{"id":30116,"plugin_id":"plugins_6aab2358993881919183acd471020907","kind":"detail","collection_source":"plugin_api","comparison_source":null,"observed_at":"2026-10-09T00:10:08.043Z","digest":"82d056cd3bb3f6612cc287414bf68aeecac634193e34d369126eb058ac92cc2f","against":20903,"payload":{"canonical_app_id":null,"connector_id":null,"created_at":"2026-09-16T23:19:46.866528Z","discoverability":"LISTED","id":"plugins_6aab2358993881919183acd471020907","is_template":false,"name":"tahr-codex-plugin","release":{"app_ids":[],"app_manifest":null,"app_templates":[],"description":"Evidence-backed application security workflows for finding, validating, and fixing vulnerabilities.","display_name":"Tahr Security","id":"pluginrel_b884a2fc99a88191b0a63c74aa4eed35","interface":{"brand_color":"#7A00F9","capabilities":["Read","Write"],"category":"Security","composer_icon_dark_url":"https://files.openai.com/content?id=file_00000000ce90823089934bba59dac300","composer_icon_url":"https://files.openai.com/content?id=file_00000000660481f5a1442a615da54212","default_prompt":"Run a comprehensive evidence-backed security review of this application and prioritize demonstrated findings.","default_prompts":["Run a comprehensive evidence-backed security review of this application and prioritize demonstrated findings.","Map this application's attack surface, roles, trust boundaries, routes, parameters, and exposed interfaces.","Verify this security fix in the original vulnerable context and test for bypasses and regressions."],"developer_name":"Tahr Security Inc","logo_url":"https://files.openai.com/content?id=file_00000000115c81fdbc186ad5c35e2784","logo_url_dark":"https://files.openai.com/content?id=file_00000000ea4c820d8e74493de7d6b5ba","long_description":"Review applications with an evidence-first security workflow that maps attack surfaces, tests authentication and access controls, traces dangerous inputs, models threats, and verifies fixes.","plugin_category_id":"security","privacy_policy_url":"https://tahr.one/privacy","screenshot_urls":[],"short_description":"Evidence-backed app security","terms_of_service_url":"https://tahr.one/terms","website_url":"https://tahr.one"},"keywords":[],"mcp_servers":[],"onboarding_skill_name":null,"requires_local_executor":false,"skills":[{"description":"Audit Android application security from an APK, AAB-derived APK, Android source repository, manifest, or authorized emulator/device. Use for mobile release reviews, OWASP MASVS-oriented assessments, exported component and deep-link testing, WebView and IPC review, local storage and token analysis, mobile API traffic review, runtime instrumentation, privacy testing, and Android hardening validation.","interface":{"brand_color":null,"default_prompt":"Use $tahr-audit-android to perform a source-backed and runtime-aware Android security review.","display_name":"Tahr Audit Android","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Audit Android application security boundaries"},"name":"tahr-audit-android","plugin_release_skill_id":"pluginrsk_6aab235ace048191b4a7cfe05d6fec47"},{"description":"Audit application-owned secrets, cryptography, dependency reachability, infrastructure-as-code, containers, CI/CD, cloud permissions, and runtime security configuration with evidence and false-positive controls. Use for repository hardening, deployment review, leaked-key triage, dependency/CVE review, exposed debug or admin surface checks, or pre-release configuration audits.","interface":{"brand_color":null,"default_prompt":"Use $tahr-audit-secrets-config to review secrets, dependencies, infrastructure, and security configuration.","display_name":"Tahr Audit Secrets and Config","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Audit secrets, dependencies, and deployment config"},"name":"tahr-audit-secrets-config","plugin_release_skill_id":"pluginrsk_6aab235c97708191977fec31782591f4"},{"description":"Map the real security-relevant surface of a web application or API from source, specifications, JavaScript, browser behavior, and authorized traffic. Use for pre-pentest reconnaissance, security-review scoping, hidden route or parameter discovery, undocumented API inventory, role-aware surface comparison, or judging whether an existing review actually covered the application.","interface":{"brand_color":null,"default_prompt":"Use $tahr-map-attack-surface to inventory the reachable security boundaries in this application.","display_name":"Tahr Map Attack Surface","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Map the real application attack surface"},"name":"tahr-map-attack-surface","plugin_release_skill_id":"pluginrsk_6aab235d47508191b5e83d0146c36fb8"},{"description":"Read applications, assessments, and findings from an already configured Tahr MCP connection. Trigger only when the user explicitly asks to query, list, summarize, or review Tahr account data; do not trigger for generic security reviews, source-code reviews, or non-Tahr findings.","interface":{"brand_color":null,"default_prompt":"Use $tahr-review-tahr-findings to summarize the latest Tahr security findings.","display_name":"Review Tahr Findings","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Review findings from an existing Tahr account"},"name":"tahr-review-tahr-findings","plugin_release_skill_id":"pluginrsk_6aab235acfac81918a12ea9f76844934"},{"description":"Perform an evidence-backed, pentester-style security review of an application from source, configuration, specifications, tests, and optionally an explicitly authorized local or staging runtime. Use for comprehensive app security audits, pentest readiness, pre-release reviews, dangerous-flaw discovery, or coordinating the Tahr specialist skills; also use when a prior scanner or LLM review created confidence that needs independent verification.","interface":{"brand_color":null,"default_prompt":"Use $tahr-secure-app to perform an evidence-backed security review of this application.","display_name":"Tahr Secure App","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Run an evidence-backed application security review"},"name":"tahr-secure-app","plugin_release_skill_id":"pluginrsk_6aab235e3d7c8191b918016702d1c7f2"},{"description":"Perform complete or focused, evidence-backed access-control review from source and optionally an explicitly authorized local or staging runtime. Model subjects, roles, tenants, resources, actions, properties, policy rules, enforcement points, and owner-attributed test cases; trace object-, function-, property-, role-, and tenant-level authorization through REST, GraphQL, web, job, and asynchronous paths; safely validate IDOR/BOLA/BFLA, mass assignment, privilege escalation, and cross-tenant isolation; and reject status-code or guessed-ID false positives. Use for authorization code review, multi-user or multi-tenant assessments, admin and role boundary analysis, pre-pentest review, or validation of a suspected access-control finding.","interface":{"brand_color":null,"default_prompt":"Use $tahr-test-access-control to perform a complete, evidence-backed access-control review of this application and separate confirmed flaws from rejected or unproven leads.","display_name":"Tahr Test Access Control","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Prove authorization flaws and reject weak signals"},"name":"tahr-test-access-control","plugin_release_skill_id":"pluginrsk_6aab235fe5688191be06baf481b254f4"},{"description":"Test security boundaries in applications that use LLM chat, RAG or vector retrieval, memory, file or URL ingestion, model-rendered output, tool/function calling, MCP, or autonomous agents. Use for source-backed AI feature reviews, authorized local or staging runtime tests, prompt-injection assessments, cross-tenant retrieval checks, agent/tool abuse reviews, and AI resource-control testing.","interface":{"brand_color":null,"default_prompt":"Use $tahr-test-ai-agents to review LLM, RAG, tool, and agent security boundaries in this application.","display_name":"Tahr Test AI Agents","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Test LLM, RAG, and agent trust boundaries"},"name":"tahr-test-ai-agents","plugin_release_skill_id":"pluginrsk_6aab235fa25c8191a7e34256bd09f0d3"},{"description":"Review and safely test web authentication and session boundaries across login, registration, password reset, magic links, MFA or OTP, OAuth/OIDC, SAML, passkeys, tokens, cookies, logout, and recovery. Use for authentication code review, pre-release auth testing, account-takeover analysis, session-management review, SSO integration review, or validating an existing security assessment.","interface":{"brand_color":null,"default_prompt":"Use $tahr-test-authentication to review login, recovery, MFA, OAuth, and session controls in this application.","display_name":"Tahr Test Authentication","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Test authentication and session boundaries"},"name":"tahr-test-authentication","plugin_release_skill_id":"pluginrsk_6aab235e97e081918e36ab6f6727cd38"},{"description":"Model and safely abuse-test stateful business workflows, API operations, and application invariants such as checkout, billing, credits, invitations, approvals, entitlements, exports, uploads, integrations, quotas, and asynchronous jobs. Use for business-logic review, race-condition and replay testing, mass-assignment or excessive-property review, workflow bypass analysis, API version/parser comparison, or pre-pentest testing of critical product flows.","interface":{"brand_color":null,"default_prompt":"Use $tahr-test-business-workflows to model and abuse-test critical workflows in this application.","display_name":"Tahr Test Business Workflows","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Test stateful business logic for abuse"},"name":"tahr-test-business-workflows","plugin_release_skill_id":"pluginrsk_6aab235e8e888191989e2ac751a5f73a"},{"description":"Build a full, implementation-backed threat model of an entire existing application, covering actors, assets, trust boundaries, entrypoints, hop-level data flows, abuse cases, connected attack paths, security invariants, control gaps, risk responses, and executable validation handoffs. Use for comprehensive system threat modeling, security architecture assessment, pentest preparation, or correlating a complete application repository with configuration, IaC, API schemas, diagrams, and deployment documentation. Do not use for a feature-only, diff-only, or design-only review.","interface":{"brand_color":null,"default_prompt":"Use $tahr-threat-model-app to perform a full implementation-backed threat model of this entire existing application and produce validated security decisions and test handoffs.","display_name":"Tahr Threat Model App","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Threat-model an entire existing application"},"name":"tahr-threat-model-app","plugin_release_skill_id":"pluginrsk_6aab235ea5a481919180744788f14c61"},{"description":"Trace attacker-controlled input through parsing, validation, normalization, storage, and dangerous server or browser sinks, then safely validate exploitability with class-specific proof gates. Use for injection review, source-to-sink analysis, XSS, SQL/NoSQL injection, command or template injection, SSRF, XXE, path traversal, unsafe deserialization, file upload/processing, webhook, CORS/postMessage, or client-side trust-boundary testing.","interface":{"brand_color":null,"default_prompt":"Use $tahr-trace-dangerous-inputs to find exploitable source-to-sink paths in this application.","display_name":"Tahr Trace Dangerous Inputs","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Trace untrusted input to dangerous sinks"},"name":"tahr-trace-dangerous-inputs","plugin_release_skill_id":"pluginrsk_6aab235c23608191a62a0ebf1c8e2da8"},{"description":"Retest a security fix in the exact vulnerable context, decide whether the exploit path is closed, and validate secure remediation and regression coverage without breaking legitimate behavior. Use after a vulnerability patch, remediation commit, PR fix, dependency or configuration change, failed security retest, or when developers need proof that a fix is complete rather than a superficial code change.","interface":{"brand_color":null,"default_prompt":"Use $tahr-verify-security-fix to prove this security fix closes the vulnerable path without breaking legitimate behavior.","display_name":"Tahr Verify Security Fix","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Verify fixes with exploit-focused regression tests"},"name":"tahr-verify-security-fix","plugin_release_skill_id":"pluginrsk_6aab235aeb80819180ffbb646de5d452"}],"version":"0.3.3"},"scope":"GLOBAL","share_url":"https://chatgpt.com/plugins/plugins_6aab2358993881919183acd471020907?open_in_app","status":"ENABLED"},"changes":[{"path":"/discoverability","type":"changed","before":"UNLISTED","after":"LISTED"},{"path":"/share_url","type":"changed","before":null,"after":"https://chatgpt.com/plugins/plugins_6aab2358993881919183acd471020907?open_in_app"}],"summary":"Fields changed: 2. /discoverability, /share_url.","summary_kind":"deterministic","summary_metadata":{}}