apiscan
API security audit — REST, GraphQL, JWT analysis, parameter discovery
One-line engagement pulse — target, phase, findings, chains, profile
> /plugin marketplace add ogrodev/fsociety > /plugin install fsociety@ogrodev-fsociety
How it fires
How this command gets triggered: by you, by Claude, or both.
/statusContext preview
What this command does when you run it.
One-line engagement pulse — target, phase, findings, chains, profile
description: One-line engagement pulse — target, phase, findings, chains, profile allowed-tools: Bash argument-hint:
Run all status queries in parallel and output a single condensed status line.
Run these in parallel:
node "${CLAUDE_PLUGIN_ROOT}/scripts/session-state.js" show
node "${CLAUDE_PLUGIN_ROOT}/scripts/findings-tracker.js" summary
node "${CLAUDE_PLUGIN_ROOT}/scripts/chain-detector.js"
node "${CLAUDE_PLUGIN_ROOT}/scripts/scan-profile.js" get 2>/dev/null || echo '{"name":"normal"}'Parse the results and output a single status line:
<target> | Phase <n>/<total> | Step <n>/<total> | <N> findings (<N> CRIT) | <N> chains | <profile>
Examples:
target.com | Phase 2/4 | Step 3/7 | 14 findings (2 CRIT) | 3 chains | stealth example.org | Phase 1/3 | Step 1/5 | 0 findings | 0 chains | normal (no campaign) | 6 findings (1 CRIT, 2 HIGH) | 1 chain | loud
If there are active blockers, add on a second line:
Blockers: <count> active (<descriptions>)
That's it. No extra commentary, no verbose output. Just the pulse.
Multi-plugin marketplace for Claude Code offensive security plugins
Repo: ogrodev/fsociety
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Archive or list previous engagement snapshots
Password brute force and hash cracking against target services
Resume or execute an attack campaign with progress tracking
Show running scans, system health, and engagement status