Audit code for security vulnerabilities, review auth flows, and verify compliance with OWASP top 10. Context: Security review needed before release user: "Audit the authentication module for vulnerabilities" assistant: "I'll use the security-auditor agent to perform a security audit.".
Use this agent to generate tests, validate coverage, and verify test quality. Works with Vitest, Jest, Pytest, Playwright, Cypress, and any test framework. Context: New feature needs tests user: "Write tests for the auth service" assistant: "I'll use the tester agent to generate test coverage.".
Runs before the agent uses a tool for Edit, Write, write, MultiEdit, search_replace, Bash and run_terminal_command tool calls, executing security-check.cjs, bun-test-guard.cjs and principal-branch-pre.cjs via node (3 commands). From Roxabi/roxabi-plugins.
Runs after a tool call finishes for Edit, Write, write, MultiEdit, search_replace, Bash and run_terminal_command tool calls, executing format.cjs and principal-branch-post.cjs via node (2 commands). From Roxabi/roxabi-plugins.
Deep technical analysis — explore existing code, risks, alternatives. Triggers: "analyze" | "technical analysis" | "how deep is it" | "deep dive" | "investigate this" | "analyze this feature" | "what are the risks" | "explore the codebase" | "look into this" | "explain the architecture" | "what is the architecture" |…
Watch a CI run with live status + emoji dashboard; dump logs on failure; watch auto-merge if CI green + auto-merge enabled + "reviewed" label. Triggers: "watch ci" | "ci watch" | "watch the ci" | "watch run" | "monitor ci".
Implementation plan — tasks, agents, file groups, dependencies. Triggers: "dev-plan" | "plan this" | "implementation plan" | "break it down" | "plan this feature" | "how should we build this" | "make a plan" | "create a plan" | "break this down into tasks" | "task breakdown" | "/dev-plan". Not the host native /plan.
Workflow orchestrator — single entry point for the full dev lifecycle. Triggers: "dev" | "start working on" | "work on issue" | "work on #" | "develop" | "pick up issue" | "tackle issue" | "let's work on".
Set up local dev environment — stack.yml, CLAUDE.md Critical Rules, docs scaffolding, LSP. Triggered by /dev-init or standalone /env-setup. Triggers: "env setup" | "setup environment" | "scaffold rules".
Problem framing — capture problem, constraints, scope, tier. Triggers: "frame" | "frame this" | "what's the problem" | "define the problem" | "scope this out" | "define the scope" | "what are we solving" | "problem statement" | "restate what we are solving" | "recap the issue" | "intent first" | "step back and…