code-review
721Skill Claude Code
Review code changes for security, performance, and style issues.
16,964 tagged Security, measured the same way as everything else here.
Browse within: cybersecurity 490bug-bounty 284agent 228generative-ai 179LangChain 176hacking 175autonomous-pentesting 139cloud-security 123skills 121claude-ai 118redteam 115LLM 107security-audit 106cors-exploitation 90
Skill Claude Code
Review code changes for security, performance, and style issues.
Skill Claude CodeCodex
An authorised reverse-engineering workflow for examining local software samples and recovering how they work. Reverse engineering means studying compiled or packaged software, such as an APK, ELF, PE, or firmware image, to infer its logic.
Skill Claude CodeCodex
Use before committing to the public CTObot repo to catch company-specific or proprietary content that has drifted into the public files (AGENTS.md, SOUL.md, docs/, skills/, README). The agent reads the diff (or all files) and reasons about whether the content is generic and shareable or specific to our company…
Skill Claude CodeCodex
Scans Claude Code skills for security risks before installation. Checks for prompt injection, credential harvesting, exfiltration patterns, hooks, excessive permissions, and settings modification. Supports GitHub URLs, local paths, and bulk scanning. Use when asked to audit, scan, or check a skill for malware or…
Skill Claude CodeCodex
A Capture The Flag, or CTF, security-competition assistant covering web attacks, binary exploitation, reverse engineering, cryptography, forensics, blockchain, and cloud security.
chenxihuang1028-a11y/variant-analysis
Skill Claude CodeCodex
Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.
yanis7774/mac-security-audit-skill
Skill Claude CodeCodex
Run a comprehensive READ-ONLY macOS security audit and triage the findings. Checks open/listening ports and external exposure, firewall + stealth, SSH and remote access (Screen Sharing, ARD), VPN/tunnels (Tailscale, WireGuard, reverse SSH), persistence (LaunchAgents/Daemons, cron, login hooks, shell rc, BTM /…
Skill Claude CodeCodex needs its repo
Configure an uninitialized project from the active SPEC.md contract and verify the local stack.
Skill Claude CodeCodex
Security scanner using VirusTotal. Use when the user asks to scan a file for malware, check if a downloaded file or script is safe, verify a file hash against threat intelligence, or assess the security of any file. Returns both antivirus engine detections AND AI-powered Code Insight analysis (when available) in a…
Skill Claude Code
Use when writing or reviewing code that crosses a trust boundary (user input, external APIs, file/network/DB I/O) — guards against invalid input, injection, unsafe failure modes, and missing validation at the edges without over-defending internal code.
Skill Claude CodeCodex
Use this skill to audit changes for security, privacy, and policy compliance.
dungnotnull/dex-market-manipulation-detector-agent-skill
Skill Claude CodeCodex
This document serves as the authoritative registry for all skills in the dex-market-manipulation-detector harness. It documents how skills are registered, resolved, executed, and validated, including input/output JSON schemas for runtime validation and automatic documentation generation.
Skill Claude CodeCodex
Lord skill for governing AI coding agents at runtime — gateway interception, agent/flow/model allowlisting, and MCP-server-as-securable. The control layer between an agent's decision and its real-world action.
get-convex/convex-codex-plugin
Skill Claude CodeCodex
Audit and harden a Convex app's authorization: identity-from-arg impersonation, missing per-document ownership checks, and public queries leaking PII/financial data by a client-supplied id — the single largest real-defect cluster measured against generated Convex backends (44 of 214). Runs a deterministic scan for the…
mumuchongchongchong/security-skills
Skill Codex
Offline reconstruction and security audit of agent execution traces from JSON, JSONL, or pasted logs. Use when Codex needs to review user input, model planning, tool calls, tool results, approvals, and final answers for prompt injection, unauthorized tools, secret exposure, missing approval, repeated-call loops, or…
jiluojiluo/agent-skill-sandbox-configurator
Skill Claude CodeCodex
A setup tool for running an agent skill inside an OpenSandbox isolation environment. It examines the skill and creates the files needed to build and use a Docker-based sandbox.
Skill Claude CodeCodex
Analyze JSON Web Tokens (JWTs) for common security vulnerabilities including algorithm confusion attacks (RS256 to HS256), none algorithm bypass, weak secret brute-forcing, and claim manipulation. Practice in isolated lab environments to understand authentication bypass and privilege escalation via token forgery.
Skill Claude Code
Provides binary exploitation (pwn) techniques for CTF challenges. Use when exploiting buffer overflows, format strings, heap vulnerabilities (House of Orange, Spirit, Lore, Apple 2, Einherjar, tcache stashing unlink), race conditions, kernel bugs, ROP chains, ret2libc, ret2dlresolve, shellcode, GOT overwrite…
newcore-network/opencore-ai-skills
Skill Claude CodeCodex
OpenCore framework best practices - bootstrap, controllers, imports, security, events, adapters, validation, runtime constraints. Use this skill when writing, reviewing, refactoring, or explaining code built with @open-core/framework and related OpenCore adapters. Trigger on any question about OpenCore, CitizenFX…
Skill Claude CodeCodex
Intelligent code security scanner with hybrid local-cloud detection. Fingerprints packages, runs static behavioral analysis, and consults cloud threat intelligence (enabled by default, can be disabled) for confidence scoring.
jinyimeng01/net-code-audit-skill-master
Skill Claude CodeCodex
A security-audit topic for unsafe deserialization. Deserialization turns stored or received data back into program objects, and unsafe handling can create security risks.
g-greatdevaks/mcp-dev-summit-blr-2026
Skill Claude CodeCodex
Detects data exfiltration, lateral movement, and crypto-mining anomalies from ExamplePay observability signals (logs, metrics, traces). Returns a structured ThreatSignal with a confidence score (0.0–1.0).
Skill Claude CodeCodex
Network scanning MCP server wrapping nmap. Provides 14 purpose-built tools for host discovery, port scanning (SYN/TCP/UDP), service & OS detection, NSE script execution, and vulnerability scanning. Returns structured JSON output. Includes scope enforcement (CIDR allowlist), audit logging, and scan persistence. Use…
austinsonger/GRC-Mapping-Analyst
Skill Codex
Use when asked to map, crosswalk, align, compare, or gap-analyze any two cybersecurity frameworks, control catalogs, or regulatory requirements using NIST IR 8477 Set-Theory Relationship Mapping (STRM). Triggers on terms like "map controls", "crosswalk", "framework alignment", "gap analysis", or producing a STRM CSV…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: