apiscan
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Web vulnerability scanning with multiple engines (nuclei, nikto, AI assessment)
> /plugin marketplace add ogrodev/fsociety > /plugin install fsociety@ogrodev-fsociety
How it fires
How this command gets triggered: by you, by Claude, or both.
/webscanContext preview
What this command does when you run it.
Web vulnerability scanning with multiple engines (nuclei, nikto, AI assessment)
description: Web vulnerability scanning with multiple engines (nuclei, nikto, AI assessment) allowed-tools: ToolSearch, Bash, Read, Write argument-hint: <target-url>
> **Storage Policy**: ALL output files MUST be saved in the project directory. NEVER write to `/tmp/` or any system temporary directory.
Target: `$ARGUMENTS`
Execute multi-engine web vulnerability scanning using Hexstrike MCP tools.
Use ToolSearch to load:
Run `nuclei_scan` against the target with:
Run `nikto_scan` for server misconfiguration, default files, and known vulnerable paths.
Run `ai_vulnerability_assessment` on the target for intelligent vulnerability detection that adapts to the target's technology stack and responses.
Consolidate findings from all three engines, deduplicate, and present sorted by severity:
Save consolidated report to `webscan-{target}.md` in the project directory. Flag any findings that warrant immediate manual investigation.
Multi-plugin marketplace for Claude Code offensive security plugins
Repo: ogrodev/fsociety
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Archive or list previous engagement snapshots
Password brute force and hash cracking against target services
Resume or execute an attack campaign with progress tracking
Show running scans, system health, and engagement status