Security commands

2,534 tagged Security, measured the same way as everything else here.

Browse within: compliance 150gdpr 116ai-security 82devsecops 75appsec 66bug-bounty 64claude-ai 52cybersecurity 52offensive-security 52ai-governance 51pentesting 51ai-coding 49ctf 46defi 32

code-review

289

dvasyliev/ai-dev-tools-getting-started

Command

Perform a thorough code review that verifies functionality, maintainability, and security before approving a change. Focus on architecture, readability, performance implications, and provide actionable suggestions for improvement.

not rated 21 +1 4mo ago A 0 tokens

campaign

292

ogrodev/fsociety

Command

Resume or execute an attack campaign with progress tracking.

not rated 20 5mo ago A 9 tokens original MIT

fsociety

293

ogrodev/fsociety

Command

Weaponize confirmed findings into validated exploit packages.

not rated 20 5mo ago A 8 tokens original MIT

planner

294

ogrodev/fsociety

Command

Analyze engagement state and create a strategic attack plan.

not rated 20 5mo ago A 9 tokens original MIT

deep-review

295

ronnycoding/.claude

Command

Run parallel specialized PR reviews (Opus 4.6 for security/architecture, Sonnet 4.6 for the rest).

not rated 20 2mo ago A 27 tokens

ai-logical-bug-scan

296

marcosd4h/DeepExtractRuntime

Command

AI-driven scan for logic vulnerabilities: authentication/authorization bypass, state machine errors, confused deputy, privilege escalation, missing impersonation revert, and sensitive API parameter injection.

not rated 20 +2 4mo ago A 0 tokens original MIT

audit

297

marcosd4h/DeepExtractRuntime

Command

Perform a focused security audit of a specific function -- building a comprehensive security dossier, tracing attack reachability, and reporting findings with risk assessment and recommendations.

not rated 20 +2 4mo ago A 0 tokens original MIT

taint

298

marcosd4h/DeepExtractRuntime

Command

AI-driven taint analysis: trace attacker-controlled data from entry points to dangerous sinks across module boundaries. Uses LLM agents that navigate taint-enriched callgraphs with trust boundary metadata, read decompiled code on demand, and verify findings against assembly ground truth.

not rated 20 +2 4mo ago A 0 tokens original MIT

security-checklist

299

claude-code-expert/example

Command Claude Code

A command that checks a project's security against a specified checklist and labels each item as passed, failed, or not applicable.

not rated 19 1mo ago B 0 tokens

nio

300

core0-io/nio

Command

Nio — scan code, evaluate an action, read the audit report, manage config.

not rated 19 12d ago A 17 tokens original Apache-2.0

registry-security

301

starslingdev/skills

Command

Check a published skill's skills.sh security audit, decide the next action, and drive a stale badge to green unattended.

not rated 19 7d ago A 23 tokens original MIT

evaluate-repository

304

Aero-Vance/awesome-cl-code

Command Claude Code

You are evaluating a repository intended for use in or alongside Claude Code, where certain features (such as hooks, commands, scripts, or automation) may execute implicitly or with elevated trust once enabled by a user.

not rated 19 5mo ago B 0 tokens

review

306

JSK9999/ai-nexus

Command

Code review command - review diff, check security, performance, style, tests.

not rated 18 5mo ago A 15 tokens original Apache-2.0

security

307

eddiesanjuan/markupr

Command Claude Code

Perform a thorough security audit of markupr, an Electron app that handles API keys, screen recordings, voice data, and AI API communication. This audit covers Electron-specific attack surfaces, OWASP Top 10 adapted for desktop apps, and markupr's specific threat model.

not rated 18 4mo ago A 0 tokens original MIT

audit

312

ducpm2303/claude-java-plugins

Command

Part of java-quality

Full quality audit — runs security scan, performance check, and test coverage analysis in sequence and produces a combined report.

not rated 16 5mo ago A 22 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: