Flowgen is a suite of slash commands for Claude Code that runs one idea through five disciplines — design, code, security, test, debug — in six numbered phases. It doesn't just generate code — it attacks it. Phase 4 runs live DAST on your app in Docker: 40 attack primitives, 10 reasoned zero-day hypotheses, 13,600+ Nuclei security templates (~4,400 CVE). Then it hands you the evidence. Free Edition is $0 forever, no card. Full Edition is a one-time purchase. No subscription. No telemetry.
I built Flowgen because I kept shipping code I couldn't defend.
Claude Code writes the feature in minutes. But "it runs" and "it holds up" are different claims, and only one of them has evidence behind it.
So Flowgen runs five disciplines on one sentence — design, code, security, test, debug. Phase 4 is the one I care about — it spins your app up in Docker and attacks it. 40 live attack primitives, 10 zero-day hypotheses it reasons out on the spot, and 13,600+ Nuclei security templates — about 4,400 of them CVE-specific — pinned to a fixed template version so the number can't drift. Then it gives you the evidence, not a score.
The verdict stays with you. Flowgen never says "safe" — it says what it tried and what happened.
Free Edition is $0 forever, no card, no time limit. Full Edition is a one-time purchase — no subscription, no telemetry, ever.
I'd genuinely like to hear where it breaks for you. If you run it on something real and it misses, tell me here — that's the feedback I can act on.