Run an audit without pretending certainty.
SecHelix is an Agent Skill and an evidence contract for scoped application-security reviews. Every page here describes behaviour that exists in the public framework repository. Where something has not been measured, it says so.
Install
npx skills@latest add omarmohelal/SecHelix --skill sechelixWorks for Claude Code, Codex, Cursor, and other Agent Skills clients.
Then point your coding agent at a repository you own or are explicitly authorized to test. The skill locks scope before any active testing. Continue with Quickstart or read What is SecHelix first.
Getting Started
What SecHelix is, how to install it, and how to run a first audit safely.
Using SecHelix
Task-shaped runs. Each one is an instruction to your coding agent, not a separate binary.
Core Concepts
The contracts that decide whether a claim is allowed to become a finding.
Tooling
How external scanner output enters the evidence contract.
Reference
The machine-readable side: contracts, report formats, the catalog, packs, and extensions.
Teams
Running SecHelix inside an organization alongside the tooling you already have.
Research
What has been measured, what has not, and why the difference is published.