dependency-audit
241Skill Codex
A security review of project dependencies managed by npm, Yarn, or pnpm. It can inspect a local project directory or a remote Git repository for known dependency risks.
16,787 tagged Security, measured the same way as everything else here.
Browse within: cybersecurity 489bug-bounty 288agent 226generative-ai 178LangChain 174hacking 174autonomous-pentesting 140cloud-security 127claude-ai 113redteam 113LLM 105skills 105cors-exploitation 94firebase-hacking 93
Skill Codex
A security review of project dependencies managed by npm, Yarn, or pnpm. It can inspect a local project directory or a remote Git repository for known dependency risks.
TheArchitectit/agent-guardrails-template
Skill Claude CodeCodex
Topic-based content filtering to block harmful or unauthorized content in agent output.
Skill Claude Code
A scam-message checker that analyzes suspicious texts, images, or conversation descriptions. It can identify the likely stage of a scam and suggest what the sender may try next.
Skill Claude CodeCodex
Simultaneous Launch Button - Two-person rule for destructive commands. Use when coordinating dangerous operations between agents, requiring peer review for rm -rf, git push --force, kubectl delete, DROP TABLE, or terraform destroy.
Skill Claude CodeCodex
Review the supplied artifact for correctness, security, maintainability, and test coverage. Report concrete findings before general suggestions, and distinguish verified defects from risks.
Skill Claude CodeCodex
Deepfake detection and media safety — detect AI-generated audio, images, video, and text, trace synthesis sources, and analyze media intelligence using direct Resemble AI API calls.
Skill Claude CodeCodex
Run and troubleshoot privacy-preserving, local DSPy RLM security audits for large legacy .NET codebases. Use when asked to scan repositories for vulnerabilities, tune RLM/tool limits, fix truncation/stall issues, or produce actionable markdown/json audit outputs without loading entire codebases into model context.
Skill Claude CodeCodex
Iteratively review an instar-development spec with multi-angle internal reviewers (security, scalability, adversarial, integration, decision-completeness, lessons-aware) and real cross-model external reviewers routed through the agent's own installed CLIs (codex → GPT-tier, gemini → Gemini-tier; one pass per available…
Skill Claude Code
Active Directory attack reference — BloodHound Cypher queries, Kerberos attack decision tree, ACE/ACL abuse, ADCS ESC1-8, and AD misconfig checklist.
Skill Claude Code
Preflight security scanner for AI coding agents — scans deployment config, skills/MCP servers, memory/sessions, and AI agent config files (hooks injection) for secrets, PII, prompt injection, and dangerous patterns. Runs 4 model behavior probes (persuasion, sandbagging, deception, hallucination). Supports LLM-enhanced…
Skill Claude CodeCodex
Review application source code for broken authorization — IDOR / Broken Object Level Authorization (OWASP API1), Broken Function Level Authorization (API5), mass assignment (API3), multi-tenant isolation gaps, and privilege escalation. Reads routes, controllers, resolvers, and data models offline and reports the…
sparkfinderoven/r01-hesreallyhim-awesome-claude-code-security
Skill Claude CodeCodex
🔒 Security & Compliance skill suite derived from hesreallyhim/awesome-claude-code. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
Skill Claude CodeCodex
Bootstrap a workstation with the dotfiles framework. Takes a GitHub user / owner+repo / explicit clone URL and runs dot init (which shells out to chezmoi) with the right safety prompts. Honors the active agent profile (ask / plan / apply / audit) so it defaults to dry-run in safer modes and full apply in apply.
Skill Claude CodeCodex
Comprehensive system control operations for security testing. Use this skill when you need unified access to file operations, process management, system information, and command execution through a single interface during authorized penetration testing.
Skill Claude CodeCodex
A procedure for turning a confirmed security vulnerability into a submission-ready DOCX report. DOCX is the Microsoft Word document format.
UseAI-pro/openclaw-skills-security
Skill Claude CodeCodex
Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission policies for security weaknesses.
Skill Claude CodeCodex
Manages cloud AI provider API keys for Gemini, OpenAI, Claude, DeepSeek, Grok.
Skill Claude CodeCodex
Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, IDOR, auth bypass, RCE, SSTI, LFI, XXE, CORS, CSRF, prototype pollution, subdomain takeover, HTTP smuggling, open…
ricmmartins/azure-sre-agent-skills
Skill Claude CodeCodex
Assess security, reliability, and cost posture of Azure OpenAI and Microsoft Foundry deployments. Detects critical anti-patterns: API keys instead of Managed Identity, public endpoints without firewall, disabled content filtering, missing diagnostic settings, deprecated model versions, over-provisioned PTU, absence of…
Skill Claude Code
Full health and security audit for Rails apps, the review a principal engineer would do. Runs rubycritic, Brakeman, bundler-audit and rubyaudit, triages every finding with the LLM as judge, brings an OWASP Top 10 arsenal of checks for what scanners miss, and returns one impact-ranked action plan. Use for a Rails…
Security-Phoenix-demo/security-skills-claude-code
Skill Claude CodeCodex needs its repo
Run comprehensive security assessment covering OWASP Top 10 2025 and ASVS Level 1 requirements. This skill provides automated, full-codebase security analysis with real-time token monitoring, knowledge graph integration, and automated test generation.
yoanbernabeu/supabase-pentest-skills
Skill Claude CodeCodex
Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.
Skill Claude CodeCodex needs its repo
Scrub AI provenance marks from text and files using the markscrub CLI: invisible Unicode (Layer A), optional statistical rewrite (Layer B), and C2PA/EXIF/XMP/container metadata on PNG/JPEG/SVG/PDF/DOCX/HTML/MD. Use when the user asks to strip watermarks, remove Content Credentials, clean AI metadata, remove invisible…
Skill Claude CodeCodex
Search the Tor dark web, fetch .onion hidden service pages, rotate Tor identity, and run structured OSINT investigations. Use when user asks to search dark web, investigate .onion sites, find if data appeared on dark web, conduct Tor-based OSINT, look up dark web leaks, fetch any .onion URL, check for leaked…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: