{"id":4798,"external_id":"plugins_6aab2358993881919183acd471020907","name":"tahr-codex-plugin","display_name":"Tahr Security","developer":"Tahr Security Inc","category":"Security","listing_language":"en","listing_language_details":{"method":"cld-0.13.0/listing-v1","reliable":true,"detected_at":"2026-10-01T13:22:05Z","input_sha256":"cb7c4b757ab0b9a425fbeb7699f9894e534e3a49bf3c540edf2015a7472d96fa","source_fields":["release.description","release.interface.short_description","release.interface.long_description"]},"version":"0.3.3","skill_count":12,"first_seen_at":"2026-09-30T22:02:35.000Z","last_seen_at":"2026-10-01T12:00:01.032Z","last_changed_at":"2026-09-30T22:02:35.000Z","install_count":null,"research_summary":null,"research_reviewed_at":null,"metadata":{"id":"plugins_6aab2358993881919183acd471020907","name":"tahr-codex-plugin","scope":"GLOBAL","status":"ENABLED","release":{"id":"pluginrel_b884a2fc99a88191b0a63c74aa4eed35","skills":[{"name":"tahr-audit-android","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Audit Android","default_prompt":"Use $tahr-audit-android to perform a source-backed and runtime-aware Android security review.","icon_large_url":null,"icon_small_url":null,"short_description":"Audit Android application security boundaries"},"description":"Audit Android application security from an APK, AAB-derived APK, Android source repository, manifest, or authorized emulator/device. Use for mobile release reviews, OWASP MASVS-oriented assessments, exported component and deep-link testing, WebView and IPC review, local storage and token analysis, mobile API traffic review, runtime instrumentation, privacy testing, and Android hardening validation.","plugin_release_skill_id":"pluginrsk_6aab235ace048191b4a7cfe05d6fec47"},{"name":"tahr-audit-secrets-config","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Audit Secrets and Config","default_prompt":"Use $tahr-audit-secrets-config to review secrets, dependencies, infrastructure, and security configuration.","icon_large_url":null,"icon_small_url":null,"short_description":"Audit secrets, dependencies, and deployment config"},"description":"Audit application-owned secrets, cryptography, dependency reachability, infrastructure-as-code, containers, CI/CD, cloud permissions, and runtime security configuration with evidence and false-positive controls. Use for repository hardening, deployment review, leaked-key triage, dependency/CVE review, exposed debug or admin surface checks, or pre-release configuration audits.","plugin_release_skill_id":"pluginrsk_6aab235c97708191977fec31782591f4"},{"name":"tahr-map-attack-surface","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Map Attack Surface","default_prompt":"Use $tahr-map-attack-surface to inventory the reachable security boundaries in this application.","icon_large_url":null,"icon_small_url":null,"short_description":"Map the real application attack surface"},"description":"Map the real security-relevant surface of a web application or API from source, specifications, JavaScript, browser behavior, and authorized traffic. Use for pre-pentest reconnaissance, security-review scoping, hidden route or parameter discovery, undocumented API inventory, role-aware surface comparison, or judging whether an existing review actually covered the application.","plugin_release_skill_id":"pluginrsk_6aab235d47508191b5e83d0146c36fb8"},{"name":"tahr-review-tahr-findings","interface":{"brand_color":null,"iconography":"radar","display_name":"Review Tahr Findings","default_prompt":"Use $tahr-review-tahr-findings to summarize the latest Tahr security findings.","icon_large_url":null,"icon_small_url":null,"short_description":"Review findings from an existing Tahr account"},"description":"Read applications, assessments, and findings from an already configured Tahr MCP connection. Trigger only when the user explicitly asks to query, list, summarize, or review Tahr account data; do not trigger for generic security reviews, source-code reviews, or non-Tahr findings.","plugin_release_skill_id":"pluginrsk_6aab235acfac81918a12ea9f76844934"},{"name":"tahr-secure-app","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Secure App","default_prompt":"Use $tahr-secure-app to perform an evidence-backed security review of this application.","icon_large_url":null,"icon_small_url":null,"short_description":"Run an evidence-backed application security review"},"description":"Perform an evidence-backed, pentester-style security review of an application from source, configuration, specifications, tests, and optionally an explicitly authorized local or staging runtime. Use for comprehensive app security audits, pentest readiness, pre-release reviews, dangerous-flaw discovery, or coordinating the Tahr specialist skills; also use when a prior scanner or LLM review created confidence that needs independent verification.","plugin_release_skill_id":"pluginrsk_6aab235e3d7c8191b918016702d1c7f2"},{"name":"tahr-test-access-control","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Test Access Control","default_prompt":"Use $tahr-test-access-control to perform a complete, evidence-backed access-control review of this application and separate confirmed flaws from rejected or unproven leads.","icon_large_url":null,"icon_small_url":null,"short_description":"Prove authorization flaws and reject weak signals"},"description":"Perform complete or focused, evidence-backed access-control review from source and optionally an explicitly authorized local or staging runtime. Model subjects, roles, tenants, resources, actions, properties, policy rules, enforcement points, and owner-attributed test cases; trace object-, function-, property-, role-, and tenant-level authorization through REST, GraphQL, web, job, and asynchronous paths; safely validate IDOR/BOLA/BFLA, mass assignment, privilege escalation, and cross-tenant isolation; and reject status-code or guessed-ID false positives. Use for authorization code review, multi-user or multi-tenant assessments, admin and role boundary analysis, pre-pentest review, or validation of a suspected access-control finding.","plugin_release_skill_id":"pluginrsk_6aab235fe5688191be06baf481b254f4"},{"name":"tahr-test-ai-agents","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Test AI Agents","default_prompt":"Use $tahr-test-ai-agents to review LLM, RAG, tool, and agent security boundaries in this application.","icon_large_url":null,"icon_small_url":null,"short_description":"Test LLM, RAG, and agent trust boundaries"},"description":"Test security boundaries in applications that use LLM chat, RAG or vector retrieval, memory, file or URL ingestion, model-rendered output, tool/function calling, MCP, or autonomous agents. Use for source-backed AI feature reviews, authorized local or staging runtime tests, prompt-injection assessments, cross-tenant retrieval checks, agent/tool abuse reviews, and AI resource-control testing.","plugin_release_skill_id":"pluginrsk_6aab235fa25c8191a7e34256bd09f0d3"},{"name":"tahr-test-authentication","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Test Authentication","default_prompt":"Use $tahr-test-authentication to review login, recovery, MFA, OAuth, and session controls in this application.","icon_large_url":null,"icon_small_url":null,"short_description":"Test authentication and session boundaries"},"description":"Review and safely test web authentication and session boundaries across login, registration, password reset, magic links, MFA or OTP, OAuth/OIDC, SAML, passkeys, tokens, cookies, logout, and recovery. Use for authentication code review, pre-release auth testing, account-takeover analysis, session-management review, SSO integration review, or validating an existing security assessment.","plugin_release_skill_id":"pluginrsk_6aab235e97e081918e36ab6f6727cd38"},{"name":"tahr-test-business-workflows","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Test Business Workflows","default_prompt":"Use $tahr-test-business-workflows to model and abuse-test critical workflows in this application.","icon_large_url":null,"icon_small_url":null,"short_description":"Test stateful business logic for abuse"},"description":"Model and safely abuse-test stateful business workflows, API operations, and application invariants such as checkout, billing, credits, invitations, approvals, entitlements, exports, uploads, integrations, quotas, and asynchronous jobs. Use for business-logic review, race-condition and replay testing, mass-assignment or excessive-property review, workflow bypass analysis, API version/parser comparison, or pre-pentest testing of critical product flows.","plugin_release_skill_id":"pluginrsk_6aab235e8e888191989e2ac751a5f73a"},{"name":"tahr-threat-model-app","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Threat Model App","default_prompt":"Use $tahr-threat-model-app to perform a full implementation-backed threat model of this entire existing application and produce validated security decisions and test handoffs.","icon_large_url":null,"icon_small_url":null,"short_description":"Threat-model an entire existing application"},"description":"Build a full, implementation-backed threat model of an entire existing application, covering actors, assets, trust boundaries, entrypoints, hop-level data flows, abuse cases, connected attack paths, security invariants, control gaps, risk responses, and executable validation handoffs. Use for comprehensive system threat modeling, security architecture assessment, pentest preparation, or correlating a complete application repository with configuration, IaC, API schemas, diagrams, and deployment documentation. Do not use for a feature-only, diff-only, or design-only review.","plugin_release_skill_id":"pluginrsk_6aab235ea5a481919180744788f14c61"},{"name":"tahr-trace-dangerous-inputs","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Trace Dangerous Inputs","default_prompt":"Use $tahr-trace-dangerous-inputs to find exploitable source-to-sink paths in this application.","icon_large_url":null,"icon_small_url":null,"short_description":"Trace untrusted input to dangerous sinks"},"description":"Trace attacker-controlled input through parsing, validation, normalization, storage, and dangerous server or browser sinks, then safely validate exploitability with class-specific proof gates. Use for injection review, source-to-sink analysis, XSS, SQL/NoSQL injection, command or template injection, SSRF, XXE, path traversal, unsafe deserialization, file upload/processing, webhook, CORS/postMessage, or client-side trust-boundary testing.","plugin_release_skill_id":"pluginrsk_6aab235c23608191a62a0ebf1c8e2da8"},{"name":"tahr-verify-security-fix","interface":{"brand_color":null,"iconography":"radar","display_name":"Tahr Verify Security Fix","default_prompt":"Use $tahr-verify-security-fix to prove this security fix closes the vulnerable path without breaking legitimate behavior.","icon_large_url":null,"icon_small_url":null,"short_description":"Verify fixes with exploit-focused regression tests"},"description":"Retest a security fix in the exact vulnerable context, decide whether the exploit path is closed, and validate secure remediation and regression coverage without breaking legitimate behavior. Use after a vulnerability patch, remediation commit, PR fix, dependency or configuration change, failed security retest, or when developers need proof that a fix is complete rather than a superficial code change.","plugin_release_skill_id":"pluginrsk_6aab235aeb80819180ffbb646de5d452"}],"app_ids":[],"version":"0.3.3","keywords":[],"interface":{"category":"Security","logo_url":"https://files.openai.com/content?id=file_00000000115c81fdbc186ad5c35e2784","brand_color":"#7A00F9","website_url":"https://tahr.one","capabilities":["Read","Write"],"logo_url_dark":"https://files.openai.com/content?id=file_00000000ea4c820d8e74493de7d6b5ba","default_prompt":"Run a comprehensive evidence-backed security review of this application and prioritize demonstrated findings.","developer_name":"Tahr Security Inc","default_prompts":["Run a comprehensive evidence-backed security review of this application and prioritize demonstrated findings.","Map this application's attack surface, roles, trust boundaries, routes, parameters, and exposed interfaces.","Verify this security fix in the original vulnerable context and test for bypasses and regressions."],"screenshot_urls":[],"long_description":"Review applications with an evidence-first security workflow that maps attack surfaces, tests authentication and access controls, traces dangerous inputs, models threats, and verifies fixes.","composer_icon_url":"https://files.openai.com/content?id=file_00000000660481f5a1442a615da54212","short_description":"Evidence-backed app security","plugin_category_id":"security","privacy_policy_url":"https://tahr.one/privacy","terms_of_service_url":"https://tahr.one/terms","composer_icon_dark_url":"https://files.openai.com/content?id=file_00000000ce90823089934bba59dac300"},"description":"Evidence-backed application security workflows for finding, validating, and fixing vulnerabilities.","app_manifest":null,"display_name":"Tahr Security","app_templates":[],"onboarding_skill_name":null,"requires_local_executor":false},"created_at":"2026-09-16T23:19:46.866528Z","is_template":false,"connector_id":null,"discoverability":"UNLISTED","canonical_app_id":null},"research":null,"package_metadata":{"name":"tahr-codex-plugin","author":{"name":"Yack Security Inc"},"license":"GPL-3.0-only","sources":[{"path":"plugin.json","sha256":"900e71452da82dbe9705e43600fe0acc940ee7d1182e95bd118e25ae7371f0c7"},{"path":".codex-plugin/plugin.json","sha256":"468f41db3aeb46487ba5497b1b6f85a299f35afbc00b34a3c65fa9ea749a41df"}],"version":"0.3.3","repository":"https://github.com/tahr-security/tahr-security-skills","artifact_id":5708,"observed_at":"2026-09-30T23:16:39Z","support_url":"https://tahr.one/contact","capabilities":["Read","Write"],"field_sources":{"name":0,"author":0,"license":0,"version":0,"repository":0,"support_url":0,"capabilities":0},"extraction_version":1,"conflicts_or_errors":[]}}