apiscan
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Port scanning with fast discovery and detailed service enumeration
> /plugin marketplace add ogrodev/fsociety > /plugin install fsociety@ogrodev-fsociety
How it fires
How this command gets triggered: by you, by Claude, or both.
/portscanContext preview
What this command does when you run it.
Port scanning with fast discovery and detailed service enumeration
description: Port scanning with fast discovery and detailed service enumeration allowed-tools: ToolSearch, Bash, Read, Write argument-hint: <target-ip-or-domain>
> **Storage Policy**: ALL output files MUST be saved in the project directory. NEVER write to `/tmp/` or any system temporary directory.
Target: `$ARGUMENTS`
Execute a two-phase port scan using Hexstrike MCP tools.
Use ToolSearch to load:
Run `rustscan_fast_scan` against the target with a high batch size for speed. This identifies all open ports quickly.
Take the open ports discovered by RustScan and run `nmap_advanced_scan` against only those ports with:
Present findings as a table: | Port | Service | Version | Notes | |------|---------|---------|-------|
Save detailed results to `portscan-{target}.md` in the project directory.
Flag any interesting findings: unusual ports, outdated versions, services with known CVEs.
Multi-plugin marketplace for Claude Code offensive security plugins
Repo: ogrodev/fsociety
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Archive or list previous engagement snapshots
Password brute force and hash cracking against target services
Resume or execute an attack campaign with progress tracking
Show running scans, system health, and engagement status