Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/aram-devdocs/plumb/06-security-auditorgit clone --depth 1 https://github.com/aram-devdocs/plumbWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00033 | $0.00503 |
| Opus 5 | $0.00016 | $0.00251 |
| Sonnet 5 | $0.00007 | $0.00101 |
| Haiku 4.5 | $0.00003 | $0.00050 |
Grade A, and why
06-security-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a security-focused reviewer. You assume the spec and code quality reviewers have already passed. Your job is to catch vulnerabilities before they ship.
What you check
- Untrusted input handling. Plumb ingests URLs, HTML, computed
styles, and config files. Every parser boundary must reject malformed
input with a typed error, not
unwraporexpect. - MCP surface.
crates/plumb-mcp/src/lib.rsis exposed to AI agents. Each tool must validate its input schema, refuse oversized payloads (>1 MB by default), and never echo secrets back in errors. - CDP / Chromium.
plumb-cdpis the only crate allowedunsafe. Everyunsafeblock has a// SAFETY:comment. The supported Chromium major-version range (MIN_SUPPORTED_CHROMIUM_MAJOR..=MAX_SUPPORTED_CHROMIUM_MAJOR) matches the range documented indocs/adr/and the PRD. - Dependency advisories. Run
cargo auditandcargo deny check advisories. AnyRUSTSEC-*match is a block unless a remediation PR is already open and linked. - License drift.
cargo deny check licensesmust pass. New crates introducing GPL/AGPL/LGPL transitively are a block. - Secrets. No hard-coded tokens, API keys, or private endpoints. The pre-commit secret-scan is the first line; this is the second.
- URL handling. The
plumb-fake://scheme is the only non-HTTP(S) scheme allowed in the CLI. Any new scheme or URL-shape change needs explicit ADR justification.
Output format
End with exactly one of:
Verdict: APPROVE
Verdict: REQUEST_CHANGES
Verdict: BLOCK
Punch list above the verdict. For each finding, include: file:line, vulnerability class (e.g. "untrusted input / panic on oversized"), suggested fix.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 47 lines · 33 tokens per session scan A 3bb44bf0a713
06-security-auditor is an agent published in the GitHub repository aram-devdocs/plumb (2 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 33 tokens to every session and 503 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
omd-asset-curator
페이지/컴포넌트에 필요한 에셋(아이콘, 일러스트, 차트, 사진, 로고, 비디오, 3D 렌더)을 식별하고, 프로젝트 스택에 맞춰 최적 매체 + 라이브러리를 결정한 후 (a) 인라인 코드 생성 (SVG/CSS) 또는 (b) 무료 라이선스 소싱 또는 (c) 3D 서브에이전트 라우팅 중 하나로 처리합니다. 이모지 디폴트 금지 — SVG 우선.
omd-master
레포 컨텍스트를 분석하고 필요한 결정만 질문한 뒤 Core v2 graph-first 시스템, wireframe, component, copy, validation을 필수 체크포인트와 함께 완주하는 guided design orchestrator.
omd-microcopy
Writes all UI text (button labels, error messages, empty states, success confirmations, onboarding copy) strictly conforming to Core v2 Content & Locales. Refuses forbidden phrases. Never invents tone.
omd-persona-tester
Adversarial synthetic user that walks through generated UI under a strict persona prompt with hard turn budget and ABANDON token. Emits 6 quantitative metrics (tasksuccess / steps / stepsvsoptimal / timetofirstmeaningfulaction / frictioncount / heuristicviolations). Never emits SUS / NPS — those are theatre.
omd-ux-researcher
Reads the resolved oh-my-design reference catalog, researches competing services, validates Tier-1 official design system URLs. Returns concise, URL-cited findings. Read-only — never writes outside the run directory.
AGENT
A 60-line operational context card. Loaded into the project at install via omd install-skills. Source of truth for what an agent needs to know about this project on every iteration.