| name | onboard |
| description | Use when the user wants to set up the security-auditor plugin for the first time. |
Onboard
First-run setup for the security-auditor plugin. Verifies dependencies, creates the data directory, explains SSH requirements, and optionally scaffolds a placeholder machine.
When to use
- User is setting up the plugin for the first time
- Migrating from a previous audit system
- Verifying the plugin is ready to use
Inputs to gather
- None required, but optionally offer to scaffold a test machine afterward
Procedure
-
Check system dependencies:
for cmd in ssh scp python3; do
which "$cmd" > /dev/null || { echo "$cmd not found"; exit 1; }
done
Fail with clear instructions if any dependency is missing.
-
Resolve and create the data directory:
DATA_DIR="${CLAUDE_USER_DATA:-${XDG_DATA_HOME:-$HOME/.local/share}/claude-plugins}/security-auditor/data"
mkdir -p "$DATA_DIR/machines" "$DATA_DIR/.trash"
echo "Data directory: $DATA_DIR"
-
Explain the SSH requirement:
This plugin audits remote machines over SSH. All target machines must be reachable via SSH without password prompts. Set up SSH keys in ~/.ssh/config or your system's SSH agent before adding machines.
-
Verify ~/.ssh/config exists and is readable:
[ -r ~/.ssh/config ] && echo "SSH config found" || echo "Warning: no SSH config"
-
Offer to scaffold a placeholder test machine (optional):
Read "Would you like to add your first machine now? (y/n)"
-
Display the data directory path and confirm readiness.
Output / side effects
- Data directory created at
${CLAUDE_USER_DATA}/security-auditor/data/
- Dependencies verified
- SSH setup instructions displayed
- Optional: first machine registered if user accepts
Safety / constraints
- SSH key-based auth is required; password-based SSH will fail in automated audits.
- The user is responsible for ensuring target machines allow SSH access.
- Data directory permissions should be restricted to the user (mode 0700).