Skill Claude CodeCodex
Use for a Codex dependency sweeper triage loop that watches advisories and lockfiles, proposes patch-only updates, rejects major upgrades without approval, and records reproducible verification commands.
27 tagged sarif, measured the same way as everything else here.
Browse within: github-action 9ai-security 8github-actions 7security-scanner 7
Skill Claude CodeCodex
Use for a Codex dependency sweeper triage loop that watches advisories and lockfiles, proposes patch-only updates, rejects major upgrades without approval, and records reproducible verification commands.
Skill Claude CodeCodex
Use when designing, implementing, auditing, hardening, or operating autonomous agent loops in this repository, including Codex/Grok/Claude Code style /loop workflows, explicit /goal runs, Git worktree orchestration, connector-backed automation, sub-agent execution, STATE.md handoffs, cost controls, maker/checker…
Skill Claude CodeCodex
Use for a Codex CI Sweeper triage loop that groups CI failures, classifies root causes, caps attempts, and proposes bounded minimal-fix candidates only after budget, denylist, and verifier gates.
Skill Claude CodeCodex
Scan an AI-built ("vibe-coded") repo for launch-blocking issues — leaked secrets, exposed API keys, broken auth, missing row-level security, unsafe payment wiring, vulnerable dependencies, and risky AI-layer surface (skills/MCP servers/agent prompts). Returns a 0-100 Ship Score with a banded verdict and ranked…
Skill Claude CodeCodex
Intentionally unsafe SkillGuard demo fixture.
Skill Claude CodeCodex
Sensitive data scanner — deterministic detection and obfuscation for text content.
Skill Claude CodeCodex
: bad yaml.
Skill Claude CodeCodex
This file intentionally omits Claude Skill frontmatter with name or description.
Skill Claude CodeCodex
Review SkillOps reference repository changes.
Skill Claude CodeCodex
Run deterministic SwiftUI and multi-module analysis after editing Swift code, before review, or when an AI-generated change may have introduced performance, task-lifetime, or module-boundary risks.
Skill Claude CodeCodex
Patterns for building reusable, accessible, production-grade React/TypeScript UI components. Use this whenever you create or review a UI component, build a form, design a component API, or work on the frontend — even if accessibility isn't explicitly mentioned. Covers state handling, a11y, responsiveness, and prop…
Skill Claude CodeCodex
Principles and checks for structuring code with clear boundaries, low coupling, and high cohesion. Use this whenever you are designing a new module, refactoring existing code, reviewing structure, deciding where logic should live, or untangling a messy codebase — even if the user doesn't say the words "clean…
Skill Claude CodeCodex
A go/no-go checklist for shipping code to production. Use this whenever you're about to deploy, finishing a feature, opening a PR for real traffic, or someone asks "is this production-ready". Covers correctness, errors, security, observability, and scale. Applies to Go, React/TypeScript, and C#/.NET.
Skill Claude CodeCodex
A synthetic fixture skill bundled with SkillGuard. It is inert -- it makes no real network or filesystem calls -- and exists only so SkillGuard's rule packs have real, safe text to match against. Do not install or run this in a real agent.
Skill Claude CodeCodex
A synthetic fixture skill bundled with SkillGuard for SG10 (marketplace typosquatting detection) end-to-end tests. Its declared name, "numpy", is an EXACT match against one of SG10's bundled well-known reference names -- standing in for that legitimate package's own official skill -- and must never be flagged: an…
Skill Claude CodeCodex
A synthetic fixture skill bundled with SkillGuard's SG09 (cross-skill privilege chaining) tests. On its own it only reads a local config file via a path-traversal pattern that happens to reach into a sensitive directory -- a real SG03 finding, but MEDIUM severity, so this skill passes cleanly (exit code 0) when…
Skill Claude CodeCodex
AI agent security gateway — policy enforcement, taint tracking, tool poisoning detection, DLP chain analysis, and SARIF output for CI/CD.