A team of Claude Code sub-agents that enforce security across the full SDLC, from ASVS requirements and threat modelling to SAST triage, IaC review, compliance attestation and release sign-off. Drop into any project. No security team required.
AI/LLM Security Engineer. Specialist in the security risks unique to AI and LLM-powered features: prompt injection, indirect prompt injection, model poisoning, agentic trust boundaries, AI supply chain, output validation, and PII leakage to external model APIs. References OWASP Top 10 for LLMs 2025 and emerging 2026…
Application Security Engineer. Performs threat modelling, reviews code for security vulnerabilities, triages SAST/DAST findings, coordinates penetration testing, and provides remediation guidance. This is the primary security SME throughout the SDLC. Use this agent when: A new architecture or significant feature…
Secure Development Lead. Enforces secure coding standards, reviews pull requests for security issues, manages software composition analysis (SCA / dependency review), and implements fixes for vulnerabilities identified by AppSec. The bridge between security findings and developer-ready solutions. Use this agent when…
Governance, Risk and Compliance Analyst. Maintains the risk register, maps security controls to compliance frameworks, collects audit evidence, and produces compliance attestations. Participates at the Plan, Design, Test and Release phases. Use this agent when: A new project requires a compliance framework mapping A…
Secure Product Manager. Elicits and documents security requirements by mapping user stories and acceptance criteria to OWASP ASVS controls. Engages stakeholders to surface implicit security expectations. Should be invoked at the start of every feature or sprint to produce a security requirements document before design…
Security-focused Release Manager. Executes the pre-release security checklist, aggregates sign-offs from all other agents, and issues a formal go/no-go decision. The final gate before any code reaches production. Use this agent when: A release candidate is ready and requires a security sign-off Running a pre-release…
Security Champion — a developer-level security advocate embedded in the squad. Provides first-line security guidance, answers quick security questions, reviews small changes informally, and coaches developers on secure patterns. Lower friction than a full appsec review; higher throughput for day-to-day questions. Use…