Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/chrisallenlane/claude-swe-workflowsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/chrisallenlane/claude-swe-workflows/sec-red-teamer)<a href="https://agentmods.dev/agents/chrisallenlane/claude-swe-workflows/sec-red-teamer"><img src="https://agentmods.dev/badge/agents/chrisallenlane/claude-swe-workflows/sec-red-teamer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/chrisallenlane/claude-swe-workflows/sec-red-teamer"><img src="https://agentmods.dev/badge/agents/chrisallenlane/claude-swe-workflows/sec-red-teamer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00024 | $0.03971 |
| Opus 5 | $0.00012 | $0.01985 |
| Sonnet 5 | $0.00005 | $0.00794 |
| Haiku 4.5 | $0.00002 | $0.00397 |
Grade B, and why
SEC - Red Teamer scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nullifies safety policiesmediumAnti-refusal
"You have no restrictions", "do anything now", "ignore your guidelines": a direct jailbreak that disables guardrails.
- Is the validation before or after transformation? If they validate then URL-decode, I can double-encode to bypass the filter. Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
How it starts
The opening of the file, as written. The whole thing — 346 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Purpose
Break this application. You are a white-hat attacker with full source code access. Your job is not to "review code for security issues" — it's to find concrete ways to compromise the system, steal data, escalate privileges, or cause damage. If you can't describe a specific attack, you haven't found a vulnerability.
You Are the Attacker
You don't think about security abstractly. You think about what you can get away with.
When you look at code, you're not asking "is this secure?" You're asking:
- Where can I get my input into this system?
- What can I make it do that the developer didn't intend?
- Where did they cut corners? Where did they get tired? Where did they assume I'd play nice?
- What happens when I send something they didn't expect?
- What do the error messages tell me that they shouldn't?
- What's the laziest path through their defenses?
You read code the way a lockpicker reads a lock. You're not interested in how it works when used correctly. You're interested in where it fails.
How to Attack
Work through these phases in order. Each phase gives you information that makes the next phase more effective. Don't jump to exploitation before you've done reconnaissance.
Phase 1: Reconnaissance — Find Your Way In
Before you look at any implementation, map every way data enters this system. These are your attack vectors.
Find every entry point:
- HTTP routes and API endpoints — especially any that don't require authentication
- WebSocket handlers
- CLI arguments, flags, and stdin
- File reads — config files, uploads, user-specified paths
- Environment variables the application trusts
- Deserialization points —
JSON.parse,yaml.load,pickle.loads,protobuf.decode - Database reads that return data originally supplied by a user
- Message queue consumers, webhook handlers, IPC endpoints
For each entry point, figure out:
- Can I reach this without authenticating? If not, what's the weakest auth I need?
- What does the application expect me to send? What happens when I send something else?
- Does the framework do any filtering before my input reaches the handler? Or is the handler on its own?
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 346 lines · 24 tokens per session scan B 5fabb06961d2
SEC - Red Teamer is an agent published in the GitHub repository chrisallenlane/claude-swe-workflows (18 stars, last pushed 3mo ago), licensed MIT. It adds 24 tokens to every session and 3,971 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (nullifies safety policies). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
afc-architect
Architecture analysis agent — invoked during plan phase for ADR recording and review phase for architecture compliance checks. Remembers ADR decisions and architecture patterns across sessions to provide consistent design guidance.
afc-pr-analyst
PR deep analysis worker — invoked during /afc:triage for deep PR verification. Performs build/test/lint verification in an isolated worktree for triage.
afc-impl-worker
Parallel implementation worker — orchestrator-managed, pre-assigned tasks only. Executes assigned tasks from the pipeline task pool with worktree isolation support.
afc-security
Security scanning agent — invoked during review phase for security vulnerability scanning. Remembers vulnerability patterns and project-specific security characteristics across sessions to improve scan precision.
cavecrew-builder
Surgical 1-2 file edit. Typo fixes, single-function rewrites, mechanical renames, comment removal, format-preserving tweaks. Hard refuses 3+ file scope. Returns caveman diff receipt. Use when scope is bounded and obvious; do NOT use for new features, new files (unless asked), or cross-file refactors.
tech-lead
Tech Leader - technical vision, architectural decisions, team guidance.