rafter-cli
01Skill Claude Code
Rafter is a security CLI that protects your codebase from leaked secrets, dangerous commands, and vulnerable dependencies. It works offline with zero config. No API key, no account, no telemetry.
Multi-language CLI for Rafter — the security toolkit built for AI coding agents and the developers who use them.
This repository also configures its own agents. See what rafter-cli tells them →
Skill Claude Code
Rafter is a security CLI that protects your codebase from leaked secrets, dangerous commands, and vulnerable dependencies. It works offline with zero config. No API key, no account, no telemetry.
Skill Claude Code
Security toolkit for AI workflows. Use when scanning code or repos for vulnerabilities, auditing third-party skills/MCPs/agent configs before installing, evaluating shell commands before running them, or generating secure design questions for new features. Provides rafter run (remote SAST + SCA, needs RAFTERAPIKEY)…
Skill Claude Code
REQUIRED before declaring a task done when the diff touches user input, SQL, shell, auth, credentials, file paths, serialization, crypto, network endpoints, data deletion, or dependency surface. Judge by that surface, not the task label — research/experimental/local-only code with none of it can skip this. Walks…
Skill Claude Code
REQUIRED before writing code for any feature touching auth, payments, credentials, tokens, sessions, file upload, user data, untrusted input, deserialization, network endpoints, or data deletion. Scope by that surface, not the task label — a research/experimental/local-only feature with none of it doesn't need this.…
Skill Claude Code needs its repo
REQUIRED before copying any third-party SKILL.md, MCP manifest, Cursor rule, or agent config into this machine or forwarding one to a user. Installing a skill grants Read/Bash/network under your identity — this is curl | sh in a different costume. Do not install, load, recommend, or forward any third-party agent asset…
Skill Claude Code
Entry point for rafter. Invoke when a sub-skill is unclear, or when the task needs rafter run (remote SAST+SCA), rafter secrets (local secrets-only), rafter audit, policy checks, or command-risk evaluation. Scope by security surface, not task label: engage when the diff touches auth, credentials/secrets/tokens…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: