mutate
[experimental] Security mutation testing -- weaken security controls and check if the scanner detects the resulting vulnerability
A command is the one you type. It runs exactly when you ask it to, and never before.
426 commands across 357 plugins.
[experimental] Security mutation testing -- weaken security controls and check if the scanner detects the resulting vulnerability
List active AKA detection exceptions (masked) from the local store
Audit third-party dependencies — resolve installed versions, cross-reference known-vulnerable releases, and flag vendored code that has diverged from upstream.
Diff two Rugproof audit reports (before vs after) to track regressions — what's new, what's fixed, and whether the grade moved.
Pull past public audits (Code4rena, Sherlock, Spearbit, etc.) for a deployed contract or known protocol.
Run a secure-by-design architecture review — threat model, trust boundaries, control selection, and a documented verdict.
Run an authorized penetration test end-to-end, chaining recon, testing, and reporting skills into one flow.
Run a build-and-harden pass across code, pipeline, cloud, and infra, then track remediation.
Scan only the changed files in a single commit or PR/MR for newly introduced vulnerabilities (fast incremental check, not a full pipeline run)
Run the full mobile SAST pipeline (phases 01-06) against this repository — Android, iOS, React Native, or Flutter
Run the full web SAST pipeline (phases 01-06) against this repository
Iteratively reviews and fixes a Claude Code skill until it meets quality standards. Triggers on 'fix my skill', 'improve skill quality', 'skill improvement…
Week-over-week automation coverage analysis with ROI narrative
Quarterly audit-committee or board-ready narrative from findings, incidents, and residual risk
Perform comprehensive system security scan for malware, hijacking, and suspicious activity
Generate a disclosure report from the current finding. Auto-detects the best submission channel. Usage: /report (run from target directory with confirmed…
Run all remaining phases autonomously — discuss→plan→execute per phase
Archive accumulated phase directories from completed milestones
[experimental] Compile human-reviewed scan history into local organization memory
[beta] Pattern propagation - find all instances of a vulnerability pattern throughout the codebase
[stable] Generate report output from `.claude/findings.json` in markdown, json, SARIF, interactive HTML, PR comment, or evidence bundle format
Set up AKA Security — calibrate notifications and detection posture from Claude's real activity.
Audit a deployed contract on a live chain. Pulls verified source from the block explorer, optionally forks the chain for live-state simulation.
Diff the on-chain configuration of one contract deployed across multiple chains — owner, oracle, fees, timelock, pause state, proxy impl — and flag the chain…
Multi-pass consensus audit — runs the audit twice with different prompts, only reports consensus findings. Aggressively cuts false positives.
Intake and risk-tier an AI use case, then produce the governance/oversight record (NIST AI RMF / EU AI Act / ISO 42001).
Run a T2/T3 security investigation — correlate telemetry, enrich, reconstruct the timeline, reach an evidence-backed verdict.
Run an objectives-based adversary-emulation operation aligned to real threat-actor TTPs, recon to impact.
GDPR breach notification procedures and 72-hour requirement
Scaffold a production-ready React/Vite portfolio website from site-config.json, with components populated from your GRC credentials and experience.
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic