Command Claude Code
Aggressively review an OWASP cheat sheet PR across security, practicality, links/sources, duplication, and language; produce a single MERGE/REQUESTCHANGES/CLOSE verdict.
82 tagged appsec, measured the same way as everything else here.
Browse within: devsecops 24sast 23ai-security 19cybersecurity 17bug-bounty 15exploit-validation 15semgrep 15threat-modeling 15api-security 9authentication 9authorization 9business-logic 9compliance 9governance 9
Command Claude Code
Aggressively review an OWASP cheat sheet PR across security, practicality, links/sources, duplication, and language; produce a single MERGE/REQUESTCHANGES/CLOSE verdict.
Command
Command "recon" from Zyrexnn/Cybermes, covering /recon, what this does, usage, steps and step 1: subdomain enumeration.
Command
Command "report" from Zyrexnn/Cybermes, covering /report, pre-conditions, usage, what this generates and platform selection.
Command
Command "web3-audit" from Zyrexnn/Cybermes, covering /web3-audit, usage, step 0: pre-dive kill signals, find accounting variables and find all early returns in critical functions.
Command Claude Code
Manage Hacker Bob egress profiles for this project.
Command Claude Code
Run or resume a Hacker Bob security evaluation.
Command Claude Code
Run the installed Hacker Bob update workflow for this project.
Command
Run automated static analysis and write the results to .claude/findings.json.
Command
Prepare a focused analysis scope for large codebases or monorepos using repomix. Creates a digestible snapshot of the target code for subsequent security analysis.
Command
Combines application understanding with systematic threat identification. First understands the application, then identifies what could go wrong.
Command Claude Code
Manual full-run E2E check — runs the threat-model pipeline against the bundled synthetic-repo fixture and validates 25 structural assertions. Costs 30–50% of a Pro 5h-window; never auto-triggered.
Command Claude Code
Triage a failed make release-check — read the captured log, identify the failing gate stage, and recommend the producer-side fix. Analysis only; applies nothing unless asked.
Command
Scan a Rust project and produce a supply chain security gap analysis.
Command
Generate a single supply chain security config file.
Command
Verify that generated supply chain configs are valid and functional.
Command
Security-audit a codebase with Sabba -- rank risk, find bugs, prove them.
Command
Recon and scan an authorized target with Sabba's security tools, then confirm findings.
Command
Prove the current change actually works, by running it (base-fail / head-pass).
ch0ks/hackarandas-claude-toolbelt
Command
Check if Semgrep is installed and working. If not, install it using the best available method. Then log in to Semgrep Pro, enable the Pro engine, and run a local Pro scan in the current directory.
ch0ks/hackarandas-claude-toolbelt
Command
List all Claude Code sessions across all projects, sorted by most recent. Show project context, date, and the exact resume command for each session.
Command
Assess the repository against SicarioSpec guardrails.
Command
Generate or update docs/compliance/control-applicability.md.
Command
Run deterministic verification.
Command
Pre-merge security gate on the current branch — runs secrets, SAST and dep-vuln checks on changed code, honors documented exceptions, returns a hard PASS/FAIL verdict.