symbolic
Symbolic execution via Halmos. For paths that fuzzing cannot reach.
A command is the one you type. It runs exactly when you ask it to, and never before.
523 commands across 665 plugins.
Symbolic execution via Halmos. For paths that fuzzing cannot reach.
Generate a Foundry test suite — happy path + edge cases + adversarial tests — for a contract or function.
Compose a tweet from the latest audit. Either auto-posts (if Twitter API creds set) or generates a one-click intent URL.
Weekly 1-page executive summary for the CISO and direct leadership
Deep dive analysis of NIST 800-53 control families with implementation guidance
Execute a hunt phase with parallel telemetry work, query logging, receipt generation, and optional wave targeting
Generate a session report with token usage estimates, work summary, and outcomes
View and search the techniques & reports database
Chronological engagement timeline — all events merged by time
Acquire and dump data from an accessible leak source
Check storage compatibility, initializer changes, and admin-function deltas between two implementations of an upgradeable contract.
Verify deployed bytecode matches the source you have, with correct constructor args.
Second-opinion mode — re-check a specific finding with deeper analysis. Triages true vs false positives.
Get a working primer on a GRC framework — purpose, scope, artifacts, cadence, and where to start
Create an editable draw.io grc framework crosswalk diagram for GRC professionals
List every SCF-mapped framework (249) and show which have a dedicated plugin
Switch model profile for THRUNT agents (quality/balanced/budget/inherit)
Turn a signal into testable hunt hypotheses, scope, datasets, and success criteria
Resume or execute a leak hunting campaign with progress tracking
Classify a discovered leak source with credibility, freshness, and access method
Search dark web .onion sites for leak databases (requires dark/ghost profile)
Aggregate connector findings, map to requested frameworks via SCF crosswalk, and produce a prioritized gap report with remediation links.
Loop on gap-assessment + generate-implementation until severity-N findings = 0
Display project statistics — phases, plans, requirements, git metrics, and timeline
Generate and execute Google dork queries for exposed databases and data
Search breach forums for leak postings and database offers
Scan GitHub and GitLab for leaked secrets, configs, and database dumps
Convert SOC 2 gap analysis findings to Infrastructure as Code fixes
Generate assessment interview questions mapped to framework controls
Validate hunt conclusions against receipts, contradictory evidence, and success criteria
Generate a structured elliot handoff package for a protected target
Unified multi-source leak hunt — runs applicable sources based on current profile
Check and install required leak hunting tools
Retroactively audit and fill Nyquist validation gaps for a completed phase
Manage parallel workstreams — list, create, switch, status, progress, complete, and resume
Create a strategic leak hunting campaign plan
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic