security-auditor

A security-focused code-analysis agent that searches a project for vulnerabilities in areas such as user input, login systems, permissions, secrets, file paths, unsafe data handling, and cryptography.

In plain words
What is it for?
Use it to review SQL queries, forms and APIs, uploads, passwords and sessions, role checks, resource ownership, tokens, deserialization, path traversal, encryption, and other security-sensitive code.
Why use it?
It helps reveal security weaknesses in the code and records where they occur, how serious they are, and how to address them.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/agricidaniel/claude-code-essentials-vs-code/security-auditor
Clone the repo
git clone --depth 1 https://github.com/AgriciDaniel/claude-code-essentials-vs-code
Per session 9 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 173 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00009 $0.00173
Opus 5 $0.00005 $0.00086
Sonnet 5 $0.00002 $0.00035
Haiku 4.5 $0.00001 $0.00017

Measured 2d ago against content hash 001318763dda, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

security-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

templates/agents/security-auditor.md · 26 lines

What it actually says

You are a security audit agent. Analyze code for vulnerabilities:

  1. Search for SQL query patterns (raw queries, string concatenation)
  2. Find user input handling (forms, APIs, file uploads)
  3. Check authentication logic (password handling, session management)
  4. Review authorization checks (role-based access, resource ownership)
  5. Identify secrets handling (API keys, tokens, passwords)
  6. Look for unsafe deserialization
  7. Check for path traversal vulnerabilities
  8. Review cryptographic implementations

Rate each finding: Critical / High / Medium / Low

Output as security report with:

  • Vulnerability description
  • File and line number
  • Severity rating
  • Remediation steps
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 26 lines · 9 tokens per session scan A 001318763dda

Subscribe to this mod's changes

security-auditor is an agent published in the GitHub repository AgriciDaniel/claude-code-essentials-vs-code (57 stars, last pushed 4mo ago), licensed MIT. It adds 9 tokens to every session and 173 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

verifier

Fresh-context, read-only verifier for a proposed claude-obsidian change or release. Inspects the requested staged diff, unstaged worktree, explicit paths, or existing release artifact; runs safe deterministic tests and contracts; and reports evidence-ranked findings without modifying Git or repository state.

AgriciDaniel/claude-obsidian · 60 tokens

wiki-ingest

Read-only ingestion worker for one already-captured source. Reads the assigned source and relevant vault context, then returns evidence-grounded page drafts, expected hashes, and proposed paths to the parent orchestrator. It never writes or applies the shared transaction.

AgriciDaniel/claude-obsidian · 53 tokens

wiki-lint

Read-only interpreter for the deterministic portable vault linter. Runs the linter against an explicitly selected vault or scope, validates surprising findings against source pages, and returns a structured health report. It never writes reports or repairs the vault.

AgriciDaniel/claude-obsidian · 50 tokens

visual-architect

Freeze a visual brief and compile bounded, model-aware prompts for complex, branded, text-heavy, or ambiguous image work. Use only when the main banana skill supplies the user request, current model constraints, and any references. Never execute generation.

AgriciDaniel/banana-claude · 52 tokens

visual-critic

Independently inspect generated or edited image files against a frozen brief. Use after generation for high-value, branded, text-heavy, edited, or multi-candidate work. Never generate, edit, or rewrite files.

AgriciDaniel/banana-claude · 47 tokens

audit-amazon

Amazon Ads evidence and controls specialist. Returns schema-valid findings for profiles and regions, portfolios, Sponsored Products, Brands, Display, DSP, search-term harvesting, retail readiness, ACOS, TACOS, and reporting.

AgriciDaniel/claude-ads · 47 tokens