report
Write a submission-ready bug bounty report. Generates H1/Bugcrowd/Intigriti/Immunefi format with CVSS 3.1 score, proof of concept, impact statement, and…
A command is the one you type. It runs exactly when you ask it to, and never before.
523 commands across 665 plugins.
Write a submission-ready bug bounty report. Generates H1/Bugcrowd/Intigriti/Immunefi format with CVSS 3.1 score, proof of concept, impact statement, and…
Serve a localhost compliance posture dashboard from monitor-continuous JSON
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
Generate a comprehensive project summary from milestone artifacts for team onboarding and review
Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion
Check and install opsec tools — verify availability or auto-install missing dependencies
Analyze current opsec posture and create a strategic hardening/cleanup plan
Configure and manage proxy chains, VPN connections, and Tor routing
Gas profile — find expensive operations and suggest optimizations with before/after numbers.
Generate Foundry invariant tests for property-based fuzzing. The high-value command for serious teams.
Mint a soulbound Audit Certificate NFT on Berachain (or other supported chain) for a completed audit.
Run Semgrep security rulesets over fetched JS/source and map results into the toolkit's severity + confidence model. Usage: /sast <path> [--config p/xss,p/jwt]…
Run a focused nuclei CVE sweep against a host or recon directory, optionally filtered by year. Runs log4j-scan in parallel when installed for legacy enterprise…
Check if a target asset is in scope for the program before hunting or submitting. Reads program scope page, checks asset against in-scope and out-of-scope…
Set up NIST 800-53 continuous monitoring per RA-5, SI-4, and CA-7
Explain a single control once and show every framework it maps to via the SCF crosswalk
Initialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories
Create an isolated workspace with repo copies and independent .planning/
Automatically advance to the next logical step in the active hunt or THRUNT workflow
Generate comprehensive opsec report covering operations, hardening, traces, identities, and risk assessment
Quick opsec pulse — one-line status showing current operation state, proxy chain, and profile
Scan for traces left behind on a system and eliminate them
Set up post-deployment monitoring — recommend which on-chain events to alert on and scan recent activity for high-severity changes.
Run Mythril (symbolic execution) and have Claude triage its findings — turn symbolic counter-examples into Foundry PoCs.
Post the latest /audit results to a Discord channel via webhook.
Pull every in-scope asset for a bug bounty program across HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi in one shot. Uses bbscope when authenticated,…
Screenshot a list of live hosts for fast visual triage and reusable PoC evidence. Builds a self-contained HTML gallery. Usage: /screenshot -l urls.txt -o…
Hunt leaked credentials in a filesystem path, git history, JS bundles from a recon run, or an entire GitHub org. Wraps trufflehog (verifies live keys against…
Create an editable draw.io grc control map diagram for GRC professionals
Interactive NIST 800-53 control tailoring for specific baselines and environments
Convert FedRAMP Rev 5 SSP DOCX templates (main SSP + Appendix A) to OSCAL 1.2.0 SSP JSON.
Create phase plans for a threat hunt with exact telemetry tasks, receipts, and query outputs
Secure a fresh VPS — encrypted storage, firewall, SSH hardening, log management, killswitch
Securely wipe files, directories, or free space using multi-pass overwrite
AI-powered payload generation for XSS, SQLi, LFI, command injection, and more
Post the latest /audit results to a Slack channel via incoming webhook.
Interactive pre-launch security checklist — walk the operational and code-safety gates and produce a final GO / NO-GO with each item PASS / FAIL / N-A.
Formal verification entrypoint — prove a property holds for all inputs with Halmos (symbolic, offline) or Certora (CVL) using ready-made property templates.
Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 +…
Show ranked attack surface for a target based on recon output + hunt memory. Invokes recon-ranker agent. Usage: /surface target.com
Scan subdomains for takeover candidates (dangling CNAMEs to GitHub Pages, S3, Heroku, Shopify, etc.). Wraps dnsReaper (best signal) and subjack (fast Go…
Create an editable draw.io grc regulated data flow diagram for GRC professionals
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic