Spray — Security skill for Claude Code
Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log.
How to install Spray
Installs to ~/.claude/commands/m1rr0r199501-agent-pentest-framework-spray.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/m1rr0r199501/agent-pentest-framework/HEAD/.claude/commands/spray.md -o ~/.claude/commands/m1rr0r199501-agent-pentest-framework-spray.md Restart Claude Code, or start a new session, for it to be picked up.
What Spray does
description: Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 + okta (via TREVORspray). Default delay 30min/round + 60s jitter. Usage /spray --mode --users --passes
/spray
Live credential spray against an authentication endpoint. **The most dangerous tool in this plugin.** Read the guards section before using.
Modes
| Mode | Use case | Engine |
Alternatives in Security
- Promptmap — Security scanner for custom LLM apps 1.2k ★
- Maestro Odyssey — Long-running iterative cycle — one entry, seven modes (debug improve planex review security defensive ui) 530 ★
- OpenTag — Open-source, channel-native agent gateway for Slack 499 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Auth Security UX Specialist
Use when a login or security flow feels either unsafe or full of friction. Signup, password reset, 2FA and pas
Agentlinter
ESLint for AI Agents — AGENTS.md/CLAUDE.md 채점·진단·자동수정 Position Risk Warning · Token Efficiency · Security Chec
API Contract Review
API platform contract review. Invokes api-platform-reviewer to audit rate-limit design, OAuth scope hygiene, w
Chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common ch
Spec Audit
Spec-vs-code compliance audit — extracts requirements from a spec / whitepaper / RFC and matches each to the i
Meta Audit
You are now the meta-audit coordinator. The user just typed /meta-audit. Your sole responsibility is to spawn
Related Agents
Auth Tester
Authentication and session management testing agent. Use for login bypass, session fixation, password reset fl
Password Spray Agent
Auth Guard
Read-only reviewer for JWT login, password hashing, and /auth routes in this tracker. Use when the user asks t