url-js-finder
1153Skill Claude CodeCodex
A web and JavaScript analysis tool for finding URLs, API endpoints, subdomains, and possible secrets such as keys or tokens in authorised targets.
17,271 tagged Security, measured the same way as everything else here.
Browse within: cybersecurity 473bug-bounty 254agent 228generative-ai 179LangChain 176hacking 175autonomous-pentesting 120skills 119claude-ai 116cloud-security 114LLM 105redteam 105agents 80cors-exploitation 80
Skill Claude CodeCodex
A web and JavaScript analysis tool for finding URLs, API endpoints, subdomains, and possible secrets such as keys or tokens in authorised targets.
Skill Claude CodeCodex
Use when the user wants to access, look up, create, edit, or manage credentials, passwords, secrets, login entries, secure notes, TOTP/2FA codes, or vault items in their Vaultwarden / Bitwarden vault via the vaultwarden-mcp MCP server. Trigger whenever the user mentions passwords, credentials, logins, secrets, vault…
Skill Claude CodeCodex
Audit an AI agent deployment against the CUSTODY containment framework and LASM threat model. Checks identity, input handling, supervision, traceability, operational controls, dependency management, and yield/teardown. Maps findings to NIST AI RMF, OWASP, CUSTODY pillars, and LASM layers.
Skill Claude CodeCodex
Security QA tester workflow for the owasp-wstg MCP server — scope, search, neighbor-walk, and citation over the WSTG corpus using five MCP tools. Load this file first; then load the model-variant file that matches your model family.
Skill Claude CodeCodex
A set of tools for replaying and capturing Yakit traffic. Yakit is a security-testing tool that can resend network requests and capture the results.
Skill Claude CodeCodex
A code-review workflow written in Chinese that checks software changes for correctness, security, performance, and maintainability. It also defines a report format for critical issues and suggestions.
samihalawa/linkedin-godmode-plugin
Skill Codex
Apply security, read-only, authorization, and same-layer verification rules to agent-operated LinkedIn workflows. Use before account-visible changes, private request replay, broad captures, or provider AI tasks.
mustafadeel/auth0-whoami-mcp-template
Skill Claude CodeCodex
Fork, customize, deploy, or troubleshoot the Auth0 Who Am I MCP template as an Auth0 Custom Extension. Use when adapting this repository's MCP tools, publishing its generated Webtask artifacts, provisioning its Auth0 API resource server, promoting a domain-level connection, registering an MCP client, or connecting an…
alexandreumatize/mcpanonimohealth
Skill Codex
Desidentifica localmente documentos de saúde antes de analisar seu texto com IA. Use quando um médico quiser trabalhar com receita, laudo, PDF ou imagem que possa conter dados de paciente.
Skill Claude CodeCodex
Version: 1.0.0 Status: Active Last Updated: 2026-01-01.
Skill Claude CodeCodex
Skill "mcp-server77" from veteranchat/mcp-server77, covering skill.md — practical examples & use cases, using the server, python example, check status and nmap scan.
Skill Codex
Retrieve revision-pinned software-agent failure evidence and unresolved verification gates without authorizing execution. Use before destructive, irreversible, privileged, broad-scope, production, infrastructure, database, filesystem, permission, MCP configuration, or supply-chain operations; when reviewing a…
Skill Claude CodeCodex
Expert analysis of Rapid7 InsightVM data exported via Bulk Export API with strict MCP requirements.
Skill Claude Code
Local host hardening audit — listening ports vs firewall, SUID/world-writable files, SSH config, and package integrity. No network target required.
Skill Claude CodeCodex
Analyse plausible attack paths to compromise a scanned AWS account and explain them against the MITRE ATT&CK framework, using the CloudLedger server. Use when the user wants an attack-path analysis, threat modelling, MITRE ATT&CK mapping, adversary/red-team perspective, "how could this account be compromised", or the…
dmc5179/redhat-security-data-api-mcp
Skill Claude CodeCodex
Query and investigate Red Hat security data (CVEs, CSAF advisories, OVAL streams) using the Red Hat Security Data API MCP server. Guides Claude through multi-step security investigation workflows.
mzaid007/Universal-Poison-Armor
Skill Claude CodeCodex
Mandatory security shield that sanitizes untrusted input, strips prompt injections & Markdown XSS tracking pixels, neutralizes zero-width Unicode steganography, detects high-entropy adversarial suffixes (GCG), identifies semantic dataset anomalies, and verifies web search results against Consensus Poisoning / Sybil…
Skill Claude CodeCodex
Use when the user mentions Chameleon Ultra/Lite, RFID or NFC card reading/cloning/emulation, Mifare Classic key recovery (fchk, nested, darkside, hardnested, autopwn), LF cards (EM410x, HID Prox, T5577...), or the MCP tools mcpplugin-chameleon-ultrachameleon. Provides device-operation workflows and mandatory safety…
Skill Claude CodeCodex
Read bounded UTF-8 files and create new files or directories on explicitly configured Windows folders through PC FileBridge. Use when the user asks ChatGPT or Codex to inspect, find, or create local PC files without overwriting or deleting anything.
Skill Claude CodeCodex
A required workflow for real-world penetration testing, which is authorised security testing that looks for ways into systems. It searches a testing knowledge base first and saves task records for future work and file safety.
Skill Claude Code
Create one-time NexFade encrypted links for attached files or sensitive notes, check link status, and revoke links.
Skill Claude CodeCodex
Test, secure, and submit project changes.
Skill Claude CodeCodex
A tool for hiding sensitive information in local documents, including PDFs, word-processing files, spreadsheets, presentations, and text files. It covers personal details, company information, project codenames, watermarks, and logos, including scanned documents and embedded PDF images.
equinoxaifinance-rgb/living-stack-mcp
Skill Claude CodeCodex
Use Living Stack MCP to establish scoped sessions, authorize bounded actions, record evidence, verify claims, checkpoint work, and export signed traces.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: