archives
Archive or list previous engagement snapshots
API security audit — REST, GraphQL, JWT analysis, parameter discovery
> /plugin marketplace add ogrodev/fsociety > /plugin install fsociety@ogrodev-fsociety
How it fires
How this command gets triggered: by you, by Claude, or both.
/apiscanContext preview
What this command does when you run it.
API security audit — REST, GraphQL, JWT analysis, parameter discovery
description: API security audit — REST, GraphQL, JWT analysis, parameter discovery allowed-tools: ToolSearch, Bash, Read, Write argument-hint: <api-base-url>
> **Storage Policy**: ALL output files MUST be saved in the project directory. NEVER write to `/tmp/` or any system temporary directory.
Target: `$ARGUMENTS`
Execute a comprehensive API security audit using Hexstrike MCP tools.
Use ToolSearch to load:
Check for common API documentation endpoints:
Run `comprehensive_api_audit` against the API base URL. This performs broad coverage testing including auth, injection, access control, and business logic.
If JWT tokens are in scope, run `jwt_analyzer` to:
Run `arjun_parameter_discovery` on key endpoints to find hidden/undocumented parameters that may bypass access controls or enable injection.
Run `api_fuzzer` on discovered endpoints with:
Run `graphql_scanner` for:
Save findings to `apiscan-{target}.md` in the project directory, organized by:
Multi-plugin marketplace for Claude Code offensive security plugins
Repo: ogrodev/fsociety
Archive or list previous engagement snapshots
Password brute force and hash cracking against target services
Resume or execute an attack campaign with progress tracking
Show running scans, system health, and engagement status
Post-engagement lessons learned analysis and debrief report