Security and Hardening
addyosmani/agent-skills
Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.
安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
$ npx skills add ReJeCtAll/ExpertTeam-Codex --skill expert-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ReJeCtAll/ExpertTeam-Codex expert-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ReJeCtAll/ExpertTeam-Codex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/expert-security .claude/skills/expert-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "expert-security" agent skill from https://github.com/ReJeCtAll/ExpertTeam-Codex/tree/main/.codex/skills/expert-security into .claude/skills/expert-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "expert-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ReJeCtAll/ExpertTeam-Codex/tree/main/.codex/skills/expert-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ReJeCtAll/ExpertTeam-Codex --skill expert-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ReJeCtAll/ExpertTeam-Codex expert-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ReJeCtAll/ExpertTeam-Codex.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/expert-security .agents/skills/expert-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "expert-security" agent skill from https://github.com/ReJeCtAll/ExpertTeam-Codex/tree/main/.codex/skills/expert-security into .agents/skills/expert-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "expert-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ReJeCtAll/ExpertTeam-Codex --skill expert-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ReJeCtAll/ExpertTeam-Codex expert-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ReJeCtAll/ExpertTeam-Codex.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/expert-security .cursor/skills/expert-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "expert-security" agent skill from https://github.com/ReJeCtAll/ExpertTeam-Codex/tree/main/.codex/skills/expert-security into .cursor/skills/expert-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "expert-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ReJeCtAll/ExpertTeam-Codex.git --path .codex/skills/expert-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ReJeCtAll/ExpertTeam-Codex --skill expert-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ReJeCtAll/ExpertTeam-Codex expert-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ReJeCtAll/ExpertTeam-Codex.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/expert-security .gemini/skills/expert-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "expert-security" agent skill from https://github.com/ReJeCtAll/ExpertTeam-Codex/tree/main/.codex/skills/expert-security into .gemini/skills/expert-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "expert-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ReJeCtAll/ExpertTeam-Codex expert-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ReJeCtAll/ExpertTeam-Codex --skill expert-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ReJeCtAll/ExpertTeam-Codex.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/expert-security .github/skills/expert-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "expert-security" agent skill from https://github.com/ReJeCtAll/ExpertTeam-Codex/tree/main/.codex/skills/expert-security into .github/skills/expert-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "expert-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ReJeCtAll/ExpertTeam-Codex --skill expert-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ReJeCtAll/ExpertTeam-Codex expert-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ReJeCtAll/ExpertTeam-Codex.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/expert-security .opencode/skills/expert-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "expert-security" agent skill from https://github.com/ReJeCtAll/ExpertTeam-Codex/tree/main/.codex/skills/expert-security into .opencode/skills/expert-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "expert-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
expert-security安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
Expert Security is an agent skill from ReJeCtAll/ExpertTeam-Codex. 安全专家入口。用于 Codex CLI 的 $expert-security 调用。 适用于威胁建模、漏洞评估、安全代码审查、安全架构设计、DevSecOps、安全运营、事件响应、合规审计和完整安全健康评估。 触发词:安全专家、威胁建模、STRIDE、OWASP、SAST、DAST、SBOM、漏洞评估、代码审计、事件响应、合规审计、SOC、等保、GDPR、PIPL、隐私政策审查
Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Security, covering Privacy and GDPR, Web application vulnerabilities and Threat modeling. The repository describes itself as: 一套可直接安装到 ~/.codex 的专家配置,面向 Codex CLI / Codex App 桌面版的 Skill 调用方式 提供 3 个专家团、3 个单专家与 1 个总路由入口。 The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 59c573b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Expert Security loads about 780 tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 127 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ReJeCtAll/ExpertTeam-Codex at commit 59c573b, republished under its MIT licence (© ReJeCtAll). 127 words, ~780 tokens.
.claude/skills/expert-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.你现在启动单专家模式的 安全专家,Agent ID 为 security-expert。
面向产品、代码、架构和运营全链路的安全问题,输出可验证、可排序、可落地的安全结论。该入口专注应用安全、威胁建模、安全审计、事件响应和合规治理;基础设施变更落地由 $expert-ops 承接,代码修复由 $expert-software 承接。
$expert-security <security request>
$expert-security --protect <security architecture or preventive control request>
$expert-security --detect <vulnerability assessment or threat detection request>
$expert-security --ops <security operations or governance request>
$expert-security --audit <full security audit request>
$expert-security --threat <STRIDE threat modeling request>
$expert-security --incident <incident response planning request>
$expert-security --code-review <secure code review request>
$expert-security --compliance <compliance gap analysis request>
$expert-security --full <complete security health assessment>注意:Codex CLI 当前使用
$skill-name调用 Skill,不一定识别/expert-securitySlash Command。
如环境支持 Agents,优先读取并采用:
~/.codex/agents/security-expert.md如环境不支持独立 Agent 调度,则由当前会话按本 Skill 的规则执行。
--protect:安全防护方向,覆盖威胁建模、零信任、安全架构、DevSecOps、数据安全、IAM 和安全基线。--detect:威胁检测方向,覆盖 OWASP Top 10、API 安全、容器安全、依赖漏洞、SBOM、代码审计、入侵检测、WAF 和 RASP。--ops:安全运营方向,覆盖事件响应、根因分析、SOC 建设、漏洞管理生命周期、等保、SOC 2、ISO 27001、GDPR 和个人信息保护法。--audit:对目标系统或代码库进行全面安全审计,输出结构化评估报告。--threat:对系统、功能或数据流做 STRIDE 威胁建模,输出威胁矩阵和缓解措施。--incident:制定事件响应预案,包含分类定级、升级路径、取证保全、恢复流程和复盘机制。--code-review:对源代码进行安全代码审查,按 OWASP、CWE 和语言生态风险给出漏洞清单与修复建议。--compliance:进行合规差距分析,覆盖等保 2.0、ISO 27001、SOC 2、GDPR、个人信息保护法或 PCI-DSS。--full:完整安全健康评估,覆盖防护、检测、运营、代码、架构和合规。当用户要求审查隐私政策、隐私协议或个人信息处理规则的 PIPL 合规性时,优先加载并使用 $privacy-policy-pipl-audit 的 18 维审查框架。
未提供参数时,根据用户意图选择单一方向;同时涉及三个及以上方向时使用完整安全健康评估。
$expert-software 或 $expert-ops。最终输出应包含:
$expert-software。$expert-ops。$expert-product。$expert-design。请使用与用户原始需求一致的语言输出。
© ReJeCtAll, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/expert-security of ReJeCtAll/ExpertTeam-Codex.
Open the folder on GitHubat commit 59c573b
Expert Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Expert Security this skillReJeCtAll/ExpertTeam-Codex | 113 | — | ~780 | Automated safety check: Pass | MIT | |
| Security and Hardeningaddyosmani/agent-skills | 103k | 1 repos | ~4.4k | Automated safety check: Notes | MIT | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Vulnerability ScannerxenitV1/Antigravity-Workflows | 130 | 7 repos | ~1.8k | Automated safety check: Notes | MIT | |
| Csono-session/pstack | 134 | — | ~12k | Automated safety check: Notes | MIT | |
| Golang Securityunxed/f4 | 241 | 2 repos | ~3.6k | Automated safety check: Pass | MIT |
addyosmani/agent-skills
Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
xenitV1/Antigravity-Workflows
Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.
no-session/pstack
Chief Security Officer mode. An agent skill from no-session/pstack.
unxed/f4
Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
ReJeCtAll/ExpertTeam-Codex
产品战略团队完整手册。覆盖需求文档撰写、路线图管理、竞品分析、用户研究综合、指标评审、Sprint规划、干系人沟通和产品头脑风暴全流程。当涉及任何产品管理相关的请求时自动触发。
ReJeCtAll/ExpertTeam-Codex
数据库优化专家入口。用于 Codex CLI 的 $expert-database 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
ReJeCtAll/ExpertTeam-Codex
设计原型专家团入口。用于 Codex CLI 的 $expert-design 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
ReJeCtAll/ExpertTeam-Codex
基础设施运维专家入口。用于 Codex CLI 的 $expert-ops 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
ReJeCtAll/ExpertTeam-Codex
产品战略团队专家团入口。用于 Codex CLI 的 $expert-product 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
ReJeCtAll/ExpertTeam-Codex
软件开发团队专家团入口。用于 Codex CLI 的 $expert-software 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
Categories
安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex. Expert Security is an agent skill from ReJeCtAll/ExpertTeam-Codex.
Expert Security fits situations like: tasks that involve Privacy and GDPR; tasks that involve Web application vulnerabilities; tasks that involve Threat modeling.
Run `npx skills add ReJeCtAll/ExpertTeam-Codex --skill expert-security -a claude-code`. Or copy the skill folder (.codex/skills/expert-security in ReJeCtAll/ExpertTeam-Codex) into .claude/skills/expert-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ReJeCtAll/ExpertTeam-Codex --skill expert-security -a codex`. Or copy the skill folder (.codex/skills/expert-security in ReJeCtAll/ExpertTeam-Codex) into .agents/skills/expert-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ReJeCtAll/ExpertTeam-Codex --skill expert-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/expert-security, .gemini/skills/expert-security, .github/skills/expert-security and .opencode/skills/expert-security in your project.
SKILL.md names no scripts, command-line tools or credentials: Expert Security is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Expert Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 780 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Expert Security: Security and Hardening (addyosmani/agent-skills, 103k stars), Cyber Neo (Hainrixz/cyber-neo, 281 stars), Vulnerability Scanner (xenitV1/Antigravity-Workflows, 130 stars) and Cso (no-session/pstack, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ReJeCtAll (a GitHub user) maintains it in ReJeCtAll/ExpertTeam-Codex, which has 113 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on July 8, 2026.
Source: ReJeCtAll/ExpertTeam-Codex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.