security automation skills

20 tagged security automation, measured the same way as everything else here.

Browse within: bugbounty 12penetration-testing 12security-audit 11agent-orchestration 6agentic-workflow 6mcp-client 6

graphql

01

PentesterFlow/agent

Skill Claude CodeCodex

GraphQL pentest playbook — find the endpoint, dump the schema (introspection or field-suggestion fallback), then test for authorization gaps, query batching, alias overload, depth-based DoS, and SQLi/NoSQLi in resolver arguments. Use when the target exposes a /graphql endpoint, GraphiQL, Apollo, or accepts GraphQL…

1.3k 2mo ago A 75 tokens original Apache-2.0

jwt

02

PentesterFlow/agent

Skill Claude CodeCodex

JWT attack playbook — algorithm confusion (alg=none, HS/RS confusion), kid path traversal/SQLi, jku/x5u SSRF, weak HS256 cracking, and embedded JWK trickery. Use when the target uses JWTs for auth (header.payload.signature).

1.3k 2mo ago A 60 tokens original Apache-2.0

supabase

03

PentesterFlow/agent

Skill Claude CodeCodex

Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked servicerole) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse (insert/update/delete — e.g. forging…

1.3k 2mo ago A 120 tokens original Apache-2.0

huntbot

04

Matador-og/huntbot

Skill Claude CodeCodex

Autonomous offensive security pipeline. Use when the user wants to hunt bugs, run pentests, do recon, or manage huntbot targets. Triggers on security testing, bug bounty, vulnerability scanning, or any mention of huntbot commands.

10 2mo ago B 48 tokens

mappedsky/seizu

Skill Claude CodeCodex

Find the CVEs recorded against one GitHub repository, then read that repository's manifests and source through the external GitHub MCP tools to judge whether each vulnerability is actually reachable in this codebase.

5 3d ago A 46 tokens original Apache-2.0

repo-cve-findings

06

mappedsky/seizu

Skill Claude CodeCodex

Resolve a GitHub repository in the security graph and list the CVEs recorded against it, confirming from the graph's dependency data which vulnerable versions are actually installed. Produces the finding set that a reachability review then judges against the source.

5 3d ago A 54 tokens original Apache-2.0

mappedsky/seizu

Skill Claude CodeCodex

Judge whether already-identified CVEs are reachable in a repository's own code, by reading its source through the external GitHub MCP tools. Takes the finding list produced by the repository CVE findings review.

5 3d ago A 48 tokens original Apache-2.0

xsoar-pack-dev

08

mdrobniu/xsoar-pack-dev-skill

Skill Claude CodeCodex

Cortex XSOAR content pack development lifecycle - create packs, integrations, scripts, playbooks, run demisto-sdk lint/validate/pre-commit, build zip packs, manage versions and release notes, run unit tests, deploy to XSOAR instances, manage git branches/tags, handle marketplace vs local pack workflows. Use when the…

5 5mo ago D 95 tokens original Apache-2.0