Run authorized security research pipelines in Claude Code with RAPTOR
RAPTOR turns Claude Code into an evidence-first offensive and defensive security research workflow for mapping attack surfaces, validating scanner findings, analyzing binaries, generating patches, and tracking project findings.
npx skills add agentskillexchange/skills --skill run-authorized-security-research-pipelines-in-claude-code-with-raptor
Use RAPTOR when an authorized security operator needs a repeatable Claude Code workflow for repository or binary security research. The upstream project provides Claude Code commands such as /agentic, /scan, /understand, /binary, /validate, /codeql, /sca, /exploit, /patch, /fuzz, and /project, chaining Semgrep, CodeQL, binary analysis, vulnerability validation, exploitability checks, and patch generation into project-owned findings.
What this skill actually does
This is skill-shaped because the operator job is specific and bounded: run controlled, evidence-backed security analysis against systems the operator is authorized to test, then preserve findings, proofs, and patches. Invoke it for security audits, dependency risk review, binary triage, validation of scanner output, or patch planning inside Claude Code. It is not a generic security platform, vulnerability database, penetration-testing endorsement, or unrestricted exploit toolkit listing.
Inputs and prerequisites: Claude Code, Python dependencies from the repository, Semgrep, CodeQL for relevant scans, optional Docker devcontainer or privileged container for rr/debugger-backed binary workflows, and authorization to test the target codebase or artifact..
Setup notes: Clone the repository with git clone https://github.com/gadievron/raptor.git , install Python dependencies with pip install -r requirements.txt , install Claude Code with npm install -g @anthropic-ai/claude-code or the documented local package install, and install Semgrep with pip install semgrep . Open Claude Code from the RAPTOR checkout and use the documented slash commands. For the recommended container path, use the upstream devcontainer or Docker image and mount the authorized target workspace.
Source and verification boundary: use https://github.com/gadievron/raptor as the canonical reference before running the workflow; keep commands, API calls, CLI usage, and generated outputs reviewable against that upstream source.
Framework fit: publish this as a Claude Code workflow only when the operator can invoke the documented toolchain directly, rather than treating the upstream project as a generic product listing.