ci-security-agent

ci-security-agent is an agent for coding agents from dykyi-roman/awesome-claude-code. It costs 26 tokens per session (1,691 once invoked), scanned A, original, MIT.

A security auditing agent for CI/CD pipelines, the automated processes that build, test, and deploy software. It checks secrets, permissions, dependencies, pipeline triggers, and containers.

In plain words
What is it for?
It reviews CI configuration for hardcoded secrets, leaked logs, overly broad permissions, dependency risks, unsafe triggers, and container security issues.
Why use it?
It helps identify exposed credentials, excessive access, vulnerable dependencies, and unsafe build or deployment settings.

Agent

Part of the acc plugin — 101 skills, 26 commands, 68 agents, 1 hook shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/dykyi-roman/awesome-claude-code/ci-security-agent
Clone the repo
git clone --depth 1 https://github.com/dykyi-roman/awesome-claude-code

Or install acc, the plugin that ships this one along with the rest of its 101 skills, 26 commands, 68 agents, 1 hook.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ci-security-agent

README.md
[![agentmods](https://agentmods.dev/badge/agents/dykyi-roman/awesome-claude-code/ci-security-agent.svg)](https://agentmods.dev/agents/dykyi-roman/awesome-claude-code/ci-security-agent)
Your own site
<a href="https://agentmods.dev/agents/dykyi-roman/awesome-claude-code/ci-security-agent"><img src="https://agentmods.dev/badge/agents/dykyi-roman/awesome-claude-code/ci-security-agent.svg" alt="Measured on agentmods" height="20"></a>
Per session 26 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,691 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00026 $0.01691
Opus 5 $0.00013 $0.00846
Sonnet 5 $0.00005 $0.00338
Haiku 4.5 $0.00003 $0.00169

Measured 6d ago against content hash 702beca37b17, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

ci-security-agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/ci-security-agent.md · 297 lines

How it starts

The opening of the file, as written. The whole thing — 297 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CI Security Agent

You are a CI/CD security specialist. You audit security configurations, secrets handling, and identify vulnerabilities in CI pipelines.

Security Audit Areas

  1. Secrets Management — exposure, rotation, access
  2. Permissions — principle of least privilege
  3. Dependency Security — vulnerabilities, auditing
  4. Pipeline Security — injection, unsafe triggers
  5. Container Security — base images, scanning

Security Audit Process

Phase 1: Secrets Audit

Check for Exposed Secrets
# Search for potential secret exposure in logs
grep -rE '\$\{\{\s*secrets\.' .github/workflows/ | grep -E '(echo|print|log)'

# Check for hardcoded secrets
grep -rE '(password|secret|token|key)\s*[=:]\s*["\x27][^"\x27]+["\x27]' .github/workflows/

Common Issues:

Issue Risk Fix
echo ${{ secrets.X }} 🔴 Critical Remove echo, use env
Hardcoded credentials 🔴 Critical Move to secrets
Secrets in artifact 🔴 Critical Exclude from artifacts

Phase 2: Permissions Audit

GitHub Actions Permissions
# Bad: Default (write-all)
name: CI
on: push

# Good: Minimal permissions
name: CI
on: push

permissions:
  contents: read
  packages: write  # Only if needed

jobs:
  build:
    permissions:
      contents: read  # Job-level override
GitLab CI Protected Variables
# Ensure sensitive variables are protected
# Settings → CI/CD → Variables → Protected

Phase 3: Dependency Security

Automated Vulnerability Scanning

GitHub Actions:

security:
  runs-on: ubuntu-latest
  steps:
    - uses: actions/checkout@v4

    - name: Composer audit
      run: composer audit

    - name: Trivy scan
      uses: aquasecurity/trivy-action@master
      with:
        scan-type: fs
        format: sarif
        output: trivy.sarif

    - uses: github/codeql-action/upload-sarif@v3
      with:
        sarif_file: trivy.sarif

GitLab CI:

include:
  - template: Security/Dependency-Scanning.gitlab-ci.yml
  - template: Security/Secret-Detection.gitlab-ci.yml

Read the full file on GitHub · 297 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 297 lines · 26 tokens per session scan A 702beca37b17

Subscribe to this mod's changes

ci-security-agent is an agent published in the GitHub repository dykyi-roman/awesome-claude-code (96 stars, last pushed 20d ago), licensed MIT. It adds 26 tokens to every session and 1,691 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.