modifying application code that handles authentication, authorization, databases or SQL, HTTP APIs, user input, file uploads, secrets or config, sessions or cookies, or LLM/MCP integrations.
Skill Claude CodeCodex
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
Skill Claude CodeCodex
Execute the implementation plan by processing and executing all tasks defined in tasks.md.
Skill Claude CodeCodex
Execute the implementation planning workflow using the plan template to generate design artifacts.
Skill Claude CodeCodex
A benign skill that provides helpful text utilities.
Skill Claude CodeCodex
A skill whose code violates the plugin-level policy manifest.
Skill Claude CodeCodex
A malicious Codex skill that exfiltrates data.
Skill Claude CodeCodex
Official AI Agent Skill for Envault Secrets Management platform. Enforces strict zero-hardcode rules, Client-Side Encryption, and Human-in-the-Loop (HITL) approval workflows.
Skill Claude CodeCodex
Design engineering principles for making interfaces feel polished. Use when building UI components, reviewing frontend code, implementing animations, hover states, shadows, borders, typography, micro-interactions, enter/exit animations, or any visual detail work. Triggers on UI polish, design details, "make it feel…
Skill Claude CodeCodex
Guide for implementing smooth, native-feeling animations using React's View Transition API ( component, addTransitionType, and CSS view transition pseudo-elements). Use this skill whenever the user wants to add page transitions, animate route changes, create shared element animations, animate enter/exit of components…
netresearch/enterprise-readiness-skill
Skill Claude CodeCodex
Use when evaluating projects for production or enterprise readiness, implementing supply chain security (SLSA, cosign, SBOMs, pnpm), hardening CI/CD pipelines, establishing quality gates (TYPO3: CI matrix PHP 8.2-8.5 x TYPO3 12.4/13.4/14.3 LTS), pursuing OpenSSF Best Practices Badge (Passing/Silver/Gold) or OSPS…
parousia8888/web-app-security-skill
Skill Claude CodeCodex
End-to-end security program for a web app — scope/authorization gate, frontend exposure reduction, API security (IDOR/BOLA, brute force, rate limiting, race conditions), LLM security (prompt injection, jailbreak, cost abuse), OAuth/OIDC identity, server-side code audit, database isolation, supply chain (SBOM/SCA/SRI)…
Skill Claude CodeCodex
This skill should be used when the user asks to "add authentication", "secure login", "implement rate limiting", "JWT best practices", "session security", or "OAuth setup". Teaches authentication hardening patterns.
Skill Claude CodeCodex
This skill should be used when the user asks to "secure my API keys", "handle secrets safely", "fix exposed key", "environment variables setup", or "rotate compromised keys". Teaches secure secret management patterns per framework.
Skill Claude CodeCodex
This skill should be used when the user asks to "run a security scan", "check for vulnerabilities", "security audit", "ship secure", "vibecheck scan", or "pre-deploy security check". Runs 156 automated security checks across 15 categories and produces a categorized vulnerability report.
Skill Claude CodeCodex
Run CH015 vulnerability assessment workflows for source-code security architecture review, 8-dimension analysis, compliance checks, self-verification, evidence verification, and VA reporting.
Skill Claude CodeCodex
Run CH015 adversarial verification workflows to independently validate security reports, recheck file-line evidence, find false positives, severity errors, missed findings, and dependencies.
Skill Claude CodeCodex
Run CH015 security design review workflows for PRDs and specs to produce security opinions or review findings mapped to standards and regulatory requirements.
HermeticOrmus/LibreSecOps-Claude-Code
Skill Claude CodeCodex
Threat hunting is the proactive, analyst-driven search for threats that have evaded automated detection. Unlike detection engineering (which builds rules that fire automatically), hunting is a human-led investigation that uses hypotheses, data analysis, and domain expertise to find adversary activity that does not…
HermeticOrmus/LibreSecOps-Claude-Code
Skill Claude CodeCodex
Skill "crypto-algorithms" from HermeticOrmus/LibreSecOps-Claude-Code, covering crypto algorithms, knowledge base, the algorithm decision tree, key size guidelines (2025+) and modes of operation (symmetric encryption).
HermeticOrmus/LibreSecOps-Claude-Code
Skill Claude CodeCodex
Every cryptographic key goes through a lifecycle. Each phase has security requirements.
Skill Claude CodeCodex
Pre-install security advisor. Activate when the user mentions installing a Claude Code plugin, MCP server, or any third-party agent tool. Offer to run an Assay scan against the target before they install.
Skill Claude CodeCodex
USAP agent skill for Security Requirements Review. Use for proactive analysis of design documents — POA&M, PRDs, architecture docs, requirements specs — to extract security gaps before any alerts fire.