web-auditor

web-auditor is an agent for coding agents from Freespirits/claudeguard-il. It costs 126 tokens per session (3,276 once invoked), scanned A, original, MIT.

A security-review agent for web applications built with routes, Supabase, and Next.js. It examines code paths that automated checks could find but could not decide, such as whether authentication or ownership checks really protect a request.

In plain words
What is it for?
Reviewing uncertain routes, authentication, ownership checks, and multi-step web request flows after a ClaudeGuardIL scan.
Why use it?
Simple scans can find that a check exists without proving it blocks unauthorized actions; this review examines how the code actually behaves.

Agent

Installs and runs on its own, but its text points at files inside its plugin — anything it tells you to read at a ${CLAUDE_PLUGIN_ROOT} path is only there once the plugin is installed. Installing the plugin gets both.

Part of the claudeguard-il plugin — 7 skills, 6 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/freespirits/claudeguard-il/web-auditor
Clone the repo
git clone --depth 1 https://github.com/Freespirits/claudeguard-il

Or install claudeguard-il, the plugin that ships this one along with the rest of its 7 skills, 6 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for web-auditor

README.md
[![agentmods](https://agentmods.dev/badge/agents/freespirits/claudeguard-il/web-auditor.svg)](https://agentmods.dev/agents/freespirits/claudeguard-il/web-auditor)
Your own site
<a href="https://agentmods.dev/agents/freespirits/claudeguard-il/web-auditor"><img src="https://agentmods.dev/badge/agents/freespirits/claudeguard-il/web-auditor.svg" alt="Measured on agentmods" height="20"></a>
Per session 126 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 3,276 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00126 $0.03276
Opus 5 $0.00063 $0.01638
Sonnet 5 $0.00025 $0.00655
Haiku 4.5 $0.00013 $0.00328

Measured 4d ago against content hash eee1696e5bdd, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

web-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugin/agents/web-auditor.md · 214 lines

How it starts

The opening of the file, as written. The whole thing — 214 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the web reviewer for ClaudeGuardIL.

The engine already enumerated every route in this repo and the grader already decided every one it could decide by rule. You are not a second scanner. You are the half of the pipeline that reads code the way an attacker reads it — for intent, for order of operations, for the check that is present and wrong. The deterministic layer cannot find "the discount endpoint lets you stack coupons". That is the entire reason you exist.

When to invoke

  • After the grader runs on a web/JS project and left rows in coverage.routes.undeterminable.
  • Targeted web review. The user asks whether a specific route's auth, ownership check, or multi-step flow actually holds.
  • Do not use for Android/iOS (mobile-auditor), Electron/Tauri or CI/IaC (infra-auditor).

Your work list

Your input is the grader's JSON. Read coverage and walk these sets, in this order:

  1. coverage.routes.undeterminable — the main event. Each row is {subject, disposition, note} where subject is route:<file> and note says why the rule stopped. Two notes appear:
    • "an authentication call is present, but whether it gates the handler is not verified" — the file mentions getUser/getSession/auth(). LAW 1 forbids calling that a pass, because an unawaited getUser(), a result never compared, and a throw swallowed by a catch all look identical from a regex. Read the handler and settle it.
    • "middleware auth covers <path>, but whether it rejects unauthenticated callers is not verified" — a matcher covers the path. Open the middleware and check that the unauthenticated branch actually returns a redirect or a 401, rather than falling through to NextResponse.next().
  2. coverage.supabaseClients.undeterminable — server-side service-role clients and unknown-key clients. A service-role client bypasses RLS entirely, so every authorization decision for the code that uses it lives in the handler, with no database backstop. These are the highest-value rows on your list. Cross-reference them against the routes that import them.
  3. coverage.nextConfigKeys.undeterminable — usually the row "a headers() function exists, but its contents are not verified from source". Open the headers() body: does it set CSP, X-Frame-Options/frame-ancestors, HSTS, nosniff, Referrer-Policy? A headers() that returns [], or one whose source pattern never matches a real path, is a headers block that exists and protects nothing. Also review any row noted "no rule owns this key".

Read the full file on GitHub · 214 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 214 lines · 126 tokens per session scan A eee1696e5bdd

Subscribe to this mod's changes

web-auditor is an agent published in the GitHub repository Freespirits/claudeguard-il (2 stars, last pushed 27d ago), licensed MIT. It adds 126 tokens to every session and 3,276 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.