Kaademos/secure-sdlc-agents

A team of Claude Code sub-agents that enforce security across the full SDLC, from ASVS requirements and threat modelling to SAST triage, IaC review, compliance attestation and release sign-off. Drop into any project. No security team required.

13Stars on the repository
16Mods indexed here, across every type
1mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

Kaademos/secure-sdlc-agents

Agent Claude Code

AI/LLM Security Engineer. Specialist in the security risks unique to AI and LLM-powered features: prompt injection, indirect prompt injection, model poisoning, agentic trust boundaries, AI supply chain, output validation, and PII leakage to external model APIs. References OWASP Top 10 for LLMs 2025 and emerging 2026…

13 1mo ago B 195 tokens original MIT

appsec-engineer

02

Kaademos/secure-sdlc-agents

Agent Claude Code

Application Security Engineer. Performs threat modelling, reviews code for security vulnerabilities, triages SAST/DAST findings, coordinates penetration testing, and provides remediation guidance. This is the primary security SME throughout the SDLC. Use this agent when: A new architecture or significant feature…

13 1mo ago A 128 tokens original MIT

Kaademos/secure-sdlc-agents

Agent Claude Code

Cloud and Platform Security Engineer. Reviews infrastructure-as-code for misconfigurations, enforces secrets management practices, performs CSPM-style checks, validates runtime hardening, and ensures the deployment pipeline is secure. Use this agent when: Reviewing Terraform, Pulumi, CloudFormation, Helm, or…

13 1mo ago A 128 tokens original MIT

dev-lead

04

Kaademos/secure-sdlc-agents

Agent Claude Code

Secure Development Lead. Enforces secure coding standards, reviews pull requests for security issues, manages software composition analysis (SCA / dependency review), and implements fixes for vulnerabilities identified by AppSec. The bridge between security findings and developer-ready solutions. Use this agent when…

13 1mo ago A 121 tokens original MIT

grc-analyst

05

Kaademos/secure-sdlc-agents

Agent Claude Code

Governance, Risk and Compliance Analyst. Maintains the risk register, maps security controls to compliance frameworks, collects audit evidence, and produces compliance attestations. Participates at the Plan, Design, Test and Release phases. Use this agent when: A new project requires a compliance framework mapping A…

13 1mo ago A 113 tokens original MIT

product-manager

06

Kaademos/secure-sdlc-agents

Agent Claude Code

Secure Product Manager. Elicits and documents security requirements by mapping user stories and acceptance criteria to OWASP ASVS controls. Engages stakeholders to surface implicit security expectations. Should be invoked at the start of every feature or sprint to produce a security requirements document before design…

13 1mo ago A 118 tokens original MIT

release-manager

07

Kaademos/secure-sdlc-agents

Agent Claude Code

Security-focused Release Manager. Executes the pre-release security checklist, aggregates sign-offs from all other agents, and issues a formal go/no-go decision. The final gate before any code reaches production. Use this agent when: A release candidate is ready and requires a security sign-off Running a pre-release…

13 1mo ago A 101 tokens original MIT

security-champion

08

Kaademos/secure-sdlc-agents

Agent Claude Code

Security Champion — a developer-level security advocate embedded in the squad. Provides first-line security guidance, answers quick security questions, reviews small changes informally, and coaches developers on secure patterns. Lower friction than a full appsec review; higher throughput for day-to-day questions. Use…

13 1mo ago A 161 tokens original MIT