audit
Audit a file, directory, or whole repo for insecure default configuration: fallback secrets, default credentials, fail-open switches, weak crypto, permissive…
A command is the one you type. It runs exactly when you ask it to, and never before.
426 commands across 357 plugins.
Audit a file, directory, or whole repo for insecure default configuration: fallback secrets, default credentials, fail-open switches, weak crypto, permissive…
Stops, cancels, or aborts the active skill improvement loop while preserving all changes made to skill files. Use to manually stop, cancel, abort, or kill the…
Deep dive analysis of ISO 27001 Annex A control domains with implementation guidance
Full SAIL V2 gap analysis of the AI agent/system in the current repo — component inventory, all 91 catalog risks dispositioned, prioritized recommendations.…
SAIL V2 compliance checklist — ISO/IEC 42001, EU AI Act, OWASP LLM/Agentic, DASF, AIUC-1. All five frameworks by default, or only those named.
Vendor RFP questionnaire from the SAIL V2 catalog — security-vendor coverage questionnaire by default, platform-vendor framing on request.
Decompile an Android APK/XAPK/AAB/DEX/JAR/AAR and analyze its structure
Activate pentest mode — displays ASCII art, configures session isolation, collects engagement scope, then OWNS the engagement: pre-flight, recon, planning (via…
Define the attack profile for an engagement — select which attack categories and skills to use. Saves to .pentest-attacks.json. If run before /pentest:pentest,…
Close pentest session — summarizes findings, ensures outputs are saved, lifts isolation, and prompts for /clear
Route an attack vector to the appropriate specialist agent — usage: /project:attack <target> <vector>
Start a new engagement for a target — verifies scope, creates evidence directories, and launches recon agent
Upload and analyze a suspicious binary file using the remote Dr. Binary MCP tools
Detect browser hijacking including homepage changes, search engine modifications, and malicious extensions
Monitor active network connections and detect suspicious network activity
Query NVD and OSV.dev for existing CVEs. Usage: /check-nvd <package-name>. Shows CVE count, severity breakdown, and recent fixes.
Take a confirmed vulnerability pattern and find the same bug in similar packages. Usage: /cross-pollinate (run after confirming a finding).
Run the 6-gate false positive elimination process on the current finding. Usage: /fp-check (run from a target directory with findings).
Add an idea to the backlog parking lot (999.x numbering)
Generate tests for a completed phase based on Evidence Review criteria and implementation
Hardstop - Pre-execution safety layer for shell commands. Shows status and help.
Test for a specific vulnerability class against target endpoints using curated payloads.
[experimental] Auto-remediate verified findings by generating patches and optionally creating a PR
[experimental] Create a custom Semgrep detection rule from a confirmed vulnerability pattern
[stable] Compare security posture between two git refs to find new/fixed vulnerabilities and track regression
Show guardrails status, switch modes, set token cap, or view the audit log. Usage: /guardrails [status|log|strict|relaxed|audit|reset|policy|tokencap]
Print the gitleaks release sha256 for a version, formatted for direct paste into a GitHub Actions workflow or `agent-guard setup --install`. Pass an optional…
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic