All projects
2026 Author
White Rabbit
Server audits with Claude Code
I wrote White Rabbit for one-off server audits. The plugin collects SSH settings, open ports, authentication logs, web logs, and OS package versions. Scripts and Claude Code use that data to produce a report with findings, supporting evidence, and suggested checks.
Collection uses standard system tools over SSH, with no agent to install on the server. A PreToolUse hook checks Bash commands against a read-only policy during the audit. Fixes are suggested for manual execution. The hook uses rules and patterns; it does not replace a sandbox or SSH user permission restrictions.
Features
- Separate server, SSH log, web log, and CVE checks, or a full audit with /wr all
- SSH data collection using ss, journalctl, and other system tools
- A hook that blocks commands outside the policy and blocks execution if policy checks fail
- OS package CVEs from OSV.dev, prioritized using CISA KEV and EPSS; reports include findings with available fixes
- IP address correlation across SSH and web logs for further investigation
- Comparison with the previous audit: new, unchanged, and resolved findings
- Behavioral tests for collectors, analyzers, and the hook using prepared fixtures
Technologies
Claude Code Bash SSH bats