AI Skill for Balam
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
|
||
| .claude-plugin | ||
| .forgejo/workflows | ||
| skills/balam | ||
| .gitignore | ||
| CHANGELOG.md | ||
| LICENSE | ||
| README.md | ||
balam-skill
A Claude Code skill that connects to Balam
(a self-hosted, DefectDojo-style vulnerability-management system) through its
MCP server, balam-mcp.
It drives day-to-day vulnerability-management work directly from Claude Code:
- Triaging and updating findings
- Importing/uploading scan reports (Nessus, OJO, or other scanners)
- Managing product types, products, engagements, and tests
- Creating risk acceptances
- Checking dashboards, metrics, and risk registers
Installation
Add this repository as a Claude Code plugin marketplace, then install the
balam-skill plugin from it. See .claude-plugin/marketplace.json for the
marketplace definition.
Requirements
- A running Balam instance
BALAM_URLandBALAM_TOKENset in the environment (seeskills/balam/SKILL.mdfor how the skill checks for and registers these)uvx, or a local checkout ofbalam-mcpas a fallback
Repository layout
skills/balam/SKILL.md - the skill itself
skills/balam/evals/ - eval prompts for testing the skill's behavior
.claude-plugin/ - plugin and marketplace manifests
.forgejo/workflows/ - CI (security scanning of this repo)
License
GPL-2.0-only. See LICENSE.