All projects
2026 Author

White Rabbit

Server audits with Claude Code

I wrote White Rabbit for one-off server audits. The plugin collects SSH settings, open ports, authentication logs, web logs, and OS package versions. Scripts and Claude Code use that data to produce a report with findings, supporting evidence, and suggested checks.

Collection uses standard system tools over SSH, with no agent to install on the server. A PreToolUse hook checks Bash commands against a read-only policy during the audit. Fixes are suggested for manual execution. The hook uses rules and patterns; it does not replace a sandbox or SSH user permission restrictions.

Features

  • Separate server, SSH log, web log, and CVE checks, or a full audit with /wr all
  • SSH data collection using ss, journalctl, and other system tools
  • A hook that blocks commands outside the policy and blocks execution if policy checks fail
  • OS package CVEs from OSV.dev, prioritized using CISA KEV and EPSS; reports include findings with available fixes
  • IP address correlation across SSH and web logs for further investigation
  • Comparison with the previous audit: new, unchanged, and resolved findings
  • Behavioral tests for collectors, analyzers, and the hook using prepared fixtures

Technologies

Claude Code Bash SSH bats