Skill Claude CodeCodex
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
18,827 tagged Security, measured the same way as everything else here.
Browse within: cybersecurity 368bug-bounty 226autonomous-pentesting 140openclaw 113claude-ai 83cloud-security 65aws 64ai-security 59redteam 59generative-ai 57ctf 56LangChain 53hacking 53penetration-testing 53
Skill Claude CodeCodex
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
Skill Claude CodeCodex
A set of rules for detecting signals that may suggest a browser user is in China. It scans browser information locally and also reuses scoring functions in a server endpoint called /api/check.
Skill Claude CodeCodex
Analyze a Laravel application for complexity hotspots, security surface, and database access patterns using laravel-brain. Activate when: the user asks what needs work, what should be improved, what to work on next, where to focus, what is the most complex code, what are the security issues, audit the codebase…
Skill Claude CodeCodex
Use when a user needs help choosing Promptbeat attack goals, risk types, scenarios, seed files, dataset subscriptions, compliance profiles, or a small smoke-test scope.
Skill Claude CodeCodex
Professional code security audit skill covering 55+ vulnerability types. Enhanced with WooYun 88,636 real-world vulnerability cases (2010-2016). This skill should be used when performing security audits, vulnerability scanning, penetration testing preparation, or code review for security issues. Supports 9 languages…
bodadotsh/npm-security-best-practices
Skill Claude CodeCodex
Prevent JavaScript/TypeScript projects from supply-chain attacks across package managers like npm, pnpm, yarn, bun, and deno. Use whenever planning, installing, updating packages or configuring package managers.
Skill Claude CodeCodex ✓ vendor
Generates and runs crash reproducers to verify security flaws. Use when viable findings exist and you need to write and execute a script or payload to verify the crash. Don't use for code auditing or patching.
Skill Claude CodeCodex
Threat-model, design, implement, and verify security controls in web, API, backend, React, and React Native software. Use when building authentication, session management, authorization, sensitive-data handling, secrets, cryptography integration, input validation, file upload, outbound requests, audit logging, error…
Skill Claude CodeCodex
Comprehensive code review for diffs. Analyzes changed code for security vulnerabilities, anti-patterns, and quality issues. Auto-detects domain (frontend/backend) from file paths.
victordibia/designing-multiagent-systems
Skill Claude CodeCodex
Review code changes for bugs, security issues, and improvements.
Skill Claude CodeCodex
Prose mentions that must not produce combination findings.
Skill Claude CodeCodex
OpenClaw skill for local API Relay Audit. Use when an OpenClaw agent must audit a third-party AI API relay, LLM proxy, gateway, or resale API before trusting coding, tool, production, or wallet-sensitive traffic.
Skill Claude CodeCodex
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze.
Skill Claude CodeCodex
Production-ready security middleware for FastAPI. Use when adding IP filtering, rate limiting, per-route security decorators, route-resolution strict mode, global behavior rules, passive/log-only mode, or Guard Agent SaaS telemetry to a FastAPI app. Covers SecurityMiddleware setup, SecurityConfig tuning, and the…
Skill Claude CodeCodex
Detect whether an API endpoint is backed by genuine Claude (not a wrapper, proxy, or impersonator) using 9 weighted rule-based checks that mirror the claude-verify project. Also extracts injected system prompts from providers that override Claude's identity. Fully self-contained — copy the code below and run, no extra…
Skill Claude CodeCodex
Reviews and repairs references already published in the Top 10 Web Hacking Techniques Markdown-and-PDF archive. Use for one article, one collection such as 2019 or YYYY-ai, or a bounded period when asked to audit, validate, verify, QA, sanity-check or proofread archived references; investigate wrong-page captures…
Skill Claude CodeCodex
Implement a Linear ticket end-to-end - fetch context, branch, code, tests, draft PR, update the ticket. Use when given a ticket ID like EVL-86 or DEP-123.
Skill Claude CodeCodex
A cryptography skill for solving capture-the-flag challenges, which are security puzzles that require finding and exploiting weaknesses. It covers algorithms, attacks, mathematical techniques, and zero-knowledge proofs.
gemini-cli-extensions/security
Skill Claude CodeCodex
Invoke this as your absolute first action before using any other tools whenever a user requests to fix, patch, or remediate a vulnerability. Do not perform manual research first.
lingbol088-spec/5.6-JAILBREAK-NERV-codex-instruct-5.6
Skill Claude CodeCodex
A skill for making code harder to read and for reversing those changes. Obfuscation alters code structure or text without changing its intended behaviour.
Skill Claude CodeCodex
Conduct comprehensive code reviews of pending changes, a branch, or a PR using parallel specialist agents that audit the diff, compare against peer code, and verify claims. Use when the user asks to 'review this', wants pending changes, a PR, a branch, or a diff reviewed, or asks for a code review. Produces review…
Skill Claude CodeCodex
Use when checking skills for security or quality issues, reviewing audit results from skills.sh or Tessl, or remediating findings across published skills.
Skill Claude CodeCodex
Integrate Arcjet security into a Claude Agent SDK agent using @arcjet/guard — wrap tool() handlers, screen inbound prompts with UserPromptSubmit, and deny unwrapped built-in/MCP tools with PreToolUse. Use when asked to add Arcjet to a Claude Agent SDK or Claude Code agent, rate limit its tools, screen inbound…
Skill Claude CodeCodex
Encode a GitHub issue describing a data breach into a VERIS-schema JSON incident for VCDB. Invoke with a vz-risk/VCDB issue URL (e.g. https://github.com/vz-risk/VCDB/issues/23372) and an optional analyst GitHub handle. Reads the issue and its linked sources, finds an additional independent source via web search, maps…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: