flounder
Operates Flounder, an autonomous white-hat security auditor.
What this skill does for you
Operates Flounder, an autonomous white-hat security auditor. Use when a user asks for a security audit, bug-bounty review, vulnerability investigation, or exploit proof for a public-source or authorized repository, source tree, package, smart contract, Solidity/EVM project, ZK or proof-system code, deployed address, transaction, project link, or prior Flounder run; to run Flounder prepare, map, dig, audit, verify, confirm, or report workflows; to configure Flounder server, daemon, provider profiles, model auth, sandboxed execution, corpus paths, source paths, build roots, coverage, or budgets; to monitor live audit activity, continue pending scopes, verify suspected vulnerabilities, reproduce findings, or collect execution-backed bug reports; or when a Flounder maintainer asks an agent to improve auditor recall, analyze Evaluation failures, run governed Harness experiments, modify Flounder source in an isolated branch, or prepare a candidate improvement PR.
Quoted from the skill description in the pinned sourceWho made it
Use it with Edge
Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the flounder skill from adshao/flounder.
Paste it into Claude, ChatGPT, Codex or Cursor.
Or read the skill source first.
Security evidence
| Scanner | Date | Result | Findings |
|---|---|---|---|
| Edge static checks | 2026-09-27 | Pass | 0 |
| Cisco skill-scanner | 2026-09-27 | Pass | 0 |
| Semgrep Edge rules | 2026-09-27 | Pass | 0 |
Static scans check the code, not how well the skill works.
Scanner scope, raw findings and mirrored provider records
Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: fd79948c70655c03cb42932d49ec5b48dc8516d7. Raw findings: 2. Counted findings: .
Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: fd79948c70655c03cb42932d49ec5b48dc8516d7. Raw findings: 1. Counted findings: .
Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: fd79948c70655c03cb42932d49ec5b48dc8516d7. Raw findings: . Counted findings: .
Source and licence
- Repository
- https://github.com/adshao/flounder
- Pinned skill file
- View source at revision
- Revision
- fd79948c70655c03cb42932d49ec5b48dc8516d7
- Package hash
- sha256:509ebb6d9110d4bc104c8826a7922ff41ee7be7fda0e860002831dd937730154
- Licence
- AGPL-3.0