Security Monitoring
Automate security monitoring, threat detection, incident response, and compliance workflows
Skills for your AI
Automate security monitoring, threat detection, incident response, and compliance workflows
Use when Codex should act as the Application Security Engineer specialist from Agency Agents. AppSec specialist who secures the software development lifecycle through threat modeling, secure code review, SAST/DAST integration, and developer security education
Use when Codex should act as the Security Architect specialist from Agency Agents. Expert security architect specializing in threat modeling, secure-by-design architecture, trust-boundary analysis, defense-in-depth, and risk-based security reviews across web,
Guides security architecture consulting work — risk and vulnerability assessment, policy and governance development, framework and compliance assessment, technology evaluation, training, incident response planning, architecture review, solution design and thre
Plans and analyzes security assessments — vulnerability scans, penetration tests, risk assessments, policy reviews, audits, architecture reviews, data classification, incident response, and tool evaluation — producing reports, checklists, and plans. Use when t
Plans, analyzes, and drafts security audit and review reports across vulnerability, configuration, access control, policy, incident response, log, training, physical, vendor, architecture, cloud, continuity, and privacy domains. Use when the user needs audit s
Plans and drafts security awareness training, phishing simulations, policy communications, campaigns, and evaluation surveys for employees. Use when the analyst needs training content, a phishing test, a policy message, a campaign, or a training evaluation.
Reviews code for language and framework specific security vulnerabilities and suggests fixes. Use when the user asks for security guidance, a security review, secure-by-default coding help, or help with authentication, data storage, error handling, security te
Provides actionable security guidance for systems administrators on passwords, access control, network security, patching, encryption, incident response, training, vulnerability management, backup, auditing, and remote access. Use when drafting security polici
Guides software engineers through security practices including vulnerability scanning, code review, secure coding, testing, incident response, compliance, architecture, encryption, and secure configuration. Use when reviewing code for flaws, planning penetrati
Use when Codex should act as the Blockchain Security Auditor specialist from Agency Agents. Expert smart contract security auditor specializing in vulnerability detection, formal verification, exploit analysis, and comprehensive audit report writing for DeFi p
Use when Codex should act as the Cloud Security Architect specialist from Agency Agents. Cloud-native security specialist designing zero trust architectures, implementing defense-in-depth across AWS, Azure, and GCP, and securing infrastructure-as-code pipeline
Provides structured guidance for security compliance, threat modeling, risk assessments, audits, incident response, and security architecture. Use when asked to review policies against SOC2, ISO27001, GDPR, HIPAA, or PCI-DSS, model threats, build risk register
Use when Codex should act as the Compliance Auditor specialist from Agency Agents. Expert technical compliance auditor specializing in SOC 2, ISO 27001, HIPAA, and PCI-DSS audits — from readiness assessment through evidence collection to certification.
Hardens infrastructure, automates security controls in CI/CD, manages vulnerability and compliance programs, and supports incident response. Use when assessing security posture, deploying controls, automating compliance evidence, scanning vulnerabilities, desi
PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operati
Use when Codex should act as the Incident Responder specialist from Agency Agents. Digital forensics and incident response specialist who leads breach investigations, contains active threats, coordinates crisis response, and writes post-mortems that prevent re
Builds a security ownership topology from git history and computes bus factor for sensitive code. Use when the user asks for security-oriented ownership or bus-factor analysis of a git repository, sensitive-code ownership mapping, or export of ownership graphs
Provides security testing payloads and bypass techniques for XSS, SSRF, SQLi, XXE, NoSQLi, command injection, path traversal, IDOR, and authentication bypass. Use when testing authorized targets or bug bounty programs for these vulnerability classes.
Use when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, and pen test report gen
Use when Codex should act as the Penetration Tester specialist from Agency Agents. Offensive security specialist conducting authorized penetration tests, red team operations, and vulnerability assessments across networks, web applications, and cloud infrastruc
Plans authorized web application penetration tests from codebase analysis, producing a detailed pentest-plan.md with test cases tied to real code, endpoints, and config. Use when the user requests a pentest plan, security assessment plan, or attack surface rev
Drafts, reviews, aligns, and implements organizational security policies against standards and regulations. Use when researching policy best practices, building policy frameworks, drafting policy documents, reviewing existing policies, mapping policies to GDPR
Assesses and mitigates security risks across systems, vendors, and processes, producing risk registers, control assessments, policy reviews, incident response plans, and compliance reports. Use when the user needs vulnerability scanning, threat modeling, risk