Codex Security

Codex Security from ConcertoNotes/codex-plugins.

by @concertonotes 9 skills

Skills in this plugin

9
  1. Validation · concertonotes bundle
    Use when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
    0 repo stars
  2. Fix Finding · concertonotes bundle
    Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
    0 repo stars
  3. Security Scan · concertonotes bundle
    Use when the user asks for a repository-wide or scoped-path security scan.
    0 repo stars
  4. Track Findings · concertonotes bundle
    Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use it for scans or fixes.
    0 repo stars
  5. Triage Finding · concertonotes bundle
    Use when the user supplies or imports existing security findings, vulnerability reports, or security/vulnerability Jira/Linear tickets from scanners, advisories, GitHub, Atlassian Rovo, Linear, or similar backlog sources and wants static repo-impact triage. Do not use for discovery, duplicate-bug triage, validation, or fixes.
    0 repo stars
  6. Finding Discovery · concertonotes bundle
    Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
    0 repo stars
  7. Deep Security Scan · concertonotes bundle
    Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated independent discovery passes over one resolved scope with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, canonical JSON completion, and generated reporting once. Do not use for PRs, commits, branch diffs, or working-tree diffs.
    0 repo stars
  8. Security Diff Scan · concertonotes bundle
    Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.
    0 repo stars
  9. Attack Path Analysis · concertonotes bundle
    Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
    0 repo stars