AgentSecOps

AgentSecOps

Active
29
Skills
1
Categories
ClaudeCode(CC)Codex

Published Skills 29

📦

webapp-sqlmap

Assess SQL Injection with SQLMap

Critical 38

Manual SQL injection testing is slow and inconsistent. This skill provides structured SQLMap commands, authorization checks, validation steps, and reporting guidance for approved assessments.

Claude Codex Code(CC)
Install
📦

skill-name

Build Security Operations Skills

Critical 38

Security skill authors need consistent workflows, references, and validation patterns. This template provides reusable structures for security guidance, rules, and CI scanning.

Claude Codex Code(CC)
Install
📦

webapp-nikto

Scan Web Servers with Nikto

Critical 38

Web teams need a repeatable way to identify server weaknesses before attackers find them. This skill guides authorized Nikto scans and structured remediation reporting.

Claude Codex Code(CC)
Install
📦

secrets-gitleaks

Scan Repositories for Hardcoded Secrets

High Risk 38

Hardcoded credentials can expose systems and fail compliance checks. This skill guides Gitleaks scans, configurations, hooks, CI pipelines, triage, and remediation.

Claude Codex Code(CC)
Install
📦

sca-trivy

Scan Dependencies and Containers with Trivy

High Risk 38

Security teams need consistent visibility into vulnerable components, images, and infrastructure configuration. This skill provides practical Trivy workflows for assessment, reporting, and remediation.

Claude Codex Code(CC)
Install
📦

sca-blackduck

Assess Dependencies with Black Duck

Critical 38

Dependency vulnerabilities and license risks can reach production unnoticed. This skill guides Black Duck scans, policy gates, SBOM creation, and remediation triage.

Claude Codex Code(CC)
Install
📦

sbom-syft

Generate SBOMs with Syft

Critical 38

Manual software inventories are incomplete and difficult to maintain. This skill guides repeatable Syft SBOM generation for containers, filesystems, archives, and CI pipelines.

Claude Codex Code(CC)
Install
📦

sast-semgrep

Audit Code with Semgrep

High Risk 38

Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.

Claude Codex Code(CC)
Install
📦

sast-horusec

Scan Code with Horusec

Critical 38

Security flaws and exposed secrets can cross language boundaries and reach production. This skill guides Horusec scans, result triage, and CI integration.

Claude Codex Code(CC)
Install
📦

sast-bandit

Scan Python Code with Bandit

High Risk 38

Python security flaws can reach production unnoticed. This skill guides Bandit scans, prioritization, CI integration, and remediation with CWE and OWASP references.

Claude Codex Code(CC)
Install
📦

reviewdog

Integrate Reviewdog Security Feedback into CI

Critical 38

Security scanner results are often fragmented across CI logs. This skill helps configure reviewdog to publish focused findings in pull requests and local hooks.

Claude Codex Code(CC)
Install
📦

recon-nmap

Run Authorized Network Reconnaissance with Nmap

Critical 38

Manual network discovery can miss exposed services and inconsistent configurations. This skill provides structured Nmap workflows for authorized discovery, enumeration, vulnerability checks, and reporting.

Claude Codex Code(CC)
Install
📦

pytm

Build pytm Threat Models as Code

Safe 81

Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.

Claude Codex Code(CC)
Install
📦

policy-opa

Enforce OPA Policy as Code

High Risk 38

Security teams need repeatable policy checks across clusters, infrastructure, and compliance controls. This skill guides Claude, Codex, and Claude Code through OPA Rego policy creation, testing, and CI/CD enforcement.

Claude Codex Code(CC)
Install
📦

pentest-metasploit

Audit Metasploit Workflows Safely

Critical 38

Security teams need structured review of authorized exploit validation, but these workflows carry high misuse risk. This skill documents Metasploit assessment steps with scope checks, logging, and cleanup guidance.

Claude Codex Code(CC)
Install
📦

network-netcat

Audit Netcat Network Testing Workflows

Critical 38

Network testers need clear netcat workflows for connectivity checks and controlled validation. This skill organizes netcat commands, authorization steps, and documentation guidance.

Claude Codex Code(CC)
Install
📦

ir-velociraptor

Investigate Endpoints with Velociraptor VQL

Critical 38

Endpoint investigations require consistent queries, collection plans, and evidence controls. This skill provides Velociraptor workflows, VQL patterns, and deployment templates for authorized response.

Claude Codex Code(CC)
Install
📦

iac-checkov

Scan Infrastructure Code with Checkov

High Risk 38

Infrastructure teams need consistent security checks before deployment. This skill guides Checkov scans, policy customization, suppression governance, compliance mapping, and CI integration.

Claude Codex Code(CC)
Install
📦

forensics-osquery

Investigate Endpoints with osquery

High Risk 38

Endpoint investigations often require many platform-specific tools and commands. This skill provides osquery workflows, detection queries, and packs for consistent forensic collection across major platforms.

Claude Codex Code(CC)
Install
📦

detection-sigma

Build Portable Sigma Detection Rules

High Risk 38

SIEM-specific rules are difficult to reuse and maintain across platforms. This skill structures Sigma detections, conversions, ATT&CK mappings, and compliance coverage.

Claude Codex Code(CC)
Install
📦

dast-zap

Automate OWASP ZAP DAST Scans

High Risk 38

Security teams need repeatable runtime testing before releases. This skill guides authorized OWASP ZAP scans, authentication setup, API testing, and CI reporting.

Claude Codex Code(CC)
Install
📦

dast-nuclei

Run Authorized Nuclei Security Scans

Critical 38

Known vulnerabilities and misconfigurations can escape manual review. This skill guides authorized Nuclei scans, template selection, validation, and reporting.

Claude Codex Code(CC)
Install
📦

dast-ffuf

Plan Authorized Web Fuzzing with ffuf

Critical 38

Web fuzzing creates noisy results and legal exposure when scope, filters, and rate limits are unclear. This skill produces authorized ffuf workflows with focused discovery, filtering, output, and CI guidance.

Claude Codex Code(CC)
Install
📦

crack-hashcat

Audit Password Hashes with Hashcat

Critical 38

Password audits need repeatable hash identification, attack selection, and reporting. This skill guides authorized Hashcat workflows for recovery, policy testing, and defensive remediation.

Claude Codex Code(CC)
Install