Comment SECURITY

Security Claude Code Toolkit

For security engineers, DevSecOps teams, and security-forward engineering orgs. Finds what pattern-matching misses.

500+high-severity vulnerabilities found that survived decades of prior scrutiny
97%reduction in time critical vulnerabilities remain open — Cogent
25–50%productivity gains across DevSecOps workflows — GitLab

Pattern-matching finds known threats. Logic flaws and cross-file data flows need reasoning.

Static analysis tools are trained to catch what they've already seen. They miss logic errors that span multiple files, exploitability chains that depend on runtime context, and novel attack vectors that don't match existing patterns. These are the vulnerabilities that survive for years.

Claude reads code the way a security researcher does — following the logic, not just the patterns. 'Claude consistently performed above expectations, finding issues that weren't caught by existing tools.' — Anthropic research on automated vulnerability discovery across production codebases.

"500+ high-severity vulnerabilities found that survived decades of prior scrutiny — by reasoning through logic, not matching patterns."

Anthropic research — automated vulnerability discovery

Security workflows that eat engineering hours.

Connected to GitHub, Sentry, Semgrep, and your security toolchain.

/vuln-scan [codebase]High impact

Identifies logic flaws and cross-file data flow issues that pattern-matching misses. Works across entire codebases, not line-by-line.

/pr-security [pr-url]High impact

Reviews pull requests for security vulnerabilities, logic errors, and edge cases that automated tools skip. Categorised by type and severity.

/threat-intel [ioc]High impact

Enriches indicators of compromise, queries intelligence sources, maps behaviors to ATT&CK techniques, flags connections between indicators.

/patch-draft [vulnerability]Medium impact

Drafts context-aware patches with full explanation of the fix. Opens PR for team review — no manual patching from scratch.

/incident-brief [alert]Medium impact

Structures security incident for triage: impact, root cause, immediate actions, timeline. From alert to brief in under 2 minutes.

/compliance-audit [control]Medium impact

Reviews codebase against specified compliance control. Identifies gaps, maps evidence, outputs audit-ready control matrix.

Copy into Claude, replace the brackets.

These work in regular Claude.ai today — paste code directly to test them.

Vulnerability ScanReview this codebase for security vulnerabilities. Focus on: SQL injection, authentication bypass, privilege escalation, and cross-service data leakage. For each finding, explain the full exploit path and provide a specific remediation. Flag by severity: Critical / High / Medium.

Works across entire codebases, not line-by-line. Paste code or connect GitHub via MCP for full-repo analysis.

PR Security ReviewReview this pull request for security issues. Check for: input validation gaps, authentication changes, authorization logic errors, cryptographic misuse, and new dependency vulnerabilities. Post findings categorized by type, each with severity and suggested fix.

Connect GitHub via MCP and this runs automatically on every PR — no manual trigger needed.

Threat IntelligenceI have these indicators of compromise: [IPs / domains / hashes]. For each one: enrich with available intelligence, identify related infrastructure patterns, map to ATT&CK techniques where applicable, and flag any connections between indicators. Output as a structured threat report.

Run this on any incident alert. Replaces 3–4 hours of manual pivot work.

Compliance Gap AnalysisReview this codebase against SOC 2 Type II CC6 (logical access) requirements. For each control: state whether we meet it, what evidence supports that, and what gaps remain. Output as a control matrix I can include in an audit package.

Adapts to PCI-DSS, ISO 27001, DPDP, and HIPAA — just change the standard in the prompt.

People don't Google your security product anymore. They ask Claude.

Security has 3 connectors listed on Claude's directory right now. Near-empty for a sector this size. If you're building a security product — SIEM, DAST/SAST tooling, threat intelligence, vulnerability management — the window to be the default recommendation when security teams ask Claude for tools in your category is open right now.

Copy this — send it to any security tool you use that isn't listed yet
Subject: [Product] + Claude — your category is still open

Hi [Company] team,

I use [Product] in our security workflow. I also use Claude for
threat research, code review, and incident triage.

Every investigation involves switching between them. A Claude MCP
connector would let me query [Product] directly from Claude —
no context switch, no copy-paste, faster investigations.

Security has 3 connectors listed on Claude's directory right now.
Your category is near-empty. That won't last.

The team that builds these: architeqt.ai

Thought you'd want to know before a competitor moves.
— [Your name]
Rishi Bajpai — Architeqt AI
The setup that changes the week

30 minutes to configure. Results visible in week one.

Get the security toolkit

For security-forward engineering teams.

I'll send you the full toolkit — CLAUDE.md template, connector configuration, prompt library, and the slash command implementation guide.

Building a security product?

Security has 3 connectors on Claude's directory. Near-empty. If your product handles threat data, vulnerability management, or security automation, your category may still be open.

Book a free callcal.com/buildwithrishi/architeqt