Multi-plugin marketplace for Claude Code offensive security plugins
> /plugin marketplace add ogrodev/fsociety> /plugin install fsociety@ogrodev-fsociety
FAQ
fsociety is a Claude Code plugin with 25 hand-picked skills for security work, indexed on Flowy. Install it with the command on its page. It includes api-testing, cloud-lateral, network-recon. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.
Repo: ogrodev/fsociety
/$$$$$$ /$$ /$$
/$$__ $$ |__/ | $$
| $$ \__//$$$$$$$ /$$$$$$ /$$$$$$$ /$$ /$$$$$$ /$$$$$$ /$$ /$$
| $$$$ /$$_____/ /$$__ $$ /$$_____/| $$ /$$__ $$|_ $$_/ | $$ | $$
| $$_/ | $$$$$$ | $$ \ $$| $$ | $$| $$$$$$$$ | $$ | $$ | $$
| $$ \____ $$| $$ | $$| $$ | $$| $$_____/ | $$ /$$| $$ | $$
| $$ /$$$$$$$/| $$$$$$/| $$$$$$$| $$| $$$$$$$ | $$$$/| $$$$$$$
|__/ |_______/ \______/ \_______/|__/ \_______/ \___/ \____ $$
/$$ | $$
| $$$$$$/
\______/
Offensive security plugins for Claude Code
Plugins โข Getting Started โข How It Works โข Adding a Plugin
A growing suite of Claude Code plugins for offensive security. Each plugin is a self-contained toolkit targeting a specific domain of penetration testing โ web apps, reverse engineering, opsec, leak hunting, and beyond. One repo, multiple weapons, all conversational.
[!CAUTION] Authorized testing only. Always obtain written authorization before testing any target. Unauthorized access to computer systems is illegal. The authors assume no liability for misuse.
| Plugin | Domain | Description |
|---|---|---|
| elliot | Web & Application Security | Full offensive lifecycle โ recon, scan, exploit, weaponize, report. 24 commands, 9 skills, 2 agents |
| romero | Reverse Engineering | Windows binary analysis, decompilation, malware classification. 10 commands, 5 skills, 1 agent |
| trenton | Operational Security | Machine hardening, VPS security, anti-forensics, footprint elimination. 12 commands, 5 skills, 2 agents |
| tyrell | Leak Database Hunting | Exposed database discovery, data acquisition, cross-plugin pipeline to elliot. 16 commands, 5 skills, 2 agents |
| fsociety | Engagement Setup | Interactive workspace wizard โ targets, goals, scope, plugin selection, OPSEC profiles |
| dom | Mobile & IoT | Planned โ Android/iOS testing, API interception, firmware analysis |
Each plugin ships with AI agents designed for autonomous multi-step operations:
| Agent | Plugin | Role |
|---|---|---|
| darlene | elliot | Campaign orchestrator โ plans and runs multi-phase attack campaigns |
| scout | elliot | Reconnaissance โ maps attack surface before exploitation |
| cipher | romero | Reverse engineering orchestrator โ drives binary analysis workflows |
| ghost | trenton | Opsec orchestrator โ multi-phase machine hardening |
| cleaner | trenton | Anti-forensics specialist โ trace removal and footprint elimination |
| joanna | tyrell | Leak hunter โ multi-source exposed database discovery |
| scott | tyrell | Acquisition specialist โ probe, dump, convert, and pipeline data |
Add the fsociety marketplace, then install the plugins you need:
claude plugin marketplace add ogrodev/fsociety
claude plugin install elliot@fsociety
No cloning, no build step, no dependencies.
[!TIP] You can install multiple plugins at once. Each plugin is independent โ install only what you need.
Initialize an engagement workspace with the setup wizard:
/setup my-operation
The wizard walks you through targets, goals, scope, and plugin selection. It generates a tailored workspace:
| File | Purpose |
|---|---|
engagement.json | Central config โ targets, plugins, opsec level, scope |
CLAUDE.md | Tailored guidance with only your active plugin commands |
scope.md | Formal scope definition |
targets.jsonl | Structured target list (append-only, SHA256-deduped) |
Choose a profile that matches your engagement's anonymity requirements:
| Profile | Speed | Anonymity | Use Case |
|---|---|---|---|
surface | Maximum | None | Lab / CTF environments |
standard | Moderate | Basic | Authorized external tests |
paranoid | Slow | Full (Tor/VPN) | Red team engagements |
fsociety is not a Node.js application โ there's no build step, no package.json, no test suite. It's a Claude Code plugin marketplace: a collection of markdown-driven plugins that extend Claude Code with offensive security capabilities.
Every plugin follows the same structure:
plugin-name/
โโโ plugin.json # Plugin definition (name, version, skills, agents)
โโโ CLAUDE.md # Plugin-specific guidance for Claude Code
โโโ commands/*.md # Slash commands with YAML frontmatter
โโโ skills/*/SKILL.md # Auto-activating skills with reference docs
โโโ agents/*.md # Agent definitions with YAML frontmatter
โโโ scripts/*.js # Node.js scripts (zero npm deps, stdlib only)
โโโ hooks/hooks.json # Lifecycle hooks wiring scripts to events
fs, path, crypto, child_process).md files with YAML frontmatterfsociety/
โโโ .claude-plugin/
โ โโโ marketplace.json # Plugin registry
โโโ elliot/ # Web & Application security
โโโ romero/ # Reverse engineering
โโโ trenton/ # Operational security
โโโ tyrell/ # Leak database hunting
โโโ fsociety/ # Engagement setup & orchestration
โโโ CLAUDE.md
โโโ LICENSE
[!NOTE] See each plugin's own
README.mdfor its complete command reference, data layer, and conventions
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XX XX
XX MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM XX
XX MMMMMMMMMMMMMMMMMMMMMssssssssssssssssssssssssssMMMMMMMMMMMMMMMMMMMMM XX
XX MMMMMMMMMMMMMMMMss''' '''ssMMMMMMMMMMMMMMMM XX
XX MMMMMMMMMMMMyy'' ''yyMMMMMMMMMMMM XX
XX MMMMMMMMyy'' ''yyMMMMMMMM XX
XX MMMMMy'' ''yMMMMM XX
XX MMMy' 'yMMM XX
XX Mh' 'hM XX
XX - - XX
XX XX
XX :: :: XX
XX MMhh. ..hhhhhh.. ..hhhhhh.. .hhMM XX
XX MMMMMh ..hhMMMMMMMMMMhh. .hhMMMMMMMMMMhh.. hMMMMM XX
XX ---MMM .hMMMMdd:::dMMMMMMMhh.. ..hhMMMMMMMd:::ddMMMMh. MMM--- XX
XX MMMMMM MMmm'' 'mmMMMMMMMMyy. .yyMMMMMMMMmm' ''mmMM MMMMMM XX
XX ---mMM '' 'mmMMMMMMMM MMMMMMMMmm' '' MMm--- XX
XX yyyym' . 'mMMMMm' 'mMMMMm' . 'myyyy XX
XX mm'' .y' ..yyyyy.. '''' '''' ..yyyyy.. 'y. ''mm XX
XX MN .sMMMMMMMMMss. . . .ssMMMMMMMMMs. NM XX
XX N` MMMMMMMMMMMMMN M M NMMMMMMMMMMMMM `N XX
XX + .sMNNNNNMMMMMN+ `N N` +NMMMMMNNNNNMs. + XX
XX o+++ ++++Mo M M oM++++ +++o XX
XX oo oo XX
XX oM oo oo Mo XX
XX oMMo M M oMMo XX
XX +MMMM s s MMMM+ XX
XX +MMMMM+ +++NNNN+ +NNNN+++ +MMMMM+ XX
XX +MMMMMMM+ ++NNMMMMMMMMN+ +NMMMMMMMMNN++ +MMMMMMM+ XX
XX MMMMMMMMMNN+++NNMMMMMMMMMMMMMMNNNNMMMMMMMMMMMMMMNN+++NNMMMMMMMMM XX
XX yMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMy XX
XX m yMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMy m XX
XX MMm yMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMy mMM XX
XX MMMm .yyMMMMMMMMMMMMMMMM MMMMMMMMMM MMMMMMMMMMMMMMMMyy. mMMM XX
XX MMMMd ''''hhhhh odddo obbbo hhhh'''' dMMMM XX
XX MMMMMd 'hMMMMMMMMMMddddddMMMMMMMMMMh' dMMMMM XX
XX MMMMMMd 'hMMMMMMMMMMMMMMMMMMMMMMh' dMMMMMM XX
XX MMMMMMM- ''ddMMMMMMMMMMMMMMdd'' -MMMMMMM XX
XX MMMMMMMM '::dddddddd::' MMMMMMMM XX
XX MMMMMMMM- -MMMMMMMM XX
XX MMMMMMMMM MMMMMMMMM XX
XX MMMMMMMMMy yMMMMMMMMM XX
XX MMMMMMMMMMy. .yMMMMMMMMMM XX
XX MMMMMMMMMMMMy. .yMMMMMMMMMMMM XX
XX MMMMMMMMMMMMMMy. .yMMMMMMMMMMMMMM XX
XX MMMMMMMMMMMMMMMMs. .sMMMMMMMMMMMMMMMM XX
XX MMMMMMMMMMMMMMMMMMss. .... .ssMMMMMMMMMMMMMMMMMM XX
XX MMMMMMMMMMMMMMMMMMMMNo oNNNNo oNMMMMMMMMMMMMMMMMMMMM XX
XX XX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
__tests__/
elliot/
chain-detector.test.js
findings-tracker.test.js
post-scan-hook.test.js
pre-scan-check.test.js
resolve-data-dir.test.js
scan-profile.test.js
session-context.test.js
session-state.test.js
target-intel.test.js
techniques-tracker.test.js
fsociety/
engagement-tools-check.test.js
resolve-data-dir.test.js
setup-engine.test.js
utils.test.js
romero/
analysis-tracker.test.js
binary-hasher.test.js
findings-tracker.test.js
post-analysis-hook.test.js
pre-analysis-check.test.js
resolve-data-dir.test.js
session-state.test.js
tool-checker.test.js
utils.test.js
test-helper.js
trenton/
identity-tracker.test.js
ops-tracker.test.js
opsec-profile.test.js
post-ops-hook.test.js
pre-ops-check.test.js
resolve-data-dir.test.js
session-state.test.js
tool-checker.test.js
utils.test.js
tyrell/
acquisition-tracker.test.js
dumper.test.js
handoff-builder.test.js
handoff-tracker.test.js
hunt-engine.test.js
hunt-profile.test.js
pipeline.test.js
post-hunt-hook.test.js
pre-hunt-check.test.js
resolve-data-dir.test.js
session-state.test.js
source-tracker.test.js
tool-checker.test.js
utils.test.js
.claude-plugin/
marketplace.json
.github/
ISSUE_TEMPLATE/
bug_report.yml
config.yml
feature_request.yml
.gitignore
analysis-db.jsonl
CLAUDE.md
elliot/
.gitignore
agents/
darlene.md
scout.md
CLAUDE.md
commands/
apiscan.md
archives.md
bruteforce.md
campaign.md
dashboard.md
debrief.md
dirscan.md
enumerate.md
findings.md
fsociety.md
ingest.md
intel.md
payload.md
planner.md
portscan.md
profile.md
recon.md
report.md
scope.md
status.md
techniques.md
timeline.md
webscan.md
wpscan.md
hooks/
hooks.json
plugin.json
README.md
scripts/
chain-detector.js
findings-tracker.js
post-scan-hook.js
pre-scan-check.js
resolve-data-dir.js
scan-profile.js
session-context.js
session-state.js
target-intel.js
techniques-tracker.js
setup.sh
skills/
api-testing/
references/
api-enumeration.md
auth-bypass.md
graphql-attacks.md
jwt-attacks.md
mass-assignment.md
oauth-attacks.md
parameter-tampering.md
rate-limit-bypass.md
SKILL.md
cloud-lateral/
references/
cloud-persistence.md
cloud-service-abuse.md
container-escape.md
iam-escalation.md
imds-exploitation.md
serverless-attacks.md
storage-exfil.md
SKILL.md
network-recon/
references/
dns-recon.md
host-discovery.md
network-pivoting.md
os-fingerprinting.md
port-scanning.md
service-enum.md
vulnerability-scanning.md
SKILL.md
password-attacks/
references/
credential-stuffing.md
hash-cracking.md
kerberos-attacks.md
online-attacks.md
password-spraying.md
wordlist-generation.md
SKILL.md
payment-security/
references/
cart-manipulation.md
gateway-testing.md
payment-idor.md
price-manipulation.md
race-conditions.md
refund-abuse.md
SKILL.md
reporting/
references/
evidence-collection.md
executive-summary.md
finding-writeup.md
remediation-guidance.md
report-templates.md
SKILL.md
waf-bypass/
references/
aws-waf-bypass.md
cloudflare-bypass.md
encoding-evasion.md
modsecurity-bypass.md
protocol-level-bypass.md
waf-fingerprinting.md
SKILL.md
web-assessment/
references/
auth-testing.md
idor-testing.md
nosqli-testing.md
rce-testing.md
sqli-testing.md
ssrf-testing.md
ssti-testing.md
xss-testing.md
xxe-testing.md
SKILL.md
wordpress-hacking/
references/
wp-authentication.md
wp-enum.md
wp-exploits.md
wp-plugin-attacks.md
wp-post-exploitation.md
SKILL.md
templates/
CLAUDE.md
fsociety/
.gitignore
CLAUDE.md
commands/
setup.md
plugin.json
README.md
scripts/
engagement-tools-check.js
resolve-data-dir.js
setup-engine.js
utils.js
skills/
engagement-setup/
references/
engagement-guide.md
SKILL.md
LICENSE
README.md
romero/
.gitignore
agents/
cipher.md
CLAUDE.md
commands/
analyze.md
classify.md
decompile.md
diff.md
dotnet.md
re-install.md
re-report.md
re-status.md
secrets.md
unpack.md
hooks/
hooks.json
plugin.json
README.md
scripts/
analysis-tracker.js
binary-hasher.js
findings-tracker.js
post-analysis-hook.js
pre-analysis-check.js
resolve-data-dir.js
session-state.js
tool-checker.js
utils.js
skills/
binary-diffing/
references/
binary-type-strategies.md
function-matching.md
patch-analysis.md
tool-workflows.md
SKILL.md
dotnet-reversing/
references/
clr-internals.md
deobfuscation.md
malware-analysis.md
patching.md
serialization-attacks.md
SKILL.md
malware-classification/
references/
behavioral-indicators.md
family-fingerprinting.md
packer-detection.md
similarity-analysis.md
yara-rules.md
SKILL.md
pe-analysis/
references/
import-export-tables.md
overlay-analysis.md
pe-anomalies.md
pe-headers.md
resource-analysis.md
section-analysis.md
SKILL.md
secret-extraction/
references/
anti-analysis-bypass.md
binary-format-extraction.md
credential-patterns.md
crypto-material.md
string-analysis.md
SKILL.md
run-tests.sh
secrets-db.jsonl
trenton/
.gitignore
agents/
cleaner.md
ghost.md
CLAUDE.md
commands/
op-campaign.md
op-clean.md
op-harden.md
op-identity.md
op-install.md
op-planner.md
op-proxy.md
op-report.md
op-status.md
op-trace.md
op-vps.md
op-wipe.md
hooks/
hooks.json
plugin.json
README.md
scripts/
identity-tracker.js
ops-tracker.js
opsec-profile.js
post-ops-hook.js
pre-ops-check.js
resolve-data-dir.js
session-state.js
tool-checker.js
utils.js
skills/
anti-forensics/
references/
application-artifacts.md
cleanup-checklists.md
filesystem-artifacts.md
log-manipulation.md
memory-and-volatile.md
metadata-stripping.md
network-artifacts.md
secure-deletion.md
shell-history.md
SKILL.md
network-anonymity/
references/
dns-privacy.md
mac-and-fingerprint.md
proxy-chain-setup.md
traffic-obfuscation.md
vpn-killswitch.md
SKILL.md
opsec-reporting/
references/
compliance-reporting.md
debrief-and-delivery.md
evidence-handling.md
redaction-methodology.md
report-templates.md
SKILL.md
system-hardening/
references/
credential-and-browser.md
disk-and-memory.md
firewall-config.md
kernel-hardening.md
services-and-sandboxing.md
ssh-hardening.md
SKILL.md
vps-security/
references/
anonymous-acquisition.md
c2-infrastructure.md
encrypted-storage.md
hardened-provisioning.md
teardown-and-recovery.md
SKILL.md
tyrell/
.gitignore
agents/
joanna.md
scott.md
CLAUDE.md
commands/
ty-acquire.md
ty-campaign.md
ty-classify.md
ty-darkweb.md
ty-dork.md
ty-forums.md
ty-github.md
ty-handoff.md
ty-hunt.md
ty-install.md
ty-planner.md
ty-profile.md
ty-shodan.md
ty-sources.md
ty-status.md
ty-telegram.md
hooks/
hooks.json
plugin.json
README.md
scripts/
acquisition-tracker.js
dumper.js
... 85 moreยฉ 2026 Flowy ยท Free and open source
Built for Claude Code ยท Not affiliated with Anthropic