Skill Claude CodeCodex
A security assessment guide for AI applications, agents, plugins, skills, retrieval systems, and MCP tools. It examines risks such as prompt injection, unauthorized actions, data leaks, and unsafe tool access.
DeepSec — AI Security Offense & Defense Platform. Shield audits AI-generated code for hallucinated packages, missing safeguards & AI pattern errors in real time. Spear automates authorized penetration testing with 40+ skill packs, from recon to PoC.
Skill Claude CodeCodex
A security assessment guide for AI applications, agents, plugins, skills, retrieval systems, and MCP tools. It examines risks such as prompt injection, unauthorized actions, data leaks, and unsafe tool access.
Skill Claude CodeCodex
An authorized penetration-testing guide for Android apps, including APK analysis, device testing, traffic capture, runtime inspection, and request replay. An APK is the installable package used to distribute an Android app.
Skill Claude CodeCodex
A guide for reverse-engineering client software and replaying its network requests during authorized security testing. It covers Android apps, browser JavaScript, desktop programs, signatures, encryption, tokens, and device checks.
Skill Claude CodeCodex
A collection of tools for encoding, decoding, hashing, and encrypting data. It covers formats such as Base64, hexadecimal, URL encoding, HTML entities, and JWTs, as well as several ciphers and encryption methods.
Skill Claude CodeCodex
A reference library for attacking cryptography challenges in CTFs, or capture-the-flag security competitions. It covers attack patterns for RSA, AES, elliptic-curve cryptography, random-number generators, classic ciphers, and lattice-based systems.
Skill Claude CodeCodex
A reference guide for miscellaneous Capture the Flag security challenges, including sandbox escapes, layered encoding, hidden data in files, game or virtual-machine reverse engineering, platform APIs, and Linux privilege escalation. Capture the Flag competitions are security puzzles where participants find secret answers called flags.
Skill Claude CodeCodex
A reference library for web-security challenges in CTFs, or capture-the-flag security competitions. It focuses on common PHP weaknesses, injection bypasses, source-code discovery, file inclusion, and finding hidden challenge data.
Skill Claude CodeCodex
CVE lookup and triage — map discovered services/versions to known CVEs via the cvelookup tool, score by CVSS/exploitability, and prioritize what to verify first.
Skill Claude CodeCodex
A HackerOne bug-bounty safety procedure that reads a program's scope and rules before testing any target. HackerOne is a platform where companies invite security researchers to report vulnerabilities for possible rewards.
Skill Claude CodeCodex
A reference library for advanced security testing inside an organisation's private network, after an initial foothold has been obtained. It covers Windows hosts, domains, services, credentials, and internal network access.
Skill Claude CodeCodex
An OSINT guide for open-source intelligence, meaning information collected from publicly available sources. It organizes reconnaissance across servers, websites, domains, and, when appropriate, people.
Skill Claude CodeCodex
A quick reference for tools and commands used in authorised penetration testing, which checks systems for security weaknesses.
Skill Claude CodeCodex
A quick-reference guide for authorized penetration testing, which is the practice of checking systems for security weaknesses. It lists common input patterns, bypass ideas, and testing order for areas such as websites, tokens, containers, and AI tools.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized Active Directory red-team security testing, including Kerberos attacks, domain privilege escalation, lateral movement, and GPO abuse. Use when a task belongs to the AD testing domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized API security testing, including BOLA/IDOR, authentication bypass, mass assignment, missing rate limits, and GraphQL issues. Use when a task belongs to the API testing domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized authentication, authorization, and session security testing, including password policy, JWT/token, OAuth, and MFA bypass issues. Use when a task belongs to the auth testing domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized web cache poisoning testing, including unkeyed headers, unkeyed parameters, cache deception, and CDN-specific behavior. Use when a task belongs to the cache poisoning domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized clickjacking testing, including missing X-Frame-Options, CSP frame-ancestors bypasses, and drag-and-drop hijacking. Use when a task belongs to the clickjacking domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized cloud security testing, including IAM misconfiguration, exposed storage, metadata services, and serverless injection. Use when a task belongs to the cloud testing domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized operating system command injection testing, including direct injection, blind injection, out-of-band callbacks, and argument injection. Use when a task belongs to the command injection domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized source code security review, including dangerous function tracing, data-flow analysis, logic flaw detection, and dependency review. Use when a task belongs to the code audit domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized container and orchestration security testing, including Docker escape, Kubernetes privilege escalation, image vulnerabilities, and service mesh bypasses. Use when a task belongs to the container testing domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized CORS misconfiguration testing, including reflected origins, null origins, subdomain trust, and credential exposure. Use when a task belongs to the CORS testing domain and needs scope, evidence, pivot, or exit criteria.
Skill Claude CodeCodex
Domain routing and boundary guidance for authorized cryptography weakness testing, including weak algorithms, padding oracles, key management errors, insecure randomness, and hash collision risks. Use when a task belongs to the cryptography testing domain and needs scope, evidence, pivot, or exit criteria.