Collect CrowdStrike Falcon endpoint posture and write Finding documents to:
How this command is triggered — by the user, by Claude, or both
Slash command
/crowdstrike-inspector:collectThe summary Claude sees in its command listing — used to decide when to auto-load this command
# /crowdstrike-inspector:collect Collect CrowdStrike Falcon endpoint posture and write Finding documents to: Coverage: - Sensor coverage and stale/offline hosts - Detection policy visibility - Prevention policy visibility - Host-group scoping visibility Options: - `--output=summary|json|silent` - `--quiet` - `--limit=<n>` host ID cap for the first release. Default: `100`
Collect CrowdStrike Falcon endpoint posture and write Finding documents to:
~/.cache/claude-grc/findings/crowdstrike-inspector/<run_id>.json
Coverage:
Options:
--output=summary|json|silent--quiet--limit=<n> host ID cap for the first release. Default: 100npx claudepluginhub mrcodechef/claude-grc-engineering --plugin crowdstrike-inspector6plugins reuse this command
First indexed Jul 18, 2026
/collectScans GitHub repositories in a specified scope for SCF compliance controls like branch protection, secret scanning, and Dependabot, emitting JSON findings per repository.
/collectScans AWS for compliance issues across IAM, S3, CloudTrail, EBS; emits JSON findings with SCF checks and severities.
/collectScans GCP project for compliance configs in IAM, Cloud Storage, audit logs, KMS, Compute; emits JSON findings to cache and stdout summary.
/collectScans Okta org for authentication policies, MFA enrollment, password policy, session settings, admin users, and logs. Emits schema-conformant security findings.
/collectCollects URLs, text notes, or file paths into PARA-classified knowledge storage. Use --search "query" to find existing collections.