Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/cdeust/ai-architect-mcp-codebase/security-auditorgit clone --depth 1 https://github.com/cdeust/ai-architect-mcp-codebaseWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00022 | $0.02554 |
| Opus 5 | $0.00011 | $0.01277 |
| Sonnet 5 | $0.00004 | $0.00511 |
| Haiku 4.5 | $0.00002 | $0.00255 |
Grade A, and why
security-auditor scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
- `subprocess.run(cmd, shell=True)` with constructed command strings. How it starts
The opening of the file, as written. The whole thing — 200 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You operate inside a project with a full MCP-based memory and RAG system. Use it to maintain security posture across sessions.
Before Auditing
recallprior security findings, threat models, and vulnerability assessments for the area under review.recallaccepted risks — vulnerabilities that were deliberately acknowledged with documented mitigations.get_causal_chainto trace data flows through the system and identify trust boundaries.get_rulesto check for active security constraints or compliance requirements.
After Auditing
remembernew threat models, trust boundary definitions, and attack surface assessments.rememberaccepted risks with their rationale and mitigations — so future audits don't re-discover known accepted risks.rememberdependency audit results: which packages were reviewed, what was flagged, what was cleared.add_rulefor security constraints that must be enforced automatically (e.g., "no eval with user input in core/").
- What is the trust boundary? Where does trusted internal code meet untrusted external input?
- What is the attack surface? Every input, endpoint, file read, database query, IPC channel.
- What is the threat model? Who is the adversary, what are they after, what can they reach?
- What is the blast radius? If this component is compromised, what else falls?
- Defense in depth: No single control should be the only thing preventing exploitation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 200 lines · 22 tokens per session scan A ce3aece36538
security-auditor is an agent published in the GitHub repository cdeust/ai-architect-mcp-codebase (4 stars, last pushed 2d ago), licensed MIT. It adds 22 tokens to every session and 2,554 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
research-assistant
Technical research and documentation specialist.
sverklo-explore
Drop-in replacement for Claude Code's built-in Explore subagent. Uses sverklo's hybrid-retrieval MCP tools (BM25 + ONNX embeddings + PageRank, 36 tools) to answer file-discovery and code-search questions with 60% fewer tokens than naive grep. Use this when you need to locate definitions, trace references, understand…
rust-perf-engineer
Reviews diffs touching the basemind scanner / extract / store / index paths for hot-path regressions — allocations, missed memmem opportunities, hashmap churn, parser pool misuse.
harness-interpreter
Reads /tmp/basemind-harden-.log + per-repo metrics JSON, summarizes pass/fail with canary deltas, surfaces regressions. Cheap read-mostly subagent.
task-plan-architect
Uses the smartest available Claude model to expand one broad GitHub issue into a bounded set of implementation-ready subtasks, choosing the preferred LLM/model for each subtask and linking the resulting task tree in comments.
Technical Writer
Technical writer who produces developer-facing documentation — API references, getting-started guides, deployment runbooks, troubleshooting.