dismiss
Mark a finding as a false positive (or accepted risk). Future audits won't re-report it.
A command is the one you type. It runs exactly when you ask it to, and never before.
426 commands across 357 plugins.
Mark a finding as a false positive (or accepted risk). Future audits won't re-report it.
Explain a finding in plain English, with examples. Optionally tailored to a beginner audience.
Generate a working Foundry PoC that exploits a specific finding. Compiles and passes.
Return ranked Google documentation references for a control or implementation topic.
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Surface Claude's assumptions about a phase approach before planning
Interactive command center for managing multiple project or hunt phases from one terminal
Chain multiple findings into a single multi-step exploit. Produces a Foundry test that proves the chain works.
Generate an exploit against a *deployed* contract on a fork. Validates the exploit works on live state.
Serve a localhost compliance posture dashboard from monitor-continuous JSON
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
Generate a comprehensive project summary from milestone artifacts for team onboarding and review
Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion
Gas profile — find expensive operations and suggest optimizations with before/after numbers.
Generate Foundry invariant tests for property-based fuzzing. The high-value command for serious teams.
Mint a soulbound Audit Certificate NFT on Berachain (or other supported chain) for a completed audit.
Set up NIST 800-53 continuous monitoring per RA-5, SI-4, and CA-7
Explain a single control once and show every framework it maps to via the SCF crosswalk
Verify specific CIS Control implementation from 18 controls
Initialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories
Create an isolated workspace with repo copies and independent .planning/
Automatically advance to the next logical step in the active hunt or THRUNT workflow
Set up post-deployment monitoring — recommend which on-chain events to alert on and scan recent activity for high-severity changes.
Run Mythril (symbolic execution) and have Claude triage its findings — turn symbolic counter-examples into Foundry PoCs.
Post the latest /audit results to a Discord channel via webhook.
Create an editable draw.io grc control map diagram for GRC professionals
Interactive NIST 800-53 control tailoring for specific baselines and environments
Convert FedRAMP Rev 5 SSP DOCX templates (main SSP + Appendix A) to OSCAL 1.2.0 SSP JSON.
Zero-friction idea capture. Append, list, or promote notes to todos.
Create phase plans for a threat hunt with exact telemetry tasks, receipts, and query outputs
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic