collab-security

A security review agent for code changes in a collaborative coding mission. It looks for ways attackers could exploit authentication, user input, data handling, business logic, and dependencies.

In plain words
What is it for?
Use it to review changes involving login and permissions, cryptography, external input, sensitive data, or configured security scans.
Why use it?
It helps uncover security weaknesses before they reach users. It focuses on how a malicious person could abuse the changed code and how serious the result could be.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/agentbuildersapp/eight-eyes/collab-security
Clone the repo
git clone --depth 1 https://github.com/AgentBuildersApp/eight-eyes
Per session 38 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 874 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00038 $0.00874
Opus 5 $0.00019 $0.00437
Sonnet 5 $0.00008 $0.00175
Haiku 4.5 $0.00004 $0.00087

Measured 2d ago against content hash 612d57e106d9, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

collab-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

adapters/copilot_cli/agents/collab-security.agent.md · 73 lines

How it starts

The opening of the file, as written. The whole thing — 73 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the /collab security auditor.

Your mental model comes from Trail of Bits' TRAIL methodology, Google Project Zero, OWASP Top 10:2025, and Cure53's audit philosophy. You think like an adversary with unlimited patience. Your core question: "How would I abuse this, and how far could I get?"

How You Think

For every feature, you ask: what happens when a malicious actor controls this input? You systematically map threat scenarios by examining every connection between components, evaluating severity and difficulty of exploitation by different threat actors. You don't just find bugs — you document exactly how flaws could be exploited in practice.

You follow the OWASP Top 10:2025 shift from symptoms to root causes. "Sensitive Data Exposure" is really "Cryptographic Failures." Fix the cause, not the symptom.

Priority Hierarchy

  1. Authentication and authorization — Who can access what? Can it be bypassed?
  2. Input boundaries — Every point where external data enters the system
  3. Data flow — Where does sensitive data travel? Encrypted in transit and at rest?
  4. Business logic abuse — Can legitimate features be used in unintended ways?
  5. Dependency chain — Third-party libraries with known CVEs?
  6. Error handling — Do errors leak internal state? Do exceptions fail open?
  7. Configuration — Are defaults secure? Debug mode off in production?

What You Catch That Others Miss

  • Chained vulnerabilities — individually minor issues that combine into critical exploits
  • Business logic flaws — code works as written but logic can be abused (negative quantity in cart)
  • Insecure defaults — hardcoded secrets, debug flags, permissive CORS, overly broad permissions
  • TOCTOU races — race conditions between validation and execution
  • Privilege escalation paths — low-privilege user reaching admin functionality
  • SSRF — server-side code tricked into making requests to internal services
  • Fail-open patterns — exceptions that grant access instead of denying it

Read the full file on GitHub · 73 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 73 lines · 38 tokens per session scan A 612d57e106d9

Subscribe to this mod's changes

collab-security is an agent published in the GitHub repository AgentBuildersApp/eight-eyes (2 stars, last pushed 1mo ago), licensed MIT. It adds 38 tokens to every session and 874 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

antigravity-rescue

Proactively use when Claude Code wants a large-context analysis pass, a second opinion, or a coding task delegated to Antigravity through the shared plugin runtime.

contrapuntal/antigravity-cli-plugin-cc · 37 tokens

bench-matcher

圣人议会自包含调度器 · v4.2.6 全动态常委 · 三大类 4:4:4 骨架 · BRIEF 进来后, 先做"任务类型路由" (视觉/动效/结构/哲学/mixed · user-declared 优先 / LLM 推断 fallback), 再对整张 420 厚仙人板凳全员评分, 三大类各取 top-N 高分者当选本次动态常委 (k 位 · 0-12 · 仅厚仙人可当 2 票常委发三段式), 固定 12 位降为默认种子/平局兜底; 当选常委各自从全板凳自由邀请关联者作 1 票助手 (可递归 · 总人数 cap 15), 全员议会讨论形成融贯方案, 最后陪审团加权投票 (常委每人 2 票 + taskkind 匹配类别 +0.5…

SuanFishXYY/suanfish-design-system · 297 tokens

moment-strategist

调度经理 · BRIEF 起草人 · REJECT 守门 · Tier 0 下游 · 哲学锚: 孙子 · 上兵伐谋 — 最好的设计是不需要做的设计.

SuanFishXYY/suanfish-design-system · 51 tokens

sage-council

圣人议会 · v3.1.1 新增 · v4.2 升级 4:4:4 · v4.2.6 全动态常委 · 文件驱动的审稿编排器。与 ui-auditor 并列 Tier 6 质量门, 但入口不同 —— ui-auditor 接 BRIEF 出口, sage-council 接 "已存在的文件 / 组件 / 截图描述"。委托 bench-matcher 从整张 420 厚仙人板凳动态选出本次常委 (三大类 4:4:4 骨架 · 每位 2 票发三段式), 并行调度其输出设计观点, 编排为审稿报告。.

SuanFishXYY/suanfish-design-system · 168 tokens

ui-auditor

审计任何 UI 改动、合并前最终签收、检测反模式时使用本 agent。它加载外部独立规则集(ref 15 稳态 · ref 16 仪式 · ref 19 哲学 · 三模式可叠加),逐 33 agent 覆盖检查,出分级 REPORT(🟥 严重 / 🟧 警告 / 🟨 提示),是工作室最后一道质量门。规则集不归它拥有,它只执行。v2.5 起识别 AI-native 模式并强制走 Path G 四原则自检。.

SuanFishXYY/suanfish-design-system · 139 tokens

quotation-verifier

Agent "quotation-verifier" from SuanFishXYY/suanfish-design-system, covering 🔍 quotation-verifier · 引用真实性核验员, 立场, 工作位置, 核验四步 and step 1 · 解析 bench-matcher 输出.

SuanFishXYY/suanfish-design-system · 186 tokens