Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/itdojp/ae-framework/securitygit clone --depth 1 https://github.com/itdojp/ae-frameworkWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00654 |
| Opus 5 | $0.00000 | $0.00327 |
| Sonnet 5 | $0.00000 | $0.00131 |
| Haiku 4.5 | $0.00000 | $0.00065 |
Grade A, and why
security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Agents Runbook: Security
🌍 Language / 言語: English | 日本語
English
When to use
- when security-oriented jobs fail, including scan, audit, and secrets lanes
- when dependency updates need a minimum security review before requesting a merge
What to load (primary sources)
SECURITY.mddocs/security/security-assurance-lane.mddocs/ci/automation-permission-boundaries.mddocs/ci/OPT-IN-CONTROLS.md
Commands (copy/paste)
pnpm -s run verify:security
pnpm -s run security:scan
pnpm -s run security:audit
pnpm -s run security:secrets
Artifacts to check
artifacts/security/*artifacts/sbom/*- Step Summary from security-oriented workflows
Escalation / follow-up
- even when you suspect a false positive, record the exclusion rationale in the PR or incident log
- for high-risk changes, record
run-securitylabel usage together with the latestpolicy-gateresult - when a secrets finding or a high-severity dependency issue is confirmed, stop merge progression and escalate through the repository security process in
SECURITY.md
日本語
When to use
- セキュリティ系ジョブ(scan / audit / secrets)の失敗対応を行うとき
- 依存更新時に、merge 依頼前の最低限の安全確認を行うとき
What to load (primary sources)
SECURITY.mddocs/security/security-assurance-lane.mddocs/ci/automation-permission-boundaries.mddocs/ci/OPT-IN-CONTROLS.md
Commands (copy/paste)
pnpm -s run verify:security
pnpm -s run security:scan
pnpm -s run security:audit
pnpm -s run security:secrets
Artifacts to check
artifacts/security/*artifacts/sbom/*- Security 系 workflow の Step Summary
Escalation / follow-up
- 誤検知の可能性がある場合でも、除外根拠を PR または incident log に明記する
- 高リスク変更では、
run-securityラベル運用と最新のpolicy-gate判定結果をあわせて記録する - secrets 検知や high-severity dependency issue が確定した場合は、merge を止めて
SECURITY.mdの repository security process に従って escalate する
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 93 lines · 0 tokens per session scan A f73255c37104
security is an agent published in the GitHub repository itdojp/ae-framework (2 stars, last pushed 1mo ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 654 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
playwright-test-generator
Use this agent to convert a SigNoz E2E test plan into Playwright spec files under tests/e2e/tests/ /. Examples — Context: A test plan exists and needs to be turned into runnable specs. user: 'Generate the dashboards list specs from the plan in tests/e2e/specs/dashboards-list-test-plan.md' assistant: 'Using the…
playwright-test-healer
Use this agent to debug and fix failing SigNoz E2E Playwright tests. Examples — Context: A spec is red. user: 'tests/e2e/tests/dashboards/list.spec.ts is failing, fix it' assistant: 'Using the healer agent to debug each failing scenario and adjust the spec.' Context: After a frontend change a previously-green spec…
playwright-test-planner
Use this agent to create a comprehensive E2E test plan for a SigNoz frontend feature. Examples — Context: A new feature has shipped and we need test coverage. user: 'Plan E2E tests for the alerts list page' assistant: 'I'll use the planner agent to read the relevant frontend source, navigate the page in a real…
codex
Production OpenAI-Codex-capable rootfs/initramfs.
claude
Production Claude-capable rootfs/initramfs.
doc-style
Markdown documentation prose — RFCs, ADRs, files under docs/, and READMEs — follows the same one-paragraph-per-line rule as commit messages. Write each paragraph on a single line; do not hard-wrap prose to a fixed column. The renderer reflows it to the reader's display width, whereas manual mid-paragraph line breaks…