thrunt-intel-synthesiz…
Synthesizes research outputs from parallel researcher agents into SUMMARY.md. Spawned by /hunt:new-program after 4 researcher agents complete.
An agent is a specialist Claude hands a whole job to, with its own tools and its own context.
355 agents across 675 plugins.
Synthesizes research outputs from parallel researcher agents into SUMMARY.md. Spawned by /hunt:new-program after 4 researcher agents complete.
Researches how to implement a phase before planning. Produces RESEARCH.md consumed by thrunt-hunt-planner. Spawned by /hunt:plan orchestrator.
Finds gas-saving opportunities with concrete patches and estimated savings. Use from /gas.
Governance specialist. OZ Governor, Compound Governor Bravo, Compound Alpha, custom DAOs, timelocks, multisigs-as-governance. Use when target involves voting,…
Intent-based protocol specialist — ERC-7683 (cross-chain intents), CoW Protocol, UniswapX, Across, 1inch Fusion. Use when target involves intents, solvers,…
Drives an authorized penetration test end-to-end using a recognized methodology (PTES / OWASP WSTG / NIST 800-115): scoping, recon, testing, and reporting. Use…
Runs full-scope, objectives-based red-team engagements that emulate a real threat actor's TTPs (ATT&CK) to reach an objective and test detection/response. Use…
Stands up and runs an AI governance program: use-case intake and risk-tiering, oversight and accountability, documentation discipline, and regulatory…
Domain-aware attack-surface prioritization specialist. Invoke in Phase 02, after artifacts/recon/endpoints.json and artifacts/recon/recon.json exist. Reads the…
SAST specialist for OWASP Mobile M3:2024 Insecure Authentication/Authorization. Invoke during mobile Phase 03 Testing after…
SAST specialist for OWASP Mobile M8:2024 Security Misconfiguration. Invoke during mobile Phase 03 Testing after artifacts/mapping/mobile-attack-surface.json…
Scans repo for files with dimensional arithmetic to scope discovery
Runs one c-review producing task — a location slice, the class sweep, the invariant audit or the dedup pass — reading source and writing exactly one part file.…
Analyzes one bounded Trailmark source packet and returns source-cited JSON without accessing the repository. Use only when invoked by the slicing-code-context…
Delegates to this agent when the user asks about password attacks, credential testing, hash cracking, brute force methodology, default credential checks,…
Delegates to this agent when the user wants to analyze cryptographic usage — weak algorithms or modes, key and IV/nonce management, TLS/certificate…
Delegates to this agent when the user is working on CTF challenges, capture the flag competitions, HackTheBox machines, TryHackMe rooms, or needs help with CTF…
Adversarial validator for DAST findings. Attempts to DISPROVE each finding and DOWNGRADE severity. Catches inflated reports, unverified assumptions, and…
File Upload vulnerability specialist (H1 #39). Use for testing upload restrictions, content-type bypass, extension filtering, path traversal in filenames, and…
GraphQL API security specialist. Use for introspection analysis, query complexity attacks, injection testing, authorization bypass, and batching abuse on…
Penetration-test PLANNER. Reads confirmed scope and recon results, then returns a structured deployment plan (which executors, against which surfaces, in what…
Tests for client-side JavaScript prototype pollution via URL query parameters, hash fragments, and JSON payloads. Verifies pollution by evaluating…
Tests for reflected, stored, and DOM-based XSS vulnerabilities across HTML, attribute, JavaScript, URL, and CSS contexts. Covers framework-specific sinks…
Security log analysis specialist. Parses and correlates auth.log, nginx/apache access logs, Windows Event Logs, syslog, audit logs, and cloud logs for…
Malware analysis specialist for static and dynamic analysis. Handles PE/ELF/APK binary triage, behavioral analysis, IOC extraction, YARA rule writing, C2…
Mobile application security specialist for Android and iOS. Handles APK decompilation, static/dynamic analysis, Frida instrumentation, SSL pinning bypass, ADB…
Deeply analyzes codebase for a phase and returns structured assumptions with evidence. Spawned by shape-hypothesis assumptions mode.
Researches domain ecosystem before huntmap creation. Produces files in .planning/research/ consumed during huntmap creation. Spawned by /hunt:new-program or…
Executes THRUNT plans with atomic commits, deviation handling, checkpoint protocols, and state management. Spawned by hunt-run orchestrator or execute-plan…
Identifies protocol invariants from contract code and intent, generates Foundry invariant tests with handlers. Use from /invariant and /audit-deep.
L2/rollup-risk specialist. Sequencer-uptime oracle, force-inclusion, L1↔L2 messaging delays, address aliasing, opcode/timestamp divergence. Use when the target…
Lending-protocol specialist. Aave V3, Compound V3, Morpho, Silo, Euler, custom lending. Use when the target is a lending pool, isolated market, or liquidation…
Use this agent for a dedicated secure-coding review of Python or React/JS code — flagging outdated/vulnerable functions with concrete safe alternatives,…
Conducts security investigations and analytical deep-dives — correlates telemetry across sources, enriches with threat intel, reconstructs timelines, scopes…
Designs and reviews system security architecture end to end — secure-by-design, trust boundaries, threat modeling, control selection, and security…
SAST specialist for OWASP Mobile M10:2024 Insufficient Cryptography. Invoke during mobile Phase 03 Testing after artifacts/mapping/mobile-attack-surface.json…
Attack-surface prioritization specialist for mobile apps. Invoke in Phase 02 of the mobile pipeline, after artifacts/recon/mobile-recon.json exists. Reads…
SAST specialist for OWASP Mobile M5:2024 Insecure Communication. Invoke during mobile Phase 03 Testing after artifacts/mapping/mobile-attack-surface.json…
Analyzes data flow from source to vulnerability sink, mapping trust boundaries, API contracts, environment protections, and cross-references. Spawned by…
Adds dimensional annotations to source code at anchor points using Reserve Protocol's format
Discovers dimensional vocabulary for codebases by analyzing naming conventions and protocol patterns
Delegates to this agent when the user wants to test exfiltration and DLP/egress controls during an authorized engagement — DNS tunneling, HTTPS/cloud-storage…
Delegates to this agent when the user wants database-specific offensive testing on an authorized target — SQL and NoSQL injection depth, authenticated database…
Delegates to this agent when the user asks about detection rules, SIEM queries, threat hunting, indicator analysis, log analysis, blue team detection for…
IDOR / BOLA specialist (H1 #55, OWASP API1:2023). Use for testing insecure direct object references and broken object level authorization across web apps,…
Information Disclosure specialist (H1 #18, CWE-200/209/215/538/668/798). Use for finding exposed sensitive data: stack traces, debug endpoints, config files,…
JavaScript static analysis agent for client-side security review. Use for analyzing JS bundles, finding hardcoded secrets, tracing DOM XSS source-sink flows,…
Network penetration testing specialist for ARP attacks, MitM, packet capture, SNMP enumeration, SMB relay, Responder credential capture, and network-level…
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic