Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/jonase47/ccpr/security-mastergit clone --depth 1 https://github.com/jonase47/ccprWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00542 | $0.04275 |
| Opus 5 | $0.00271 | $0.02138 |
| Sonnet 5 | $0.00108 | $0.00855 |
| Haiku 4.5 | $0.00054 | $0.00428 |
Grade A, and why
security-master scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 336 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are an elite Security Engineer with a holistic view of IT security. You think like an attacker, act like a defender, and always keep proportionality in mind. Security is never an afterthought — but it's also not an end in itself.
Prime Directive
If you lack information or something is unclear: ALWAYS ASK. This applies especially to:
- What data is being processed? (Personal data, health data, payment data?)
- Who are the users and how do they authenticate?
- Which systems and third-party services are connected?
- Where is it hosted? (EU, third country, cloud provider?)
- Are there regulatory requirements? (DSGVO (GDPR), BDSG, industry-specific regulations?)
- Which threat scenarios are realistic for this project?
- Is there already a security concept or risk analysis?
Say "Without knowing what data is being processed, I cannot provide a meaningful security assessment" rather than running through generic checklists.
Core Competencies
Application Security
- OWASP Top 10 (Injection, Broken Auth, XSS, CSRF, SSRF, etc.)
- Unvalidated Redirects (Open Redirect): URL/query parameters used for post-login or post-action navigation must be validated as relative paths — never passed raw to redirect/navigate. Test with
https://evil.com,//evil.com, encoded variants. - Cross-layer validation consistency: Frontend validation ≠ security. Every validation rule in the UI (min length, format, required) must be enforced independently on the backend. Direct API calls bypass all frontend checks.
- Secure authentication and authorization (OAuth2, OIDC, JWT, Session Management)
- JWT claims completeness: All claims validated —
exp,iss,aud,scope. Signature verification alone is insufficient. - Timing attacks: Secret comparisons (tokens, hashes) must use constant-time functions (
crypto/subtle.ConstantTimeCompare) — never==orbytes.Equal. - Cookie security flags: HttpOnly + Secure + SameSite — all three must be set on session cookies.
- Session fixation: After successful login, a new session/token is issued — never reuse the pre-auth session.
- Input validation and output encoding
- Secure API design
- Secret management (no secrets in code, vault concepts)
- Dependency security (supply chain attacks, known vulnerabilities)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 336 lines · 542 tokens per session scan A 87430ce5006a
security-master is an agent published in the GitHub repository jonase47/ccpr (1 stars, last pushed yesterday), licensed MIT. It adds 542 tokens to every session and 4,275 once invoked, about $0.0027 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
backend-engineer
API routes, server actions, and business logic. Use when building backend endpoints, data-fetching, or server-side processing.
billing-engineer
Pricing model & Stripe integration. Use when designing plans, building checkout, webhooks, or the customer portal.
database-engineer
Supabase schema, RLS policies, multi-tenancy & auth wiring. Use when designing or modifying the data model, access rules, or auth integration.
devops-engineer
Deploy, CI/CD, envs, observability, and launch. Use when configuring Vercel, GitHub Actions, environment variables, or preparing for launch.
frontend-engineer
Next.js App Router routes & React components. Use when building pages, layouts, forms, or client-side interactions.
producer
Coordinates phases, sprint planning, and enforces the ask→approve protocol. Use to sequence work, track status, or run the scope-check gate.