upload-agent
SAST specialist for file upload vulnerabilities (RCE via upload, path traversal, stored XSS through uploaded files). Invoke during Phase 03 Testing after…
An agent is a specialist Claude hands a whole job to, with its own tools and its own context.
200 agents across 361 plugins.
SAST specialist for file upload vulnerabilities (RCE via upload, path traversal, stored XSS through uploaded files). Invoke during Phase 03 Testing after…
SAST quality-gate specialist. Invoke in Phase 04, after at least one artifacts/findings/raw-findings.*.json exists. Merges all per-agent raw-findings files,…
Second-stage judge in the rust-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors)…
Runs one assigned rust-review cluster task and writes finding files to the run's output directory. Spawned by the rust-review skill orchestrator only.
Executes Semgrep CLI scans for a specific language category and produces SARIF output. Spawned by the semgrep skill as a parallel worker — one agent per…
SAST specialist for XSS (stored/reflected/DOM). Invoke during Phase 03 Testing after artifacts/mapping/attack-surface.json exists. Statically traces user input…
Evaluates APIs, configurations, and library interfaces for misuse resistance and footgun potential. Use when reviewing code for error-prone designs, dangerous…
Checks one documented requirement against the code that should implement it, and returns a verdict with the lines that evidence it. Writes its analysis to disk…
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic