breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent.…
A command is the one you type. It runs exactly when you ask it to, and never before.
9,227 commands across 665 plugins.
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent.…
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot…
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata,…
Active vulnerability hunting. Two-track dispatcher — asks Red Team vs WAPT, hands off to hunt-dispatch skill and sibling commands. Usage: /hunt target.com |…
Create a new obsidian-second-brain command via interview - zero markdown editing required
Surface 3-5 next-direction candidates by reading ungraduated ideas, open project questions, and orphan research notes - what is worth working on next
Vault-first source-grounded research via Gemini File Search. One command, no browser. The grounded parallel to /research-deep (which is open-web via…
Smart router - Single entry point with natural language intent detection
Start a creative thought partner brainstorming session
Switch Octopus model routing to the configured budget tier
ChatGroup architecture — how conversation data flows from raw JSONL to rendered chat groups. Use when working on UserGroup, AIGroup, SystemGroup, display…
Design system and visual language — theming, CSS variables, Tailwind config, component styling patterns, icon usage, animations, and z-index layers. Use when…
Explains what "Visible Context" is — the 6 trackable token categories, what falls outside tracking, how it's displayed, and why it matters. Use when someone…
Autonomous performance optimization: research, PoC, benchmark, implement, review, PR
<meta> description: Create comprehensive technical design for a specification argument-hint: <feature-name> [-y] arguments: feature-name: $1 -y flag: $2 </meta>
Generate comprehensive technical design for a specification
<meta> description: Execute spec tasks using TDD methodology argument-hint: <feature-name> [task-numbers] arguments: feature-name: $1 task-numbers: $2 </meta>
Compatibility shim for entering the governed Vibe-Skills runtime through the canonical vibe skill.
Run the governed Vibe-Skills runtime for implementation after planning approval.
Run the governed Vibe-Skills runtime for review-first work.
Update CHANGELOG.md with all changes from the latest tag to current commit.
Adds a new rule to an existing SYNAPSE domain file.
<!-- ACORE-CLAUDE-AGENT-COMMAND: legacy-shim --> <!-- Canonical Skill: .claude/skills/AIOX/agents/aiox-master/SKILL.md --> <!-- Source:…
<!-- ACORE-CLAUDE-AGENT-COMMAND: legacy-shim --> <!-- Canonical Skill: .claude/skills/AIOX/agents/analyst/SKILL.md --> <!-- Source:…
Step 4 of the vibe-coding workflow: generate `AGENTS.md` + tool configs so the AI builder stays on track.
Step 5 of the vibe-coding workflow: build the MVP one verified feature at a time.
Step 2 of the vibe-coding workflow: define WHAT to build, WHO it's for, and WHY it matters.
Apply the Five Whys root cause analysis technique to investigate an issue
Create a branch, split changes into logical commits, and open a pull request
Run a multi-perspective PR review (product, dev, QA, security, DevOps, UX) and post it to GitHub
Auto-detect project type and configure quality gates, permissions, and hooks for a new codebase
Smart context compaction with state preservation — saves critical state before compact and restores after
Run a paid-ads (ROAS) workflow: audience segments, account structure, ad creative, experiment design, pre-launch signal QA + the account-audit gate,…
Natural-language front door to the marketing pack (narrative/TALE, SEO/GEO/SITE, social/ECHO, email/SEND, Paid Ads/ROAS, influencer/STAR, launch/RAMP). Use…
Run an email-marketing (SEND) workflow: deliverability/consent setup, segmentation, email creative, lifecycle flows, newsletter monetization, send-testing, and…
I'll help clean up development artifacts while preserving your working code.
I'll analyze recent operations and create contextual TODO comments in your code.
`/bmad-pilot <PROJECT_DESCRIPTION> [OPTIONS]`
`/project:bugfix <ERROR_DESCRIPTION>`
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic