investigate
Run a T2/T3 security investigation — correlate telemetry, enrich, reconstruct the timeline, reach an evidence-backed verdict.
A command is the one you type. It runs exactly when you ask it to, and never before.
523 commands across 665 plugins.
Run a T2/T3 security investigation — correlate telemetry, enrich, reconstruct the timeline, reach an evidence-backed verdict.
Run an objectives-based adversary-emulation operation aligned to real threat-actor TTPs, recon to impact.
Active vulnerability hunt against a target by invoking tools/hunt.py (which calls vuln_scanner.sh against recon/<target>/). Auto-runs recon first if no recon…
On-demand intelligence fetch for a target — CVEs, disclosed reports, new features. Wraps learn.py + hunt memory context. Usage: /intel target.com
JWT attack toolkit (offline) — alg:none forgery, RS256→HS256 algorithm confusion, weak-secret crack, static claim analysis. Usage: /jwt-scan <token>…
Mandatory pre-flight scope check — verify an asset is in scope BEFORE any HTTP touch. Deterministic (deny-wins, default-deny) via engine/scope.py against the…
Show ranked attack surface for a target from its recon manifest + hunt memory. Deterministic backing is `cbh surface <target>` (reads…
Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP lock bypass, authority retention, bonding curve…
Scaffold a production-ready React/Vite portfolio website from site-config.json, with components populated from your GRC credentials and experience.
Generate CAIQ (Consensus Assessments Initiative Questionnaire) responses
Cross-engagement pattern memory — recall prior techniques, record confirmed findings, housekeeping
Resume an engagement from the engine trace — skip completed steps, continue where you left off
Generate an executable proof-of-concept exploit for a confirmed High/Critical finding — detect the toolchain, pick the harness framework by finding type, spawn…
Fast security triage — discovery + static analysis + the highest-severity vector subset, without the full item-by-item walk. Use for a first look or a CI gate.
Fix-review / re-audit. Takes a prior audit report + the current tree and classifies every prior finding FIXED / PARTIALLY-FIXED / STILL-OPEN / REGRESSED /…
[beta] Run quick, deep, or audit scan profiles and emit a shared findings artifact
[stable] Prepare focused analysis scope for large codebases, list workspaces in monorepos
[beta] Search for dangerous functions (sinks) and auto-discover output patterns
Binary diffing — compare two binaries for patch analysis
Directory and content discovery with recursive crawling
.NET assembly analysis — decompilation, deobfuscation, metadata extraction
Show token usage and estimated cost per model from your local AKA store
Generate a responsible-disclosure bounty submission from a confirmed finding — Immunefi / protocol bounty / SEAL 911 formats.
Submit a finding to a bug-bounty platform (Immunefi, Cantina) automatically.
Generate a shareable PNG audit card from the latest /audit. Optimized for social media.
Run the pre-commit security gate on the current changeset and report a single pass/fail verdict.
Run an AI safety review for a feature/model — harms, evaluations, guardrails, and a documented safety case.
Assess technology/security risk for a strategic decision and frame the secure-by-design path.
LLM red-team corpus runner — fires categorized prompt-injection / jailbreak / system-prompt-leak / data-exfil / indirect-injection / guardrail-bypass payloads…
Inspect or rotate hunt-memory JSONL files (audit.jsonl, patterns.jsonl, journal.jsonl). Caps file size and keeps N rotated backups so memory does not grow…
NoSQL injection scanner (MongoDB/Mongoose/operator-injection DBs) — auth bypass via $ne/$gt operators, bracket-syntax query injection, $where time-based blind.…
Quick 7-Question Gate triage on a finding before writing a report. Kills N/A submissions before they happen. Faster than /validate — for quick go/no-go…
Validate a finding — runs 7-Question Gate + 4-gate checklist. Kills weak findings before report writing. Prevents N/A submissions that hurt validity ratio.…
Smart contract security audit — runs through 10 bug class checklist (accounting desync, access control, incomplete path, off-by-one, oracle errors, ERC4626,…
Calibrate model verdict trust (Wilson-bounded miss-rate) to short-circuit re-validation
Spec-vs-code compliance audit — extracts requirements from a spec / whitepaper / RFC and matches each to the implementation with typed verdicts.
Builds the pre-review threat model as audit_<n>/threat-model.md — an asset inventory (crown-jewel funds/authority/data and where they live), an actor x…
Re-runnable batch triage checkpoint over the candidate finding set (fixes triage being diffused across agents). Dedups by root-cause signature (reusing…
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic