Agent
INTERNAL — verifies one receipted abuse-case candidate end-to-end against bounded candidate metadata and targeted code evidence.
Claude Code plugin for code-anchored threat modeling and security architecture review.
Agent
INTERNAL — verifies one receipted abuse-case candidate end-to-end against bounded candidate metadata and targeted code evidence.
Agent
INTERNAL — controller-dispatched actor discovery after config/IaC scanning and before architecture modeling; writes .actors-discovered.json and is skipped in quick mode.
Agent
INTERNAL — Stage 4 of the create-threat-model skill. Rewrites the prose of an assembled threat model for clarity and consistency, and changes nothing else. Reads the bounded projection at .dispatch-context/editorial/blocks.json and writes one plan to .dispatch-context/editorial/plan.json; applyeditorialplan.py…
Agent
INTERNAL context-v2 role that converts validated recon and topology evidence into the bounded architecture-stage artifacts for Phases 3 through 6.
Agent
Standalone AuthN/AuthZ analyzer. Consumes deterministic scanner output (sourceauthscanner, authzconfirm, routeinventory) and optional requirements violations to produce a cross-component authentication and authorization threat report. Runs as part of the authnz-review skill or as a post-Phase-9 deepener.
Agent
INTERNAL — controller-dispatched configuration and IaC analysis after recon and before STRIDE fan-out; emits contracted findings from supported deployment and package surfaces.
Agent
INTERNAL — controller-dispatched context resolver for approved external context, business context, and bounded repository documents; writes .threat-modeling-context.md.
Agent
INTERNAL context-v2 role that evaluates validated architecture and control evidence and writes only Phase-8 controls and bounded STRIDE semantic context.
Agent
Semantic-quality judge for a threat-model run, used by the eval-threat-model dev/test skill (NOT in the create-threat-model phase map). Two modes: JUDGE surfaces candidate quality defects for one rubric dimension from a pre-digested brief; VERIFY adversarially refutes another judge's candidates (refute-by-default)…
Agent
INTERNAL context-v2 role that judges the controller-selected evidence sample from bounded receipted source windows.
Agent
INTERNAL — lightweight repair executor for the create-threat-model re-render loop; rewrites only planned fragments and reruns deterministic composition without analysis stages.
Agent
INTERNAL specialist for Stage-2 Management Summary fragments. Authors only management-summary inputs; the controller owns composition and shared stage state.
Agent
INTERNAL context-v2 role for the bounded qualitative mitigation splits, additions, and cross-finding tier root-cause synthesis that deterministic post-STRIDE scripts cannot derive.
Agent
INTERNAL — exceptional Stage-3 semantic triage after the deterministic QA gate. Consumes a compact repair plan; never repeats the full mechanical detector battery.
Agent
INTERNAL — controller-dispatched repository reconnaissance for structure, technology, and security-relevant code signals; writes $OUTPUTDIR/.recon-summary.md.
Agent
Security reviewer for a single code change. Reads the diff, works out which security expectations it implicates, and grades the post-change code PASS/PARTIAL/FAIL/UNVERIFIABLE/NOTAPPLICABLE with file:line evidence and a code-aware fix → .requirements-verification.json. Grades against the active standard: the company…
Agent
INTERNAL — dispatched on request when APPSECPLUGINDEV=1, either from the offer after a create-threat-model run's completion summary or from /appsec-advisor:diagnose-run. Reads the deterministic .run-issues.json, decides per issue whether the symptom is a defect in this plugin or an environment/expected condition, and…
Agent
INTERNAL specialist for the Stage-2 Security Architecture fragment. Authors only evidence-grounded prose in security-architecture.md; the controller owns composition and shared stage state.
Agent
INTERNAL context-v2 — bounded STRIDE for one component.
Agent
INTERNAL — controller-dispatched STRIDE fan-in reviewer for bounded merge candidates; emits merge, keep, or consolidate decisions without performing STRIDE analysis.
Agent
INTERNAL renderer for Stage 2 of create-threat-model. Invoke only from the skill after Stage 1 has produced validated intermediate artifacts.
Agent
INTERNAL — controller-dispatched cross-component threat triage; validates rating consistency and prioritization, writes .triage-flags.json, and annotates .threats-merged.json.
Agent
INTERNAL — dedicated Stage-1b analyst. Assesses deterministic crossing signals in a fresh context and writes only untrusted trust-boundary candidates and explicit signal dispositions.