Unclecheng-li/DeepSec

DeepSec — AI Security Offense & Defense Platform. Shield audits AI-generated code for hallucinated packages, missing safeguards & AI pattern errors in real time. Spear automates authorized penetration testing with 40+ skill packs, from recon to PoC.

365Stars on the repository
50Mods indexed here, across every type
7d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

ai-mcp-security

01

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A security assessment guide for AI applications, agents, plugins, skills, retrieval systems, and MCP tools. It examines risks such as prompt injection, unauthorized actions, data leaks, and unsafe tool access.

365 7d ago A 46 tokens copy · 100% MIT

android-pentest

02

Unclecheng-li/DeepSec

Skill Claude CodeCodex

An authorized penetration-testing guide for Android apps, including APK analysis, device testing, traffic capture, runtime inspection, and request replay. An APK is the installable package used to distribute an Android app.

365 7d ago A 32 tokens copy · 100% MIT

client-reverse

03

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A guide for reverse-engineering client software and replaying its network requests during authorized security testing. It covers Android apps, browser JavaScript, desktop programs, signatures, encryption, tokens, and device checks.

365 7d ago A 56 tokens copy · 100% MIT

crypto-toolkit

04

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A collection of tools for encoding, decoding, hashing, and encrypting data. It covers formats such as Base64, hexadecimal, URL encoding, HTML entities, and JWTs, as well as several ciphers and encryption methods.

365 7d ago A 69 tokens copy · 100% MIT

ctf-crypto

05

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A reference library for attacking cryptography challenges in CTFs, or capture-the-flag security competitions. It covers attack patterns for RSA, AES, elliptic-curve cryptography, random-number generators, classic ciphers, and lattice-based systems.

365 7d ago A 67 tokens copy · 100% MIT

ctf-misc

06

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A reference guide for miscellaneous Capture the Flag security challenges, including sandbox escapes, layered encoding, hidden data in files, game or virtual-machine reverse engineering, platform APIs, and Linux privilege escalation. Capture the Flag competitions are security puzzles where participants find secret answers called flags.

365 7d ago A 54 tokens copy · 100% MIT

ctf-web

07

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A reference library for web-security challenges in CTFs, or capture-the-flag security competitions. It focuses on common PHP weaknesses, injection bypasses, source-code discovery, file inclusion, and finding hidden challenge data.

365 7d ago A 56 tokens copy · 100% MIT

cve-triage

08

Unclecheng-li/DeepSec

Skill Claude CodeCodex

CVE lookup and triage — map discovered services/versions to known CVEs via the cvelookup tool, score by CVSS/exploitability, and prioritize what to verify first.

365 7d ago A 44 tokens copy · 100% MIT

hackerone

09

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A HackerOne bug-bounty safety procedure that reads a program's scope and rules before testing any target. HackerOne is a platform where companies invite security researchers to report vulnerabilities for possible rewards.

365 7d ago A 43 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A reference library for advanced security testing inside an organisation's private network, after an initial foothold has been obtained. It covers Windows hosts, domains, services, credentials, and internal network access.

365 7d ago A 50 tokens copy · 100% MIT

osint-recon

11

Unclecheng-li/DeepSec

Skill Claude CodeCodex

An OSINT guide for open-source intelligence, meaning information collected from publicly available sources. It organizes reconnaissance across servers, websites, domains, and, when appropriate, people.

365 7d ago A 42 tokens copy · 100% MIT

pentest-tools

12

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A quick reference for tools and commands used in authorised penetration testing, which checks systems for security weaknesses.

365 7d ago A 66 tokens copy · 100% MIT

rapid-checklist

13

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A quick-reference guide for authorized penetration testing, which is the practice of checking systems for security weaknesses. It lists common input patterns, bypass ideas, and testing order for areas such as websites, tokens, containers, and AI tools.

365 7d ago A 42 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized Active Directory red-team security testing, including Kerberos attacks, domain privilege escalation, lateral movement, and GPO abuse. Use when a task belongs to the AD testing domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 59 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized API security testing, including BOLA/IDOR, authentication bypass, mass assignment, missing rate limits, and GraphQL issues. Use when a task belongs to the API testing domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 61 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized authentication, authorization, and session security testing, including password policy, JWT/token, OAuth, and MFA bypass issues. Use when a task belongs to the auth testing domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 58 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized web cache poisoning testing, including unkeyed headers, unkeyed parameters, cache deception, and CDN-specific behavior. Use when a task belongs to the cache poisoning domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 61 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized clickjacking testing, including missing X-Frame-Options, CSP frame-ancestors bypasses, and drag-and-drop hijacking. Use when a task belongs to the clickjacking domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 66 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized cloud security testing, including IAM misconfiguration, exposed storage, metadata services, and serverless injection. Use when a task belongs to the cloud testing domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 55 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized operating system command injection testing, including direct injection, blind injection, out-of-band callbacks, and argument injection. Use when a task belongs to the command injection domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago B 58 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized source code security review, including dangerous function tracing, data-flow analysis, logic flaw detection, and dependency review. Use when a task belongs to the code audit domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 59 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized container and orchestration security testing, including Docker escape, Kubernetes privilege escalation, image vulnerabilities, and service mesh bypasses. Use when a task belongs to the container testing domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 59 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized CORS misconfiguration testing, including reflected origins, null origins, subdomain trust, and credential exposure. Use when a task belongs to the CORS testing domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 61 tokens copy · 100% MIT

Unclecheng-li/DeepSec

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized cryptography weakness testing, including weak algorithms, padding oracles, key management errors, insecure randomness, and hash collision risks. Use when a task belongs to the cryptography testing domain and needs scope, evidence, pivot, or exit criteria.

365 7d ago A 62 tokens copy · 100% MIT