gadievron/raptor
Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we configure the agent for adversarial thinking, an
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
Copy this rig
# review before running: this installs third-party code
$ npx degit gadievron/raptor/.claude ./rig-raptor # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit gadievron/raptor/.claude/skills/audit .claude/skills/audit $ npx degit gadievron/raptor/.claude/skills/code-understanding .claude/skills/code-understanding $ npx degit gadievron/raptor/.claude/skills/exploitability-validation .claude/skills/exploitability-validation $ npx degit gadievron/raptor/.claude/skills/frida .claude/skills/frida
$ curl -fsSL --create-dirs -o .claude/agents/audit-reviewer.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/audit-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/coverage-analysis-generator-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/coverage-analysis-generator-agent.md $ curl -fsSL --create-dirs -o .claude/agents/crash-analysis-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/crash-analysis-agent.md $ curl -fsSL --create-dirs -o .claude/agents/crash-analyzer-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/crash-analyzer-agent.md $ curl -fsSL --create-dirs -o .claude/agents/crash-analyzer-checker-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/crash-analyzer-checker-agent.md $ curl -fsSL --create-dirs -o .claude/agents/crash-report-fetcher-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/crash-report-fetcher-agent.md $ curl -fsSL --create-dirs -o .claude/agents/exploitability-validator-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/exploitability-validator-agent.md $ curl -fsSL --create-dirs -o .claude/agents/function-trace-generator-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/function-trace-generator-agent.md $ curl -fsSL --create-dirs -o .claude/agents/offsec-specialist.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/offsec-specialist.md $ curl -fsSL --create-dirs -o .claude/agents/oss-evidence-verifier-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/oss-evidence-verifier-agent.md $ curl -fsSL --create-dirs -o .claude/agents/oss-hypothesis-checker-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/oss-hypothesis-checker-agent.md $ curl -fsSL --create-dirs -o .claude/agents/oss-hypothesis-former-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/oss-hypothesis-former-agent.md $ curl -fsSL --create-dirs -o .claude/agents/oss-investigator-gh-archive-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/oss-investigator-gh-archive-agent.md $ curl -fsSL --create-dirs -o .claude/agents/oss-investigator-github-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/oss-investigator-github-agent.md $ curl -fsSL --create-dirs -o .claude/agents/oss-investigator-ioc-extractor-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/oss-investigator-ioc-extractor-agent.md $ curl -fsSL --create-dirs -o .claude/agents/oss-investigator-local-git-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/oss-investigator-local-git-agent.md $ curl -fsSL --create-dirs -o .claude/agents/oss-investigator-wayback-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/oss-investigator-wayback-agent.md $ curl -fsSL --create-dirs -o .claude/agents/oss-report-generator-agent.md https://raw.githubusercontent.com/gadievron/raptor/main/.claude/agents/oss-report-generator-agent.md
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Skills (4)
Subagents (18)
| audit-reviewer model: inherit | Hypothesis-driven code review with tool-grounded validation. Forms testable hypotheses, validates with Semgrep/Coccinelle/SMT, records findings. |
| coverage-analyzer model: inherit | Generate gcov coverage data for a code repository. |
| crash-analysis-agent model: inherit | Analyze security bugs from any C/C++ project with full root-cause tracing |
| crash-analyzer model: inherit | Analyze crashes using rr recordings, function traces, and coverage data to produce root-cause analyses. |
| crash-analysis-checker model: inherit | Carefully analyze root cause analysis reports for crashes to make sure they are correct |
| crash-report-fetcher model: inherit | Fetch a bug-tracker report and distil it into one schema-validated bug-report.json artifact |
| exploitability-validator-agent model: inherit | Multi-stage pipeline to validate vulnerability findings are real, reachable, and exploitable |
| function-trace-generator model: inherit | Generate function-level execution traces for debugging and analysis. |
| offsec-specialist model: inherit | Use this agent when the user needs to perform offensive security operations, security testing, or vulnerability research tasks. This includes:\n\n<example>\nContext: User wants to test a web applicati |
| oss-evidence-verifier-agent model: inherit | Verify all collected evidence against original sources |
| oss-hypothesis-checker-agent model: inherit | Validate hypothesis claims against verified evidence |
| oss-hypothesis-former-agent model: inherit | Form evidence-backed hypotheses for forensic investigations |
| oss-investigator-gh-archive-agent model: inherit | Query GH Archive via BigQuery for tamper-proof forensic evidence |
| oss-investigator-github-agent model: inherit | Query GitHub API for repository state, commits, and recovery of deleted commits |
| oss-investigator-ioc-extractor-agent model: inherit | Extract IOCs from vendor security reports as forensic evidence |
| oss-investigator-local-git-agent model: inherit | Analyze cloned repositories for dangling commits and git forensics |
| oss-investigator-wayback-agent model: inherit | Recover deleted GitHub content via Wayback Machine |
| oss-report-generator-agent model: inherit | Generate final forensic report from confirmed hypothesis and evidence |
Hooks (4)
| event | matcher | runs |
|---|---|---|
| SessionStart | startup | "$CLAUDE_PROJECT_DIR/libexec/raptor-session-init" |
| Stop | * | "$CLAUDE_PROJECT_DIR/libexec/raptor-lifecycle-hook" stop |
| PostToolUseFailure | Bash | "$CLAUDE_PROJECT_DIR/libexec/raptor-lifecycle-hook" tool-failure |
| SessionEnd | * | "$CLAUDE_PROJECT_DIR/libexec/raptor-lifecycle-hook" session-end |
Slash commands (39)
/agentic/analyze/annotate/ask/audit/binary/codeql/commands/crash-analysis/create-skill/cve-diff/cve-env/describe/diagram/exploit/frida/fuzz/ghidra/openant/oss-forensics/patch/project/raptor-frida/raptor-fuzz/raptor-sca/raptor-scan/raptor-web/raptor/review/sage/sca/scan/scorecard/threat-model/tune/understand/validate/version/web
Permissions
deny (0)
—
ask (0)
—
allow (69)
Bash(libexec/raptor-agentic *)
Bash(libexec/raptor-annotate *)
Bash(libexec/raptor-audit *)
Bash(libexec/raptor-binary-study *)
Bash(libexec/raptor-binary-study-oneshot *)
Bash(libexec/raptor-bq-query *)
Bash(libexec/raptor-build-checklist *)
Bash(libexec/raptor-build-cpg-cache *)
Bash(libexec/raptor-clone-repo *)
Bash(libexec/raptor-coverage-summary *)
Bash(libexec/raptor-cve-checker *)
Bash(libexec/raptor-cve-diff *)
Bash(libexec/raptor-cve-env *)
Bash(libexec/raptor-describe *)
Bash(libexec/raptor-describe)
Bash(libexec/raptor-enrich-context-map *)
Bash(libexec/raptor-enrich-context-map-ast-view *)
Bash(libexec/raptor-enrich-context-map-callgraph *)
Bash(libexec/raptor-enrich-context-map-frida *)
Bash(libexec/raptor-enrich-context-map-imports *)
Bash(libexec/raptor-enrich-context-map-mitigation *)
Bash(libexec/raptor-enrich-context-map-observe *)
Bash(libexec/raptor-enrich-context-map-sinks *)
Bash(libexec/raptor-enrich-context-map-sites *)
Bash(libexec/raptor-enrich-context-map-taint *)
Bash(libexec/raptor-enrich-flow-trace-ast-view *)
Bash(libexec/raptor-fetch-anchor *)
Bash(libexec/raptor-fetch-attachment *)
Bash(libexec/raptor-ghidra *)
Bash(libexec/raptor-llm-ask *)
Bash(libexec/raptor-llm-scorecard *)
Bash(libexec/raptor-may-ask *)
Bash(libexec/raptor-may-ask)
Bash(libexec/raptor-normalize-context-map *)
Bash(libexec/raptor-openant *)
Bash(libexec/raptor-pick-strategies *)
Bash(libexec/raptor-project-manager *)
Bash(libexec/raptor-render-diagrams *)
Bash(libexec/raptor-resolve-mode *)
Bash(libexec/raptor-review *)
Bash(libexec/raptor-review)
Bash(libexec/raptor-run-feasibility *)
Bash(libexec/raptor-run-lifecycle *)
Bash(libexec/raptor-run-sandboxed *)
Bash(libexec/raptor-sage *)
Bash(libexec/raptor-sage)
Bash(libexec/raptor-sage-setup *)
Bash(libexec/raptor-sandbox-summary *)
Bash(libexec/raptor-sca-run *)
Bash(libexec/raptor-smt-check-null-deref *)
Bash(libexec/raptor-smt-check-oob *)
Bash(libexec/raptor-smt-check-overflow *)
Bash(libexec/raptor-smt-check-overflow-to-oob *)
Bash(libexec/raptor-smt-validate-path *)
Bash(libexec/raptor-startup-check *)
Bash(libexec/raptor-study-loop *)
Bash(libexec/raptor-study-prep *)
Bash(libexec/raptor-study-run *)
Bash(libexec/raptor-teach-recall *)
Bash(libexec/raptor-teach-store *)
Similar rigs
quisbaum-prog/occam
Occam's razor for Claude Code and Codex: a 30-line rule set. Benchmarks vs base: 51-55% lower estimated task cost on Opus/Sonnet 5.5 max with more tests passed. 8.3% fewer tokens in a Sol 6.1 max pilot. Raw data, Docker setup and comparison
Minimalist 67 tok ·
fALECX/agentic-harness-tips
Claude Code setup tips: one tip, one picture, one snippet — plus a plugin that audits your repo against the list.
Minimalist 393 tok ·
dheerajjha/show-your-work
Your coding agent says "all tests pass". Show your work. A Claude Code plugin that holds the agent's final message up against what actually ran, plus a skill for Codex, Cursor, Copilot and others.
Minimalist 421 tok ·
MasterPlayspots/motionspec
MCP server and CLI for web animation accessibility: deterministic GSAP + CSS, reduced-motion defaults and static WCAG 2.2.2/2.3.3 checks. MIT core.
Pragmatist 4.7k tok ·