audit-diff
Diff two Rugproof audit reports (before vs after) to track regressions — what's new, what's fixed, and whether the grade moved.
A command is the one you type. It runs exactly when you ask it to, and never before.
523 commands across 665 plugins.
Diff two Rugproof audit reports (before vs after) to track regressions — what's new, what's fixed, and whether the grade moved.
Pull past public audits (Code4rena, Sherlock, Spearbit, etc.) for a deployed contract or known protocol.
Run a secure-by-design architecture review — threat model, trust boundaries, control selection, and a documented verdict.
Run an authorized penetration test end-to-end, chaining recon, testing, and reporting skills into one flow.
Run a build-and-harden pass across code, pipeline, cloud, and infra, then track remediation.
Create an STM team or join one, guided end-to-end via stm teams quickstart
Scan only the changed files in a single commit or PR/MR for newly introduced vulnerabilities (fast incremental check, not a full pipeline run)
Run the full mobile SAST pipeline (phases 01-06) against this repository — Android, iOS, React Native, or Flutter
Run the full web SAST pipeline (phases 01-06) against this repository
Scan an endpoint for CORS misconfiguration — arbitrary-origin reflection, null-origin trust, credential exposure, suffix/prefix regex bypass, scheme downgrade.…
Test for CRLF / HTTP response-splitting and host-header injection — Set-Cookie injection, cache poisoning, reset-poisoning. Usage: /crlf <url> [--host-header]…
Confirm DOM XSS in a real headless browser — injects canary payloads into params + URL fragment and only reports when the browser actually executes them.…
Run full recon pipeline on a target — subdomain enum (Chaos API + subfinder), live host discovery (dnsx + httpx), URL crawl (katana + waybackurls + gau), gf…
Optional manual note on a target or the last confirmed finding. Capture is automatic during autopilot; this is for extra context. Usage: /remember
Write a submission-ready bug bounty report. Generates H1/Bugcrowd/Intigriti/Immunefi format with CVSS 3.1 score, proof of concept, impact statement, and…
Have I seen this before? Check a seed against every prior case BEFORE collecting. Always run this first. Usage: /cti-recall <domain|indicator>
Render case deliverables — relationship graph (PNG/SVG/Mermaid) and a polished PDF/DOCX assessment. Usage: /cti-report <CASE-ID> [--graph|--pdf]
Health check — backend tier, case store, MCP tools, API credit balances. Run this when something behaves oddly. Usage: /cti-status
Week-over-week automation coverage analysis with ROI narrative
Quarterly audit-committee or board-ready narrative from findings, incidents, and residual risk
Initialize a new security engagement following the Kill Chain workflow
Execute Phase 5 - Installation and Persistence Establishment
Quantify a candidate economic finding — compute attack cost vs extractable value and, when possible, reproduce deposit→manipulate→withdraw against a Surfpool…
Interactive engagement intake (alias /scope). Walks QUESTIONS.md and persists the answers to audit_<n>/intake.md — the durable intake artifact both audit-cycle…
Draft and verify a fix for a confirmed finding — a MINIMAL idiomatic unified diff against the pinned audited commit, applied to a scratch worktree and proven…
Generate a disclosure report from the current finding. Auto-detects the best submission channel. Usage: /report (run from target directory with confirmed…
Perform comprehensive system security scan for malware, hijacking, and suspicious activity
Run all remaining phases autonomously — discuss→plan→execute per phase
[experimental] Compile human-reviewed scan history into local organization memory
[beta] Pattern propagation - find all instances of a vulnerability pattern throughout the codebase
[stable] Generate report output from `.claude/findings.json` in markdown, json, SARIF, interactive HTML, PR comment, or evidence bundle format
Show running scans, system health, and engagement status
Post-engagement lessons learned analysis and debrief report
Ghidra headless decompilation with function analysis
Set up AKA Security — calibrate notifications and detection posture from Claude's real activity.
Audit a deployed contract on a live chain. Pulls verified source from the block explorer, optionally forks the chain for live-state simulation.
Diff the on-chain configuration of one contract deployed across multiple chains — owner, oracle, fees, timelock, pause state, proxy impl — and flag the chain…
Multi-pass consensus audit — runs the audit twice with different prompts, only reports consensus findings. Aggressively cuts false positives.
Intake and risk-tier an AI use case, then produce the governance/oversight record (NIST AI RMF / EU AI Act / ISO 42001).
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic