exploit-poc-writer
Writes Foundry test files that prove an exploit. The test MUST compile and pass. Use from /exploit, /exploit-chain, /exploit-live.
An agent is a specialist Claude hands a whole job to, with its own tools and its own context.
200 agents across 361 plugins.
Writes Foundry test files that prove an exploit. The test MUST compile and pass. Use from /exploit, /exploit-chain, /exploit-live.
When Claude should delegate to this agent. Describe the end-to-end task it owns (e.g. "Run a full LLM security assessment of a feature, from threat model to…
Runs governance, risk & compliance work — framework gap-assessments (SOC 2 / ISO 27001 / PCI / HIPAA / GDPR / NIST), security risk assessment and the risk…
Senior AI security reviewer for an end-to-end assessment of an LLM / RAG / agentic feature — from threat model through OWASP LLM Top 10 and prompt-injection…
SAST specialist for vulnerable dependencies (SCA against known CVEs), scoped to Medium-Critical impact only. Invoke during Phase 03 Testing as a repo-wide task…
Applies code-level remediation for a validated SAST finding (web or mobile). Invoked explicitly by /vantage:fix-issue <finding-id> (one finding), /vantage:fix…
SAST specialist for server-side injection (command injection, SSTI, SSRF, path traversal, XXE, LDAP injection), scoped to Medium-Critical impact only. Invoke…
Verifies that each zeroize-audit PoC actually proves the vulnerability it claims to demonstrate. Reads PoC source code, finding details, and original source to…
Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test…
Models attacker perspectives and builds exploit scenarios for HIGH RISK code changes. Use when differential review identifies high-risk changes that need…
Synthesizes outputs from all four mapping agents (software-catalog, directory-scanner, api-discovery, javascript-mapper) into a unified attack surface report.…
On-demand PayloadsAllTheThings fetcher. Use when a pentest agent needs full payloads not in local payloads/ files. Input: PATT category name (see URL Map).…
Executes specific vulnerability tests. Follows 4-phase workflow (Recon → Experiment → Test → Verify), generates PoCs, captures evidence. Specialized by attack…
Antivirus and EDR evasion specialist for authorized red team engagements. Handles AMSI bypass, payload obfuscation, living-off-the-land techniques, sandbox…
Exploitation specialist for gaining initial access. Use when exploiting CVEs, running Metasploit modules, using searchsploit, obtaining shells, or executing…
IoT and embedded systems security specialist. Handles firmware extraction and analysis, hardcoded credential discovery, UART/JTAG access, MQTT/CoAP protocol…
Researches a single gray area decision and returns a structured comparison table with rationale. Spawned by shape-hypothesis advisor mode.
Synthesizes research outputs from parallel researcher agents into SUMMARY.md. Spawned by /hunt:new-program after 4 researcher agents complete.
Researches how to implement a phase before planning. Produces RESEARCH.md consumed by thrunt-hunt-planner. Spawned by /hunt:plan orchestrator.
Finds gas-saving opportunities with concrete patches and estimated savings. Use from /gas.
Governance specialist. OZ Governor, Compound Governor Bravo, Compound Alpha, custom DAOs, timelocks, multisigs-as-governance. Use when target involves voting,…
Intent-based protocol specialist — ERC-7683 (cross-chain intents), CoW Protocol, UniswapX, Across, 1inch Fusion. Use when target involves intents, solvers,…
Drives an authorized penetration test end-to-end using a recognized methodology (PTES / OWASP WSTG / NIST 800-115): scoping, recon, testing, and reporting. Use…
Runs full-scope, objectives-based red-team engagements that emulate a real threat actor's TTPs (ATT&CK) to reach an objective and test detection/response. Use…
Stands up and runs an AI governance program: use-case intake and risk-tiering, oversight and accountability, documentation discipline, and regulatory…
Domain-aware attack-surface prioritization specialist. Invoke in Phase 02, after artifacts/recon/endpoints.json and artifacts/recon/recon.json exist. Reads the…
SAST specialist for OWASP Mobile M3:2024 Insecure Authentication/Authorization. Invoke during mobile Phase 03 Testing after…
SAST specialist for OWASP Mobile M8:2024 Security Misconfiguration. Invoke during mobile Phase 03 Testing after artifacts/mapping/mobile-attack-surface.json…
Scans repo for files with dimensional arithmetic to scope discovery
Deduplication judge for the c-review pipeline. Merges duplicate findings deterministically by exact location and bug class, then runs LLM passes over…
Second-stage judge in the c-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors)…
Penetration-test PLANNER. Reads confirmed scope and recon results, then returns a structured deployment plan (which executors, against which surfaces, in what…
Tests for client-side JavaScript prototype pollution via URL query parameters, hash fragments, and JSON payloads. Verifies pollution by evaluating…
Tests for reflected, stored, and DOM-based XSS vulnerabilities across HTML, attribute, JavaScript, URL, and CSS contexts. Covers framework-specific sinks…
Security log analysis specialist. Parses and correlates auth.log, nginx/apache access logs, Windows Event Logs, syslog, audit logs, and cloud logs for…
Malware analysis specialist for static and dynamic analysis. Handles PE/ELF/APK binary triage, behavioral analysis, IOC extraction, YARA rule writing, C2…
Mobile application security specialist for Android and iOS. Handles APK decompilation, static/dynamic analysis, Frida instrumentation, SSL pinning bypass, ADB…
Deeply analyzes codebase for a phase and returns structured assumptions with evidence. Spawned by shape-hypothesis assumptions mode.
Researches domain ecosystem before huntmap creation. Produces files in .planning/research/ consumed during huntmap creation. Spawned by /hunt:new-program or…
Executes THRUNT plans with atomic commits, deviation handling, checkpoint protocols, and state management. Spawned by hunt-run orchestrator or execute-plan…
Identifies protocol invariants from contract code and intent, generates Foundry invariant tests with handlers. Use from /invariant and /audit-deep.
L2/rollup-risk specialist. Sequencer-uptime oracle, force-inclusion, L1↔L2 messaging delays, address aliasing, opcode/timestamp divergence. Use when the target…
Lending-protocol specialist. Aave V3, Compound V3, Morpho, Silo, Euler, custom lending. Use when the target is a lending pool, isolated market, or liquidation…
Use this agent for a dedicated secure-coding review of Python or React/JS code — flagging outdated/vulnerable functions with concrete safe alternatives,…
Conducts security investigations and analytical deep-dives — correlates telemetry across sources, enriches with threat intel, reconstructs timelines, scopes…
Designs and reviews system security architecture end to end — secure-by-design, trust boundaries, threat modeling, control selection, and security…
SAST specialist for OWASP Mobile M10:2024 Insufficient Cryptography. Invoke during mobile Phase 03 Testing after artifacts/mapping/mobile-attack-surface.json…
Attack-surface prioritization specialist for mobile apps. Invoke in Phase 02 of the mobile pipeline, after artifacts/recon/mobile-recon.json exists. Reads…
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic