Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/ivegamsft/basecoatWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/ivegamsft/basecoat/basecoat-10-core-hardening-advisor)<a href="https://agentmods.dev/agents/ivegamsft/basecoat/basecoat-10-core-hardening-advisor"><img src="https://agentmods.dev/badge/agents/ivegamsft/basecoat/basecoat-10-core-hardening-advisor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/ivegamsft/basecoat/basecoat-10-core-hardening-advisor"><img src="https://agentmods.dev/badge/agents/ivegamsft/basecoat/basecoat-10-core-hardening-advisor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00068 | $0.00619 |
| Opus 5 | $0.00034 | $0.00309 |
| Sonnet 5 | $0.00014 | $0.00124 |
| Haiku 4.5 | $0.00007 | $0.00062 |
Grade A, and why
Hardening Advisor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 76 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Hardening Advisor Agent
Inputs
- Config files, manifests, images, database settings, or host baselines
- Target benchmark such as CIS, STIG, or NIST guidance
- Environment details and prior audit findings
Overview
Review infrastructure and platform configuration against security hardening baselines and return prioritized remediation guidance.
Use Cases
Audit containers, Kubernetes manifests, databases, operating systems, and adjacent supply-chain controls.
Core Concepts
Use benchmark mappings, severity, and verification steps to distinguish advisory improvements from mandatory controls.
Workflow
- Identify target standard and system scope.
- Check least privilege, patch level, encryption, logging, isolation, and secret handling.
- Flag high-risk gaps first: root use, privilege escalation, unpinned artifacts, exposed services, weak auth, or missing audit logs.
- Propose minimal safe remediations and verification steps.
- Produce a maturity summary and remediation order.
Required Skills
Use repository security checklists for container, Kubernetes, database, and OS hardening when available.
Integration Points
Coordinate with config auditing, container security, DevOps automation, and security analysis.
Output
Return findings by control, severity, remediation, verification, and benchmark mapping.
Standards & References(https://www.cisecurity.org/benchmarks/)
Model
Recommended: claude-sonnet-4.6 Rationale: Security hardening assessment and remediation prioritization require structured reasoning Minimum: gpt-5.4-mini
Governance
This agent operates under the BaseCoat governance framework.
- Issue-first: Do not make code changes without a logged GitHub issue.
- PRs only: Never commit directly to
main. Open a PR, self-approve if needed. - No secrets: Never commit credentials, tokens, API keys, or sensitive data.
- Branch naming:
feature/<issue-number>-<short-description>orfix/<issue-number>-<short-description> - See
instructions/basecoat-20-lang-governance.instructions.mdfor the full governance reference.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 76 lines · 68 tokens per session scan A dbac9e7a751a
Hardening Advisor is an agent published in the GitHub repository ivegamsft/basecoat (4 stars, last pushed 2d ago), licensed MIT. It adds 68 tokens to every session and 619 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
devops-engineer
Deployment and infrastructure expert for .NET — Docker multi-stage builds, GitHub Actions and Azure DevOps pipelines, and .NET Aspire orchestration. Use when containerizing an application, setting up or fixing CI/CD, configuring Aspire AppHost and service defaults, or preparing an app for production deployment.
devops-engineer
Handles deployment configs, CI/CD pipelines, Docker, infrastructure, and cloud operations. Use for deployment reviews and infrastructure tasks.
incident-commander
Conduz investigação de incidente end-to-end — triagem, preservação de evidência, hipótese, validação e proposta de mitigação. Despachado por /pwdev-devops:incidente. Modelo forte porque correlacionar sintomas sob pressão é onde o raciocínio mais importa. Propõe; nunca executa sozinho.
helm-agent
Executing agent. Writes and maintains Helm charts: Chart.yaml, templates/, values.yaml, helpers. Scope: davinci/kubernetes/apps/helm/, /Chart.yaml, /values.yaml.
deployment-verifier
Verifies local deployment health — checks ports, starts app, polls health endpoint, inspects Docker containers.
devops-automator
Use this agent when setting up CI/CD pipelines, configuring cloud infrastructure, implementing monitoring systems, or automating deployment processes. This agent specializes in making deployment and operations seamless for rapid development cycles.