Signal-driven black-box security testing skill for authorized bug bounty, SRC, crowdsourced, and enterprise assessments across Web, API, cloud, mobile, and AI applications. Use when Codex needs a structured security testing workflow with scan modes, first-pass vulnerability signals, business-logic modeling, sensitivity triage, exploit chaining, HITL external-resource controls, and classic CLI-oriented tooling.
MCP-first black-box security testing skill for authorized bug bounty, SRC, crowdsourced, and enterprise assessments when Yakit MCP and Chrome MCP are available. Use when Codex should run Atomic Rain with MCP-based HTTP fuzzing, traffic querying, browser automation, SyntaxFlow static analysis, exec_codec transformations, scan modes, business-logic modeling, HITL external-resource controls, and evidence automation.