An optimized collection of AI agent skills, loops and workflows for security auditing
Overview
An optimized collection of AI agent skills, loops and workflows for security auditing
README
.context
An optimized collection of AI agent skills, loops and workflows for security auditing
Claude Code · Copilot · Gemini · Codex
Telegram DM
Installation
Agents:
Paste in your chat:
Run the AI Security Registry installation wizard https://github.com/forefy/.context/blob/main/install.md
Manual
- Data maintained in this repo is also listed on https://forefy.com/aisecurity
- Search and download from there via easy installation button
What is this?
Security auditing skills for AI agents, adhering to the Agent Skills Format.
.context is one of the oldest efforts by security researchers to share auditing knowledge directly to your AI agent, and is built gradually over time. at the most simple form, you type “audit this contract” and end up with a multi-agent triaged AI report.
About the Skills
Skills are grouped into category folders under skills/. Discovery is flat, so the folders are for organization only; each skill still lives at skills///SKILL.md.
Applicative pentest
skills/applicative-pentest/ - portable, tool-agnostic web-app testing methodologies (curl/python3, no scanner required), each with runnable snippets and the wordlists/regexes/thresholds inline or in references/.
ssrf-oob- active out-of-band SSRF probe; injects an OAST/collaborator callback into request-forwarding params and client-IP headers, then watches for the DNS/HTTP interaction that proves a blind server-side request.http-request-smuggling- active HTTP desync detection for CL.TE and TE.CL via raw socket requests, using timing probes plus differential-response confirmation with the exact payloads.jwt-attacks- forges and re-signs captured JWTs to test signature validation (alg:none, signature stripping, kid traversal, jwk/jku injection, RS256/HS256 confusion) plus offline HMAC secret cracking.broken-access-control- active authorization and IDOR testing by replaying captured requests with swapped identities and incremented object-ids, carrying the response-diff thresholds that decide a finding.webapp-probe- assesses what a web app exposes or leaks, passively from captured traffic (headers, cookies, secrets, error pages, tech fingerprints, RCE-prone params) and actively (exposed files, vulnerable software on open ports, Wayback endpoints, dependency confusion).cdn-peek- checks whether a CDN/WAF-fronted host is reachable outside its edge, using only dig, curl, openssl, whois, and nc; works against any reverse-proxy edge.
Blockchain
skills/blockchain/ - smart-contract auditing and on-chain investigation.
smart-contract-audit- full smart contract audit framework with multi-expert analysis for Solidity, Anchor, Vyper, TON (FunC/Tact), and Sui (Move), with language-specific checks and vulnerability pattern references.foundry-poc- context-window-optimized skill to generate a Foundry proof of concept for a discussed finding.blockchain-forensics- trace stolen funds and attribute attacker wallets using only public on-chain data; also useful for deployer history and privileged-role validation during audits.safe-hunt- sweeps DeFi protocol Safe multisig wallets for governance misconfigurations, scoring each against a finding pattern library and producing an audit-ready ranked report.
Cloud
skills/cloud/ - cloud and infrastructure exposure.
cloud-bucket-brute- active enumeration of publicly readable cloud-storage buckets; permutes a company name into candidate bucket names and probes AWS S3, Google Cloud, DigitalOcean, Alibaba, Oracle, and Vultr.infrastructure-audit- infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations; audits generate numbered folders in.context/outputs/for tracking and reports.
Hunter utils
skills/hunter-utils/ - general auditing methodology and workflow tooling picked up naturally as you travel through a codebase.
tiny-auditor- context-window-optimized audit skill; think caveman for audits.auditor-quiz- get engaged with the codebase from a security-auditor perspective and test how well you memorized it by quizzing yourself.audit-scope- generate a security audit scope document from GitHub repo URLs and/or API access descriptions, with a protocol narrative and a scope table (NSLOC, focus areas, days).sandboxed-audit-runner- wraps the agent session inside the Anthropic Sandbox Runtime before auditing untrusted code, protecting the host from prompt-injection embedded in the codebase.agent-onboarding- onboard concurrent agents to a shared TODO.md so parallel auditing terminals sync work and keep coverage tracking.gdocs-audit-report- create, format, and maintain security audit reports in Google Docs via the Docs API, covering finding formatting, summary tables, severity colors, and index-drift safety.git-commit- before committing, pre-runs tests, security-reviews changed code, strips dead code and sensitive data, enforces clean commit messages, and validates the change won’t break deployments.context-window-to-skill- converts a completed agent conversation into a reusable skill, extracting the pitfalls, tweaks, and lessons so the next run gets it right from the start.
Defensive
skills/defensive/ - blue-team and DFIR.
endpoint-threat-hunt- live endpoint threat hunting across process/file/network/persistence/registry categories using native OS tools (macOS/Linux/Windows), producing a structured findings report with explicit coverage gaps.
Quality
Skills, workflows and loops are following industry best practice and guidance (e.g. we read the docs):
And are CI-validated by in-repo, versioned json-schema files:
.context skills are CI-level security-audited via skill-warden, skills, loops and workflows are validated on the AI Security Registry.
Contributions
Your research knowledge is the only skill required to contribute, whether its a methodology, specific knowledge on a protocol or language or even corrections - everything’s highly welcome! help secure and improve the community!
Recommended Tools
Try a different keyword or remove a filter.
Install
npx skillfish add forefy/.context