status
97Command
You are the operator providing a status summary of the current engagement.
2,363 tagged Security, measured the same way as everything else here.
Browse within: compliance 158gdpr 116ai-security 109bug-bounty 89claude-ai 79devsecops 71appsec 61ai-governance 52bugcrowd 49ctf 45offensive-security 44pentesting 43cti 40cybersecurity 37
Command
You are the operator providing a status summary of the current engagement.
sinewaveai/agent-security-scanner-mcp
Command Claude Code
Analyze the current file for security vulnerabilities detected by the Agent Security extension and automatically apply fixes.
Command
Command "c2_evasion" from SeaOf0/dsh-redteam-model, covering c2 evasion command, usage, what this command does, critical: per-rule analysis and priority framework.
Command
Command "loader_generate" from SeaOf0/dsh-redteam-model, covering loader generate command, usage, what this command does, components and output.
Command
Command "tools_evasion" from SeaOf0/dsh-redteam-model, covering input, workflow, phase 1: tool understanding, phase 2: open source detection (if applicable) and phase 3: behavior analysis.
Command
Run all auditors and produce a ship-readiness scorecard.
Command
Full SAIL V2 gap analysis of the AI agent/system in the current repo — component inventory, all 91 catalog risks dispositioned, prioritized recommendations. Writes SAIL-assessment.md.
Command
SAIL V2 compliance checklist — ISO/IEC 42001, EU AI Act, OWASP LLM/Agentic, DASF, AIUC-1. All five frameworks by default, or only those named.
Command
Vendor RFP questionnaire from the SAIL V2 catalog — security-vendor coverage questionnaire by default, platform-vendor framing on request.
Command
Set up an open source repository for healthy long-term maintenance — branch protection, commit signing, tag immutability, issue and PR templates, CODEOWNERS, CONTRIBUTING.md, SECURITY.md, Dependabot, stale bot, and triage workflow. Use when the user is publishing an open source project, mentions branch protection…
Command Claude Code
A read-only security review command for a specified task, code change, design, or threat model.
get-convex/convex-agent-plugins
Command
Audit and harden Convex authorization: identity-from-arg impersonation, missing per-document ownership checks, PII-leaking public queries. Deterministic scan + canonical requireIdentity/requireOwner fix + tsc verify. Use for 'secure my app' / 'audit auth' / 'who can access this data', not generic code review.
incogbyte/android-reverse-engineering-claude-skill
Command
Decompile an Android APK/XAPK/AAB/DEX/JAR/AAR and analyze its structure.
AsifKibria/claude-code-toolkit
Command
Scan all conversations for leaked secrets and PII.
cisco-foundation-ai/fully-automated-prompt-optimization
Command Claude Code
Copyright 2026 Cisco Systems, Inc. and its affiliates.
Command
Enforce 7 production safety gates with evidence before deployment.
Command
Fee Config Validator: the generalized Bags exploit. A curated catalog of the silent zero-revenue class — revenue-bearing config fields (fees, royalties, rewards) that, if omitted or set to zero, quietly collect nothing forever. The call succeeds, nothing reverts, and a creator/treasury/holder simply earns $0.
Command Claude Code
Security audit for Solana programs (Anchor/native).
Command Claude Code
Manage Hacker Bob egress profiles for this project.
Command Claude Code
Run or resume a Hacker Bob security evaluation.
Command Claude Code
Run the installed Hacker Bob update workflow for this project.
Command
Define the attack profile for an engagement — select which attack categories and skills to use. Saves to .pentest-attacks.json. If run before /pentest:pentest, the orchestrator will respect the selection. If run standalone, does not launch a pentest.
Command
Connect to a Metasploit-Kali Server (MKS) REST API — verifies connectivity, discovers available Kali tools, and configures agents to prefer MKS endpoints over local Bash equivalents.
Command
Activate pentest mode — displays ASCII art, configures session isolation, collects engagement scope, then OWNS the engagement: pre-flight, recon, planning (via the pentester-orchestrator planner), executor dispatch, a time-budget quota loop, aggregation, and report generation.