Review Attack Surface — Development skill for Claude Code
Review external attack surface using Zscaler EASM findings, exposed services, and lookalike domains.
How to install Review Attack Surface
Installs to ~/.claude/skills/zscaler-zscaler-mcp-server-review-attack-surface/SKILL.md
mkdir -p ~/.claude/skills/zscaler-zscaler-mcp-server-review-attack-surface && curl -fsSL https://raw.githubusercontent.com/zscaler/zscaler-mcp-server/HEAD/commands/review-attack-surface.md -o ~/.claude/skills/zscaler-zscaler-mcp-server-review-attack-surface/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Review Attack Surface does
name: review-attack-surface disable-model-invocation: true argument-hint: "[organization_name] [focus: findings|lookalikes|all]" description: "Review external attack surface using Zscaler EASM findings, exposed services, and lookalike domains."
Review Attack Surface
Review attack surface: **$ARGUMENTS**
Step 1: List Organizations
easm_list_organizations()
```text
If an organization was specified, find its ID. Otherwise, use the primary organization.
## Step 2: Retrieve
Alternatives in Development
- MCP Builder — Guide for creating high-quality MCP servers to integrate external APIs and services 94.1k ★
- Om Standup — Morning kickoff 4.6k ★
- JWT Scan — JWT attack toolkit (offline) — alg:none forgery, RS256→HS256 algorithm confusion, weak-secret crack, static cl 4.5k ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Codeweb
Dissect a codebase into atomic nodes, wire the system web, tag domains, and surface overlap/consolidation oppo
Axguard Paths
Attack graph + vulnerability chaining (Phase 6). Chains Phase 1-5 findings into multi-hop attack paths. Usage:
/surface
View the prioritized attack surface for a target.
Engage.Recon
Execute Phase 1 - Reconnaissance and Attack Surface Mapping
Minimize
Remove unused dependencies and convert Dockerfiles to multi-stage builds to reduce attack surface
Zp Surface
Show the ranked attack surface and what it dispatches to. Usage: /zp-surface
Related Agents
Ext Attack Planner
Reasons from an external-pentest inventory to the most likely footholds in an authorized engagement. Correlate
Cloud Recon
Cloud misconfiguration scanner. Use for S3 bucket enumeration, Azure blob discovery, GCP storage checks, expos
Recon Scanner
You are a security mapping agent. Your job: map the project's exposed surface, where each access control is en