osint
Open source intelligence specialist for passive reconnaissance. Handles domain intelligence, certificate transparency, Shodan enumeration, email harvesting,…
An agent is a specialist Claude hands a whole job to, with its own tools and its own context.
355 agents across 675 plugins.
Open source intelligence specialist for passive reconnaissance. Handles domain intelligence, certificate transparency, Shodan enumeration, email harvesting,…
Password cracking and credential attack specialist. Use when working with password hashes, hash cracking, wordlist attacks, credential analysis, or password…
Retroactive 6-pillar visual audit of implemented frontend code. Produces scored UI-REVIEW.md. Spawned by /thrunt:ui-review orchestrator.
Validates UI-SPEC.md design contracts against 6 quality dimensions. Produces BLOCK/FLAG/PASS verdicts. Spawned by /thrunt:ui-phase orchestrator.
Produces UI-SPEC.md design contract for frontend phases. Reads upstream artifacts, detects design system state, asks only unanswered questions. Spawned by…
NFT specialist — ERC-721, ERC-1155, royalties (ERC-2981, EIP-7585), metadata mutability, mint mechanics, marketplaces. Use when target is an NFT contract or…
Writes patches that fix specific findings. Validates via forge build + test. Use from /remediate.
Writes the final audit report (Markdown + HTML + JSON) from raw findings. Used by /report. Produces polished prose without consuming main context.
Builds security in and hardens systems across code, cloud, and infrastructure — DevSecOps, secure CI/CD pipelines, control implementation, automation, and…
Works a SOC alert queue and runs tiered monitoring/triage: validates, enriches, scopes, and decides escalate vs. close consistently, escalating real incidents…
SAST reconnaissance specialist for mobile apps (Android/iOS). Invoke first in the mobile pipeline, once artifacts/recon/scope.json exists and…
SAST specialist for OWASP Mobile M9:2024 Insecure Data Storage. Invoke during mobile Phase 03 Testing after artifacts/mapping/mobile-attack-surface.json…
SAST specialist for OWASP Mobile M4:2024 Insufficient Input/Output Validation (WebView XSS, local SQLi, deep-link/IPC injection). Invoke during mobile Phase 03…
Propagates dimensional annotations through arithmetic and call chains, reporting mismatches found during propagation
Validates dimensional consistency and detects dimensional bugs in annotated code
Draw the 12 Houses of the Zodiac Tarot spread and return a concise structured reading. Use as a named agent instead of wrapping Skill(let-fate-decide) in an…
Delegates to this agent when the user needs to plan a penetration test, define attack methodology, scope an engagement, map techniques to MITRE ATT&CK, or…
Delegates to this agent when the user wants to test defensive evasion during an authorized red team or EDR-validation engagement — AV/EDR evasion, AMSI and ETW…
Delegates to this agent when the user wants to automatically chain isolated vulnerabilities into multi-step attack paths, pivot through a system from a…
LLM and Agentic AI vulnerability specialist. Covers OWASP LLM Top 10 v2025 (LLM01-LLM10) and OWASP Agentic AI Top 10 (AA-01..AA-10). Dispatcher passes subtype…
Continuous monitoring agent for authorized bug bounty programs. Modes: 'baseline' captures initial state, 'check' detects changes, 'scope' re-syncs platform…
Custom nuclei template builder. Use when you've found a pattern that should be checked across multiple targets or when existing templates miss a specific…
Post-exploitation specialist for privilege escalation, lateral movement, persistence, and credential harvesting. Use after obtaining initial shell access.…
Reconnaissance and enumeration specialist. Use when scanning, enumerating ports, fingerprinting services, discovering subdomains, running nuclei vulnerability…
Penetration test report writing specialist. Consolidates evidence from all evidence/ directories into professional reports with CVSS scoring, executive…
Restaking and AVS specialist — EigenLayer, Symbiotic, Karak, Babylon, AVS implementations, operator slashing. Use when target involves restaking deposits,…
Staking-protocol specialist. Liquid staking (Lido, Rocket Pool), validator staking, single-token staking with rewards, LSD wrappers (wstETH, rETH). Use when…
Vyper-language specialist. Compiler-version bugs, decorator semantics, raw_call/create_from_blueprint, no-inheritance auth. Use when any contract is written in…
Proof-of-concept documentation specialist, shared by the web and mobile pipelines. Invoke in Phase 05, after artifacts/findings/validated-findings.json has at…
SAST specialist for OWASP Mobile M6:2024 Inadequate Privacy Controls, scoped to Medium-Critical impact only. Invoke during mobile Phase 03 Testing as a…
SAST reconnaissance specialist. Invoke first in the vantage pipeline, before any other testing agent, once artifacts/recon/scope.json exists. Statically parses…
Verifies whether a suspected vulnerability is actually exploitable by proving attacker control, mathematical bounds, and race condition feasibility. Spawned by…
Applies fixes for the blocking findings dispatched by the /code-improver:improve workflow and returns one verdict per finding (fixed, rejected, or deferred)…
Analyzes one function in depth for audit context: invariants, assumptions, and what its callees establish. Writes the prose analysis to disk and returns a…
Delegates to this agent when the user asks about exploitation techniques, attack methodologies, tool configurations for authorized testing, post-exploitation…
Delegates to this agent when the user wants to retest a vulnerability after a fix has been deployed, prove that a remediation actually closed the issue, verify…
Delegates to this agent when the user asks about digital forensics, incident response, evidence acquisition, memory forensics, disk forensics, network…
OAuth 2.0 / 2.1, OpenID Connect (OIDC), SAML SSO, and JWT specialist. Dispatcher passes subtype — 'oauth', 'oidc', 'saml', or 'jwt' — in the task; falls back…
Open Redirect specialist (H1 #38). Use for testing URL redirect parameters, login/logout flows, OAuth callbacks, and any endpoint that redirects based on user…
Bug bounty PoC and report builder. Use after confirming a vulnerability to create minimal reproduction steps, self-contained HTML demonstration pages,…
Binary reverse engineering and exploit development specialist. Handles static analysis with Ghidra/Radare2, dynamic analysis with GDB/strace, shellcode…
Social engineering and phishing simulation specialist. Handles GoPhish campaign setup, spear-phishing email crafting, evilginx2 adversary-in-the-middle…
Proactive threat hunting specialist using ATT&CK-based hypotheses. Hunts for lateral movement, persistence, credential dumping, C2 beaconing, data…
Yield aggregator and ERC-4626 specialist. Yearn V3, Beefy, Sommelier, MetaMorpho, custom vaults with strategies. Use when target is an ERC-4626 vault or…
ZK proof-verifier contract specialist. Groth16/PLONK/Halo2 on-chain verifiers, public-input binding, pairing-precompile misuse, field-range checks, nullifier…
Final report assembly specialist. Invoke in Phase 06, once artifacts/findings/validated-findings.json exists (PoCs if any). Synthesizes validated findings,…
SAST specialist for hardcoded secrets and cryptographic failures (API keys/credentials in source, weak crypto on sensitive data), scoped to Medium-Critical…
SAST specialist for SQL/NoSQL injection. Invoke during Phase 03 Testing after artifacts/mapping/attack-surface.json exists. Statically traces user input into…
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic