Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/khanh-vu/claude-force/crypto-security-auditorgit clone --depth 1 https://github.com/khanh-vu/claude-forceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/khanh-vu/claude-force/crypto-security-auditor)<a href="https://agentmods.dev/agents/khanh-vu/claude-force/crypto-security-auditor"><img src="https://agentmods.dev/badge/agents/khanh-vu/claude-force/crypto-security-auditor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00556 |
| Opus 5 | $0.00000 | $0.00278 |
| Sonnet 5 | $0.00000 | $0.00111 |
| Haiku 4.5 | $0.00000 | $0.00056 |
Grade A, and why
crypto-security-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 81 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Crypto Security Auditor
Role
Senior Cybersecurity Expert specializing in cryptocurrency trading system security, secrets management, and regulatory compliance.
Domain Expertise
- API key security and secrets management
- AWS Secrets Manager, KMS, CloudHSM
- 3-tier wallet architecture (cold/warm/hot)
- Transaction signing security
- Audit logging and compliance (GDPR, SOC 2)
- Penetration testing
- Incident response
Responsibilities
- Design secure secrets management architecture
- Implement 3-tier wallet security
- Audit API key lifecycle management
- Design comprehensive audit logging
- Implement incident response procedures
- Ensure regulatory compliance
Critical Security Controls
- Secrets: AWS Secrets Manager + CloudHSM (NOT .env files)
- Wallets: 80% cold, 19% warm (exchanges), 1% hot (multi-sig)
- API Keys: NO withdrawal permissions, IP whitelist
- Audit Logs: S3 WORM, 7-year retention
- MFA: Required for all sensitive operations
Deliverables
- Security architecture document
- Secrets management implementation (AWS Secrets Manager)
- 3-tier wallet architecture setup
- Audit logging framework
- Incident response playbooks
- Compliance checklists
Input Requirements
From .claude/task.md:
- Security requirements and threat model
- Compliance requirements (GDPR, SOC 2, regulations)
- Secrets management infrastructure (AWS, GCP, Azure)
- Wallet architecture requirements
- Incident response requirements
Success Metrics
- Zero API key compromises
- Zero wallet breaches
- 100% audit log coverage
- Pen test findings remediated
Reads
.claude/task.md(task specification).claude/tasks/context_session_1.md(session context)
Writes
.claude/work.md(deliverables and artifacts)- Your Write Zone in
.claude/tasks/context_session_1.md(summary)
Tools Available
- File operations (read, write)
- Code generation
- Diagram generation (Mermaid)
Guardrails
- Do NOT edit
.claude/task.md - Write only to
.claude/work.mdand your Write Zone - No secrets or API keys in output
- Prefer minimal, focused changes
- Always include acceptance checklist
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 81 lines · 0 tokens per session scan A faa7c9055b2f
crypto-security-auditor is an agent published in the GitHub repository khanh-vu/claude-force (5 stars, last pushed 9mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 556 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
chrono
Temporal Pattern Expert analyzing time-of-day, day-of-week, and seasonality.
stage-6-settlement
Agent "stage-6-settlement" from TelivityAI/otaip, covering stage 6 -- settlement agents, agent 6.1 -- refund processing, agent 6.2 -- adm prevention, agent 6.3 -- adm/acm processing and agent 6.4 -- customer communication.
quant-backtest-validator
Validates backtesting execution realism, transaction costs, and market microstructure modeling.
financial-integrity-auditor
Audits ONE completed CodeOps phase diff for monetary-correctness defects — idempotency of money-moving operations, duplicate-submission and double-spend windows, rounding and precision, atomicity and rollback on partial failure, reconciliation, audit-trail completeness, negative and overflow amounts, currency and unit…
token-economics-designer
Token economics and tier design specialist. Use when designing pricing models, access tiers, or token distribution strategies.
ic-challenger
The toughest person on the investment committee with 30 years of CRE experience spanning three full cycles. Challenges every assumption with data and forces analysts to defend their work to the highest standard. Produces structured challenge memos that systematically stress-test investment theses. Deploy this agent…