sechelix-lite
v4.0.0-alpha.7by omarmohelal · author: Omar
sechelix-lite is an Agent Plugin published by omarmohelal. It packages 1 skill. We fetched the plugin.json from GitHub on 2026-10-08 and checked it against the official Agent Plugins 1.0.0 schema.
Application-security review skill for codebases and pull requests you are authorized to assess. Maps trust boundaries, keeps issues as hypotheses until evidenced, runs a separate pass that tries to refute material findings, and ends with a release verdict.
- Skills
- 1
- MCP servers
- 0
- Stars
- 1
- License
- Apache-2.0
- Repo created
- 2026-08-31
- Last pushed
- 2026-10-05
- Publisher type
- User
- Version
- 4.0.0-alpha.7
Links
Skills · 1
- sechelix-lite
- Evidence-first application-security review for codebases, pull requests and environments the user is authorized to assess. Use when asked to security-review a repository or diff, audit authentication, authorization (IDOR/BOLA/BFLA), business logic, race conditions, injection, SSRF, file handling, s…
Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
Category
Other. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.
Keywords
security · appsec · security-review · code-review · authorization · business-logic · supply-chain · ai-security
Related by publisher and keywords
Evidence-first application-security Agent Skill for repositories and environments you are authorized to test. Maps the attack surface, selects applicable security hypotheses from a 546-item catalog, hunts in parallel across specialist roles, then sends every candidate to an independent verifier whose job is to disprove it. Applicability resolves to APPLICABLE, NOT_APPLICABLE, UNKNOWN or BLOCKED so missing evidence is never read as absence; High and Critical findings require regression proof; and the release gate is fail-closed, returning PASS, PASS_WITH_KNOWN_RISK, BLOCKED or INCOMPLETE. Includes an UNTRUSTED_REPO mode that treats repository content as data and never as control instructions.
Trent, an AI security engineer. Review code, plans and configs for security problems, run threat models over a repo or website, and track remediation without leaving the editor.
Investigate incidents, review code and execute UAT for release readiness, scan code for vulnerabilities, and run penetration tests with AWS DevOps Agent and AWS Security Agent.
Add Auth0 authentication to any app: login, MFA, SSO, Organizations, RBAC, ACUL, custom domains, and branding. Debug auth errors, validate JWTs, manage token lifecycles, and migrate from Clerk, Firebase, or Cognito. Covers React, Next.js, Vue, Nuxt, Angular, Express, Flask, Spring Boot, Go, Swift, Android, Flutter, Laravel, PHP, ASP.NET Core, React Native, Expo, Ionic,.NET MAUI, and more.
Skills for using the Pixee CLI: authentication, scans, workflows, repositories, findings, and API access.
Agent workflow skills that behave the same in Claude Code and Codex CLI, with a portability contract enforced in CI.
[](https://agentpluginsdirectory.com/plugins/sechelix-lite)✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.