Skill Detail

Run authorized security research pipelines in Claude Code with RAPTOR

RAPTOR turns Claude Code into an evidence-first offensive and defensive security research workflow for mapping attack surfaces, validating scanner findings, analyzing binaries, generating patches, and tracking project findings.

Security & VerificationClaude Code
Security & Verification Claude Code Security Reviewed
⭐ 3.3k GitHub stars
COPY SKILL INSTRUCTIONS (OPTIONAL)
npx skills add agentskillexchange/skills --skill run-authorized-security-research-pipelines-in-claude-code-with-raptor Copy
Uses the third-party skills CLI, not an ASE-owned installer. Check your agent’s compatibility. This copies instructions; complete the upstream tool setup below separately.
At a glance
Tools required
Claude Code, Python dependencies from the repository, Semgrep, CodeQL for relevant scans, optional Docker devcontainer or privileged container for rr/debugger-backed binary workflows, and authorization to test the target codebase or artifact.
Install & setup
Clone the repository with git clone https://github.com/gadievron/raptor.git, install Python dependencies with pip install -r requirements.txt, install Claude Code with npm install -g @anthropic-ai/claude-code or the documented local package install, and install Semgrep with pip install semgrep. Open Claude Code from the RAPTOR checkout and use the documented slash commands. For the recommended container path, use the upstream devcontainer or Docker image and mount the authorized target workspace.
Author
Gadi Evron, Daniel Cuthbert, Thomas Dullien, Michael Bargury, and John Cartwright
Publisher
Individuals
Last updated
Jul 18, 2026
Quick brief

Use RAPTOR when an authorized security operator needs a repeatable Claude Code workflow for repository or binary security research. The upstream project provides Claude Code commands such as /agentic, /scan, /understand, /binary, /validate, /codeql, /sca, /exploit, /patch, /fuzz, and /project, chaining Semgrep, CodeQL, binary analysis, vulnerability validation, exploitability checks, and patch generation into project-owned findings.

How it works

What this skill actually does

This is skill-shaped because the operator job is specific and bounded: run controlled, evidence-backed security analysis against systems the operator is authorized to test, then preserve findings, proofs, and patches. Invoke it for security audits, dependency risk review, binary triage, validation of scanner output, or patch planning inside Claude Code. It is not a generic security platform, vulnerability database, penetration-testing endorsement, or unrestricted exploit toolkit listing.

Inputs and prerequisites: Claude Code, Python dependencies from the repository, Semgrep, CodeQL for relevant scans, optional Docker devcontainer or privileged container for rr/debugger-backed binary workflows, and authorization to test the target codebase or artifact..

Setup notes: Clone the repository with git clone https://github.com/gadievron/raptor.git , install Python dependencies with pip install -r requirements.txt , install Claude Code with npm install -g @anthropic-ai/claude-code or the documented local package install, and install Semgrep with pip install semgrep . Open Claude Code from the RAPTOR checkout and use the documented slash commands. For the recommended container path, use the upstream devcontainer or Docker image and mount the authorized target workspace.

Source and verification boundary: use https://github.com/gadievron/raptor as the canonical reference before running the workflow; keep commands, API calls, CLI usage, and generated outputs reviewable against that upstream source.

Framework fit: publish this as a Claude Code workflow only when the operator can invoke the documented toolchain directly, rather than treating the upstream project as a generic product listing.