{"repo":"adshao/flounder","free":true,"listed":false,"github":"https://github.com/adshao/flounder","clone":"git clone https://github.com/adshao/flounder.git","description":"Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.","language":"TypeScript","stars":329,"topics":["audit","security","smart-contracts","white-hat","zk","autonomous-agents","bug-bounty","code-audit","evm","exploit-development"],"license":"AGPL-3.0","category":"blockchain-web3","readme_excerpt":"Flounder An autonomous white-hat security auditor. Security automation for target prep, audit, exploit construction, and execution proof. Usage · Architecture · Security · Contributing --- Flounder turns modern coding agents into an end-to-end security audit system. Give it a public-source or authorized target boundary - a repository, source tree, package, deployed clue, or prior run - and the agent can prepare the workspace, read the code and supporting material, map the attack surface, dig into promising regions, construct exploit paths, run local proof tests, and then reproduce confirmed findings against real-world ground truth. The important distinction is that Flounder is not a scanner for one stack, a checklist runner, or a set of hand-written bug rules. It is a thin white-hat audit workflow around the model: the model decides how to reason about the target, while Flounder supplies the sandbox, command policy, durable state, execution gates, daemon control plane, and reporting needed to make that reasoning usable. Use It With An Agent Install the skill once from GitHub, even when you do not have the source checkout locally: If you are already in a local checkout, install the checked-out copy instead: Then ask Codex, Claude Code, or another skills-aware agent naturally: The installed skill should trigger from requests about Flounder audits, public-source or authorized source review, smart-contract or ZK audit work, daemon/provider setup, verifying suspected findings, con","default_branch":null,"files":null,"tree":[],"storefront":"/r/adshao","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/adshao/flounder/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}