deploy
Build the React/Vite site, sync to S3, and invalidate the CloudFront cache. Your portfolio goes live.
A command is the one you type. It runs exactly when you ask it to, and never before.
523 commands across 665 plugins.
Build the React/Vite site, sync to S3, and invalidate the CloudFront cache. Your portfolio goes live.
Create phases to close all gaps identified by milestone audit
Capture a forward-looking idea with trigger conditions — surfaces automatically at the right milestone
Create a clean PR branch by filtering out .planning/ commits — ready for code review
Analyze engagement state and create a strategic attack plan
Port scanning with fast discovery and detailed service enumeration
Set or view the scan profile (loud, normal, stealth, paranoid)
Fast pre-commit-grade scan. Only catches Critical and High. Optimized for hooks.
Generate code patches that fix one or more findings. Outputs as a unified diff and (optionally) applies it.
Replay a historical exploit tx (by tx hash) on a fork. Explains step-by-step what the attacker did.
Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP lock bypass, authority retention, bonding curve…
Quick 7-Question Gate triage on a finding before writing a report. Kills N/A submissions before they happen. Faster than /validate — for quick go/no-go…
Validate a finding — runs 7-Question Gate + 4-gate checklist. Kills weak findings before report writing. Prevents N/A submissions that hurt validity ratio.…
StateRAMP ATO package documentation guidance (SSP, SAP, SAR, POA&M)
Generate developer behavioral profile and create Claude-discoverable artifacts
Check project or hunt progress, show context, and route to the next action
Publish a hunt as a case report, escalation, detection promotion, or leadership summary
Check and install reverse engineering tools on Kali Linux
Generate comprehensive reverse engineering analysis report
One-line analysis pulse — binary, phase, findings, IOCs, tools installed
Render the latest audit as a deliverable report in Markdown / HTML / PDF / JSON / PNG.
Fast owner-power / rugability scan — score how much unilateral control the deployer holds and return a 0-100 rug-risk verdict.
60-second onboarding — set up .rugproof.yml, choose severity profile, configure hooks, pick supported chains.
Smart contract security audit — runs through 10 bug class checklist (accounting desync, access control, incomplete path, off-by-one, oracle errors, ERC4626,…
Generate a company-specific password wordlist for spray attacks. Crawls the target website with cewler, dedups + length-filters, then applies hashcat rules to…
Create an editable native draw.io diagram, optionally exported to PNG/SVG/PDF with embedded XML
Execute a quick task with THRUNT guarantees (atomic commits, state tracking) but skip optional agents
Remove a future phase from huntmap and renumber subsequent phases
Full reconnaissance workflow — subdomain enum, tech detection, WAF fingerprinting, crawling
Generate a formatted vulnerability report from engagement findings
Set engagement scope and auto-detect target technology stack
Compute a Rugproof grade (A+ → F) for the contract or repo based on findings from /audit.
Multi-actor, multi-block simulation against a live fork. Stateful attack sequences across many txs.
Run Slither and have Claude triage its findings — separate true positives from false positives, write PoCs for real bugs.
Create an editable draw.io grc evidence flow diagram for GRC professionals
Loop collect-evidence over a framework's controls until every control has a manifest for the target period
Resume project or hunt work from the previous session with full context restoration
Focused secret and credential extraction from a binary
Initialize a new engagement workspace — gather targets, select plugins, check tools, generate project files
One-line engagement pulse — target, phase, findings, chains, profile
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic