FlorianBruniaux/claude-code-ultimate-guide
Command Claude Code
Audit quality of agents, skills, and commands in a Claude Code project.
217 tagged ai security, measured the same way as everything else here.
Browse within: bug-bounty 61cybersecurity 58bugcrowd 52devsecops 49claude-ai 37cti 37agentic-security 30attack-trees 30llm-security 28agentic-coding 27ai-assistant 27ai-pair-programming 27appsec 19open-source 18
FlorianBruniaux/claude-code-ultimate-guide
Command Claude Code
Audit quality of agents, skills, and commands in a Claude Code project.
FlorianBruniaux/claude-code-ultimate-guide
Command Claude Code
Audit repository documentation against 85+ best practices from claude-code-ultimate-guide.
FlorianBruniaux/claude-code-ultimate-guide
Command Claude Code
Audit version freshness, FR/EN parity, and metadata quality of all whitepapers and recap cards.
Command
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 | /bypass-403 -l.
Command
Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 + okta (via TREVORspray). Default delay 30min/round + 60s jitter. Usage /spray --mode --users --passes.
Command
Smart contract security audit — runs through 10 bug class checklist (accounting desync, access control, incomplete path, off-by-one, oracle errors, ERC4626, reentrancy, flash loan, signature replay, proxy/upgrade). Applies pre-dive kill signals first. Generates Foundry PoC template for confirmed findings. Usage…
elementalsouls/Claude-BugHunter
Command
Active vulnerability hunting. Two-track dispatcher — asks Red Team vs WAPT, hands off to hunt-dispatch skill and sibling commands. Usage: /hunt target.com | /hunt .target.com | /hunt targets.txt [--vuln-class X] [--source-code P] [--chrome].
elementalsouls/Claude-BugHunter
Command
Run full recon pipeline on a target — subdomain enum (Chaos API + subfinder), live host discovery (dnsx + httpx), URL crawl (katana + waybackurls + gau), gf pattern classification, nuclei scan. Outputs to recon/ / directory. Usage: /recon target.com.
elementalsouls/Claude-BugHunter
Command
Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP lock bypass, authority retention, bonding curve exploits, fake renounce, sandwich amplification). Manual 8-class grep audit (with an optional automated scanner if present). Usage: /token-scan [--chain solana].
Command
List pentest-ai agents relevant to a domain or tag (web, ad, cloud, mobile, recon, etc.).
Command
Update the project memory with what was accomplished in this session.
Command
Recommend the right pentest-ai agent and concrete next steps for a freeform task description.
Command
Set up Adrian security - choose the backend and configure your API key.
Command
Show Adrian security status - backend URL, key presence, and connection health.
Command Claude Code
Create a commit using the git-commit-creator skill.
Command Claude Code
Create an issue using the github-issue-creator skill. Here is the relevant info for the issue: #$ARGUMENTS.
Agent-Threat-Rule/agent-threat-rules
Command Claude Code
Open GitHub issues on flagged repos to notify authors before public disclosure.
Agent-Threat-Rule/agent-threat-rules
Command Claude Code
Scan the most popular MCP skills to find issues in well-known packages. This is the highest-value content for Skills Sec.
Agent-Threat-Rule/agent-threat-rules
Command Claude Code
Show current status of the scanning pipeline and content queue.
sinewaveai/agent-security-scanner-mcp
Command Claude Code
Analyze the current file for security vulnerabilities detected by the Agent Security extension and automatically apply fixes.
Command
Full SAIL V2 gap analysis of the AI agent/system in the current repo — component inventory, all 91 catalog risks dispositioned, prioritized recommendations. Writes SAIL-assessment.md.
Command
SAIL V2 compliance checklist — ISO/IEC 42001, EU AI Act, OWASP LLM/Agentic, DASF, AIUC-1. All five frameworks by default, or only those named.
Command
Vendor RFP questionnaire from the SAIL V2 catalog — security-vendor coverage questionnaire by default, platform-vendor framing on request.
Command Claude Code
Execute implementation with Architect checkpoints at critical phases - Streamlined v2.