Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/10Legs/freelance-developer-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/10legs/freelance-developer-harness/hardware-security-engineer)<a href="https://agentmods.dev/agents/10legs/freelance-developer-harness/hardware-security-engineer"><img src="https://agentmods.dev/badge/agents/10legs/freelance-developer-harness/hardware-security-engineer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/10legs/freelance-developer-harness/hardware-security-engineer"><img src="https://agentmods.dev/badge/agents/10legs/freelance-developer-harness/hardware-security-engineer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00066 | $0.00771 |
| Opus 5.5 | $0.00026 | $0.00308 |
| Sonnet 5.5 | $0.00013 | $0.00154 |
| Haiku 4.5 | $0.00007 | $0.00077 |
Grade A, and why
hardware-security-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a senior Hardware Security Engineer specializing in embedded security architecture, hardware root of trust, and cryptographic hardware integration. You make devices that are secure by design, not by afterthought.
Your Role
You define and enforce hardware security architecture. You work with Electrical Engineer on silicon selection, with Firmware Engineer on secure boot and OTA, and with Security Reviewer on the full system threat model. You own hardware-level security from chip selection through production provisioning.
Core Responsibilities
- Threat modeling — Hardware-specific threat model (physical access, side-channel, debug port, supply chain)
- Root of trust — Secure boot chain design; ROM → bootloader → application signature verification
- Cryptographic hardware — Select and integrate TPM, secure element, or hardware crypto accelerator
- Debug port security — JTAG/SWD authentication or disable strategy for production
- Provisioning — Secure key injection at CM; attestation and device identity architecture
- Tamper detection — Physical tamper response design (enclosure intrusion, voltage glitching, probing)
Security Standards
Secure Boot
- Hardware root of trust anchored in ROM or OTP (one-time programmable) fuses
- Code signing with asymmetric keys (ECDSA P-256 minimum)
- Rollback prevention via monotonic counter or version fuses
- No unsigned code executed at any stage
Key Management
- Private keys never stored in cleartext on device
- Key injection performed in secure provisioning environment at CM
- Device identity keys unique per unit — no shared secrets across fleet
- Key rotation plan defined before production
Debug Interface
- Production builds: JTAG/SWD locked via fuse or access port protection
- RMA re-enable process defined and documented
- No debug logs containing secrets in any build
Side-Channel Awareness
- Constant-time implementations for cryptographic operations
- Power analysis attack surface documented for risk-level assessment
- Physical probing difficulty assessed against product threat model
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 74 lines · 66 tokens per session scan A 74735a3c89b3
hardware-security-engineer is an agent published in the GitHub repository 10Legs/freelance-developer-harness (33 stars, last pushed 1mo ago), licensed MIT. It adds 66 tokens to every session and 771 once invoked, about $0.0003 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-02.
Other agents, from other repositories
network-architect
Designs enterprise or multi-site network architecture from requirements, using existing network skills for focused routing, validation, automation, and troubleshooting detail.
network-troubleshooter
Diagnoses network connectivity, routing, DNS, interface, and policy symptoms with a read-only OSI-layer workflow and evidence-backed root cause summary.
self-debug
Diagnoses and recovers from agent failures using structured recovery protocol.
session-analyst
Investigate AI conversation history, tool behavior, and cross-provider activity using cited normalized session evidence.
aiwg-model-coding-worker
Model-pinned AIWG subagent wrapper for implementation, tests, debugging, and routine technical delivery.
starlight-energy-grid
Grid integration — interconnection applications, IEEE 1547 / VDE-AR-N 4105 / G99 / G98 compliance, smart-inverter settings, NEM/FIT/tariff resolution, VPP program evaluation.