caiq-generate
Generate CAIQ (Consensus Assessments Initiative Questionnaire) responses
A command is the one you type. It runs exactly when you ask it to, and never before.
426 commands across 357 plugins.
Generate CAIQ (Consensus Assessments Initiative Questionnaire) responses
Archive completed milestone and prepare for next version
Systematic debugging with persistent state across context resets
Route freeform text to the right hunt or THRUNT command automatically
[beta] Run quick, deep, or audit scan profiles and emit a shared findings artifact
[stable] Prepare focused analysis scope for large codebases, list workspaces in monorepos
[beta] Search for dangerous functions (sinks) and auto-discover output patterns
Show token usage and estimated cost per model from your local AKA store
Generate a responsible-disclosure bounty submission from a confirmed finding — Immunefi / protocol bounty / SEAL 911 formats.
Submit a finding to a bug-bounty platform (Immunefi, Cantina) automatically.
Generate a shareable PNG audit card from the latest /audit. Optimized for social media.
Run the pre-commit security gate on the current changeset and report a single pass/fail verdict.
Run an AI safety review for a feature/model — harms, evaluations, guardrails, and a documented safety case.
Assess technology/security risk for a strategic decision and frame the secure-by-design path.
CCCS assessment process and certified cloud provider guidance
Execute a trivial task inline — no subagents, no planning overhead
Post-mortem investigation for failed THRUNT workflows — analyzes git history, artifacts, and state to diagnose what went wrong
Diagnose planning directory health and optionally repair issues
[beta] Application understanding + threat modeling - maps architecture, generates DFDs, performs STRIDE analysis
[beta] Trace data flow from sources to a specific sink with explicit evidence requirements
[stable] Verify findings with Joern plus code review and update the shared findings artifact
Run forge coverage, identify untested branches, generate tests to close gaps.
Run Rugproof against the bundled vulnerable example contracts — first-run "wow moment".
Diff the contract against a canonical reference implementation (OZ, Solady, Uniswap V3, etc.) and flag suspicious deltas.
Triage a SOC alert end-to-end — validate, enrich, decide, and escalate or close with rationale.
Generate ISO 27001 certification roadmap from readiness through surveillance audits
Set up GitHub Actions CI/CD with OIDC for keyless AWS authentication — automatic deployment on every push to main.
NYDFS CISO role, qualifications, and responsibilities
Show available THRUNT threat hunting commands and artifact layout
Insert urgent work as decimal phase (e.g., 72.1) between existing phases
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic