trustshell
01Plugin Claude Code
Plugin marketplace listing 1 plugin: trustshell.
Plugin Claude Code
Plugin marketplace listing 1 plugin: trustshell.
Plugin Claude Code
AI agent security for Claude Code — read the code, break the running agent, prove it (exploit-validated). Commands: /static-scan, /red-team. Subagent: agent-red-teamer. Skills: RT-1..RT-9.
Agent
Use this to security-test an AI AGENT (not ordinary app code) — prompt injection, memory poisoning, tool/action abuse, sandbox escape, channel injection, supply chain, exfiltration. It runs TrustShell's static-triage → dynamic-confirm loop and reports only exploit-validated findings. Authorized, disposable-environment…
Command
Red-team a RUNNING AI agent you own/are authorized to test; a finding is CONFIRMED only when the exploit's proof marker returns. Authorized, disposable-env testing only.
Command
Statically triage an AI agent's SOURCE for candidate vulnerable paths (RT-1..RT-9). Candidate != vuln — confirm with /red-team.
Skill Claude CodeCodex
Security-audit an AI agent's OWN framework code for classic appsec vulnerabilities the LLM can't defend — path traversal, command injection, SSRF, fail-open security controls, missing/late auth, unsafe deserialization — especially at the untrusted-input boundaries (channels, file/media handlers, config & skill…
Skill Claude CodeCodex
Orchestrate a static + dynamic, exploit-validated red-team of an AI agent — read the source to find candidate vulnerable paths, then run the dynamic skills to confirm or refute each one empirically. The arbiter of truth is whether the exploit works, not a model vote. Authorized testing of agents you own or are…
Skill Claude CodeCodex
The end-to-end methodology for red-teaming a specific AI agent — adaptively, exploit-validated, and honestly. Read THIS target's own code, stand up a disposable harness, and prove or refute each weakness through a real attacker-reachable entry point. This is the orchestration + discipline that makes a finding…
Skill Claude CodeCodex
Red-team an AI agent for prompt injection — does content the agent is asked to process (email, page, ticket, tool result) override its actual task? Authorized testing of agents you own or are permitted to test.
Skill Claude CodeCodex
Red-team an AI agent's tools — can it be coerced (often via injection) into calling a tool it shouldn't, with attacker-influenced arguments, or into acting as a confused deputy with its own privileges? Authorized testing of agents you own or are permitted to test.
Skill Claude CodeCodex
Red-team an AI agent's tool-execution isolation — do tools run un-sandboxed on the host, and does the sandbox silently disable itself when a dependency is missing? Authorized testing of agents you own or are permitted to test.
Skill Claude CodeCodex
Red-team an AI agent's high-risk action gating — can a costly or destructive action (pay, message, delete) reach execution without out-of-band human confirmation, especially under auto-approve/unattended modes? Authorized testing of agents you own or are permitted to test.
Skill Claude CodeCodex
Red-team the channels an AI agent listens on (Telegram/Discord/Slack/WhatsApp/email/webhooks) — can untrusted inbound content, including group messages and forwards, steer the agent? Authorized testing of agents you own or are permitted to test.
Skill Claude CodeCodex
Red-team an AI agent's persistent memory for cross-session prompt injection ("memory poisoning") — does untrusted content the agent processes get written into long-term memory and re-fire in future sessions with no attacker present? Authorized testing of agents you own or are permitted to test.
Skill Claude CodeCodex
Red-team an AI agent's skill / plugin / MCP supply chain — can a poisoned skill doc, a malicious MCP server, or a dependency-confused package become persistent executable instruction? Authorized testing of agents you own or are permitted to test.
Skill Claude CodeCodex
Red-team an AI agent for data exfiltration — can an injection coax secrets, credentials, or sensitive data out of the agent through a tool call, a URL, or an outbound message? Authorized testing of agents you own or are permitted to test.
Skill Claude CodeCodex
Red-team a multi-agent system — can one agent (or content it relays) inject instructions into another, escalate privilege by hopping between agents, or turn an orchestrator/sub-agent handoff into a trust-laundering path? Authorized testing of systems you own or are permitted to test.