security first
by Roy Yuen
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
Skills for security audits, static analysis, vulnerability triage, and compliance checks. Ship safer software and meet regulatory requirements faster.
318 live security & compliance skills for Codex CLI.
by Roy Yuen
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
by Roy Yuen
Automated security and compatibility firewall for installing AI agent skills and Codex/OpenClaw packages.
by Kaymue
Get SOC2 Type II-ready in 90 days. 17 policy templates, 64 control mappings, automated AWS/GCP/GitHub evidence collection.
by Kaymue
Audit prompts and MCP tools for prompt injection. 47 attack patterns, OWASP LLM Top 10, generates adversarial tests. CVSS-scored.
Red-team your own AI agent for prompt-injection and tool-misuse vulnerabilities before it ships — then fix them. Maps your attack surface, generates a defensive test plan with the safe behavior expected for each case, and gives a prioritized mitigations list. Defensive use only.
by GTDataworks
Generate source-safe repository audits and repair handoff bundles without mutating your code.
by Timoranjes
Professional-grade Kubernetes YAML auditor for security, API deprecations, and deployment best practices.
by OnwireFlow
Makes your coding agent work like a senior developer: exact money with no rounding errors, configurable rules, real audit trails, honest testing and review. Any stack, any country.
Adversarially audit your agent hooks before you trust them. Catches command injection, secret leakage, over-broad matchers, destructive actions, and blocking-logic mistakes in pre/post-tool-use, prompt, and stop hooks — with a PASS or REVISE verdict and severity-ranked fixes.
by rayyer
Find accessibility barriers and WCAG 2.2 AA failures in web and mobile UI code — with file:line, the exact criterion, and a fix
by heyhridyansh
A technical auditor for SKILL.md packages that validates structure, triggers, security, and marketplace readiness.
A production-grade blueprint for designing, hardening, and shipping stable, autonomous AI agents.
by Timoranjes
Teaches AI coding agents to audit their own CLAUDE.md, cursor rules, and project config files for structural flaws that cause rule non-compliance. Diagnoses WHY agents ignore rules (ambiguity, contrad
An adversarial gate that audits cloud and infrastructure-as-code config — Terraform, Kubernetes, IAM, security groups, buckets — for the misconfigurations that cause real breaches, and returns a structured PASS/REVISE/BLOCK verdict with severities and exact fixes before anything reaches your environment.
by Nex AI
Automated US multi-state privacy compliance engine for threshold mapping, policy generation, and DSR workflows.
by Nex AI
Automates Belgian automotive sales docs, Car-Pass workflows, and 2022 warranty compliance for garages.
by Nex AI
Automated security scanner for FastAPI repos to detect secrets, SQLi, insecure CORS, and unverified webhooks.
by Nex AI
Professional accessibility auditing for architects, balancing legal regulations with real-world usability.
by Roy Yuen
Professional security audit skill for web apps and APIs with structured severity-based findings and remediation plans.
Automates NGO grant reporting with strict compliance checks, budget tracking, and impact storytelling.
by Vivek K
Audits a repository for exposed secrets and vulnerable dependencies with threat-model context, false-positive filtering, secret lifecycle, attack-path analysis, remediation, and a CRITICAL-EXPOSURE → CLEAN maturity verdict — without ever printing full secret values.
Sovereign cryptographic identity (Ed25519), message signing, and P2P trust mesh for AI agents.
by Jai
Automated SEO optimization and Chinese Advertising Law compliance scanning for social media content.
by Elyas
A 6-layer engineering containment gate for agents that move real money.
Each skill on this page is a SKILL.md file built for security & compliance work and confirmed to run in Codex CLI. Install one into ~/.codex/skills/, start a new session, and Codex CLI follows the workflow the creator encoded instead of improvising from a short prompt.
Listings are ranked by installs, upvotes and reviews, so what surfaces first is what other Codex CLI users actually keep. Free and paid skills compete on the same page, and every listing shows its security scan result before you download anything.