verify
Run a deterministic one-shot secret scan over the current working tree (staged + unstaged + untracked). Use to confirm "is the current state safe to commit?"…
A command is the one you type. It runs exactly when you ask it to, and never before.
426 commands across 357 plugins.
Run a deterministic one-shot secret scan over the current working tree (staged + unstaged + untracked). Use to confirm "is the current state safe to commit?"…
Launch the AKA web dashboard in your browser (reads your local store)
List installed AKA detection packs, versions, and available updates
Full security audit of a Solidity/Vyper/Rust contract or directory. Runs the entire vuln-skills library and dispatches DeFi specialist subagents based on…
Audit only the git diff vs main (or specified base). Optimized for PR review.
Deep audit — same as /audit but spawns more parallel subagents, runs multi-pass review, and chases exploit chains across files.
Run a compliance gap-assessment for a framework, tie gaps to risk, and produce findings + remediation.
Build a board/executive security brief — strategy, quantified risk, and a board-ready deck.
Run a threat-informed defense cycle for a technique or threat — coverage check, hunt, detection, and purple-team validation.
Open the subscribetome dashboard to view and manage API keys and subscriptions
Scan .env files for existing API keys to import into subscribetome
Show the subscribetome inventory — API keys, subscriptions, and monthly spend
Apply code-level fixes for ALL validated findings, one at a time — modifies the target repository's source code
Apply a code-level fix for a finding from /vantage:scan-diff's commit/PR/MR scan — modifies the target repository's source code
Apply a code-level fix for one validated finding by id (e.g. F-001) — modifies the target repository's source code
Performs security-focused differential review of code changes
Identifies state-changing entry points in smart contracts
Create an editable draw.io grc audit workflow diagram for GRC professionals
Connect to a Metasploit-Kali Server (MKS) REST API — verifies connectivity, discovers available Kali tools, and configures agents to prefer MKS endpoints over…
Define or update engagement scope — saves scope to disk without launching a pentest. Can be run before or during an engagement. If a pentest is active and the…
Incident response workflow — triage, evidence collection, timeline, and IOC extraction
Post-exploitation workflow after getting shell access — privesc, credential harvest, lateral movement
Generate a professional penetration test report from all evidence files
Query the Android/AOSP kernel CVE database by CVE id, version, build date, or branch
Deep scan of Windows Registry for malware persistence and unauthorized modifications
Scan file system for suspicious files in common malware locations
Full CVE hunting pipeline. Usage: /hunt <package-name>. Orchestrates all agents: registry check, clone, code review, PoC build, validation, and report…
Find targets in a category. Usage: /recon <category>. Examples: /recon csv-parsers, /recon template-engines, /recon archive-libs.
Query or update the research registry. Usage: /registry [query]. Examples: /registry stats, /registry check lodash, /registry list in-progress.
Capture idea or task as todo from current conversation context
Cross-phase audit of all outstanding Evidence Review and findings validation items
Audit milestone completion against original intent before archiving
Define and authorize the target scope for a penetration testing engagement. This is the **mandatory first step** — all other commands refuse to run without an…
Display the engagement progress dashboard. Read-only — does not modify any state files.
Run the 6-gate strict quality gate on unvalidated findings.
[stable] End-to-end security audit with hotspot-aware framework pivots, shared findings.json schema, and CI-friendly workflow flags
[beta] Audit a decompiled Android target — scans jadx_out/sources + apktool_out together and merges findings
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic