apiscan
API security audit — REST, GraphQL, JWT analysis, parameter discovery
AI-powered payload generation for XSS, SQLi, LFI, command injection, and more
> /plugin marketplace add ogrodev/fsociety > /plugin install fsociety@ogrodev-fsociety
How it fires
How this command gets triggered: by you, by Claude, or both.
/payloadContext preview
What this command does when you run it.
AI-powered payload generation for XSS, SQLi, LFI, command injection, and more
description: AI-powered payload generation for XSS, SQLi, LFI, command injection, and more allowed-tools: ToolSearch, Bash, Read, Write argument-hint: <type> <target-context>
Type: `$1` Context: `$2`
Generate targeted security testing payloads using Hexstrike AI tools.
Use ToolSearch to load:
Map the requested type to the appropriate category:
Run `ai_generate_payload` with:
If a broader test is needed, run `ai_generate_attack_suite` to create a comprehensive set of payloads covering multiple injection points and evasion techniques.
If the target is WAF-protected, also run `advanced_payload_generation` with evasion context for:
Optionally run `ai_test_payload` against the target to validate which payloads succeed and which are blocked.
Present payloads organized by:
Include usage instructions for each payload (where to inject, expected response).
Multi-plugin marketplace for Claude Code offensive security plugins
Repo: ogrodev/fsociety
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Archive or list previous engagement snapshots
Password brute force and hash cracking against target services
Resume or execute an attack campaign with progress tracking
Show running scans, system health, and engagement status