apiscan
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Directory and content discovery with recursive crawling
> /plugin marketplace add ogrodev/fsociety > /plugin install fsociety@ogrodev-fsociety
How it fires
How this command gets triggered: by you, by Claude, or both.
/dirscanContext preview
What this command does when you run it.
Directory and content discovery with recursive crawling
description: Directory and content discovery with recursive crawling allowed-tools: ToolSearch, Bash, Read, Write argument-hint: <target-url>
> **Storage Policy**: ALL output files MUST be saved in the project directory. NEVER write to `/tmp/` or any system temporary directory.
Target: `$ARGUMENTS`
Execute comprehensive directory and content discovery using Hexstrike MCP tools.
Use ToolSearch to load:
Run `feroxbuster_scan` against the target with:
Run `gobuster_scan` in directory mode with a different wordlist than feroxbuster to maximize coverage. Include vhost mode if subdomain enumeration is relevant.
Run `katana_crawl` for JavaScript-aware crawling that discovers dynamically generated paths, API endpoints in client-side code, and linked resources that brute-forcing misses.
Deduplicate findings across all tools. Present organized by:
Save to `dirscan-{target}.md` in the project directory.
Multi-plugin marketplace for Claude Code offensive security plugins
Repo: ogrodev/fsociety
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Archive or list previous engagement snapshots
Password brute force and hash cracking against target services
Resume or execute an attack campaign with progress tracking
Show running scans, system health, and engagement status