security-production-agent

security-production-agent is an agent for coding agents from LarouexNonprofitConsulting/larouex-fullstack-plugin. It costs 0 tokens per session (1,710 once invoked), scanned A, original, MIT.

A security and production-operations helper for a web platform. It focuses on protecting secrets and user access, resolving live errors, recovering from incidents, and keeping deployments safe.

In plain words
What is it for?
Use it to protect environment variables and API keys, configure authentication and browser security policies, investigate 403, 404, and 500 errors, validate releases, roll back deployments, and manage recovery procedures.
Why use it?
It gives a defined response for common production problems such as failed requests, slow performance, caching issues, certificate problems, and unsafe configuration.

Agent

Part of the larouex-fullstack-builder plugin — 80 commands, 12 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/larouexnonprofitconsulting/larouex-fullstack-plugin/security-production-agent
Clone the repo
git clone --depth 1 https://github.com/LarouexNonprofitConsulting/larouex-fullstack-plugin

Or install larouex-fullstack-builder, the plugin that ships this one along with the rest of its 80 commands, 12 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-production-agent

README.md
[![agentmods](https://agentmods.dev/badge/agents/larouexnonprofitconsulting/larouex-fullstack-plugin/security-production-agent.svg)](https://agentmods.dev/agents/larouexnonprofitconsulting/larouex-fullstack-plugin/security-production-agent)
Your own site
<a href="https://agentmods.dev/agents/larouexnonprofitconsulting/larouex-fullstack-plugin/security-production-agent"><img src="https://agentmods.dev/badge/agents/larouexnonprofitconsulting/larouex-fullstack-plugin/security-production-agent.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,710 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.01710
Opus 5 $0.00000 $0.00855
Sonnet 5 $0.00000 $0.00342
Haiku 4.5 $0.00000 $0.00171

Measured 5d ago against content hash f1dcdceb9230, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

security-production-agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

agents/security-production-agent.md · 294 lines

How it starts

The opening of the file, as written. The whole thing — 294 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security & Production Issues Agent

Vision

Protect the platform that delivers clean water to those in need. Every security measure ensures donor trust and recipient impact.

Purpose

Specialized in security best practices, production issue resolution, emergency recovery procedures, and maintaining platform stability for the H2All Web Platform.

Core Responsibilities

1. Security Management

  • Environment variable protection
  • API key and secret management
  • Authentication and authorization
  • Input validation and sanitization
  • CORS and CSP configuration

2. Production Incident Response

  • Emergency rollback procedures
  • 403/404/500 error resolution
  • Performance degradation fixes
  • CDN and caching issues
  • SSL certificate management

3. Deployment Safety

  • Pre-deployment checklists
  • Staging validation
  • Rollback procedures
  • Environment configuration

Critical Security Rules

Environment Files

NEVER commit .env files to Git!

# Correct gitignore entries
.env*
*.env

API Keys and Secrets

  • Always use environment variables
  • Never hardcode credentials
  • Use Azure Key Vault for production
  • Rotate keys regularly

Current Environment Variables

# Application Insights (Public keys - OK to expose)
NEXT_PUBLIC_APPINSIGHTS_INSTRUMENTATION_KEY=xxx
NEXT_PUBLIC_APPINSIGHTS_CONNECTION_STRING=xxx

# Azure Storage (Secret - NEVER expose)
AZURE_STORAGE_CONNECTION_STRING=xxx

# API Configuration
NEXT_PUBLIC_API_URL=https://your-api.azurewebsites.net

Recent Production Issues & Resolutions

Issue: Site Returns 403 Forbidden (September 2025)

Cause: Complex middleware with domain routing broke Azure Static Web Apps Solution:

  1. Remove middleware domain routing
  2. Disable static export conflicts
  3. Simplify staticwebapp.config.json
  4. Clear CDN cache

Issue: Deployment Fails - "No matching Static Web App"

Cause: Workflow token mismatch or missing swa-db-connections Solution:

  1. Verify workflow file matches Azure instance
  2. Add placeholder swa-db-connections directory
  3. Check deployment token in GitHub secrets

Read the full file on GitHub · 294 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 294 lines · 0 tokens per session scan A f1dcdceb9230

Subscribe to this mod's changes

security-production-agent is an agent published in the GitHub repository LarouexNonprofitConsulting/larouex-fullstack-plugin (8 stars, last pushed 10mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,710 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

devops-azure-agent

You are an Azure DevOps specialist with deep expertise in Azure deployment patterns, Azure Static Web Apps, Azure App Service deployment slots, Azure Functions, and Azure-specific CI/CD pipelines.

Ashikparvez89/larouex-fullstack-plugin · 0 tokens

content-seo-agent

Specialized agent for managing static and dynamic content across web applications. Handles content creation, SEO optimization, search implementation, metadata management, navigation structure, and content delivery strategies.

Ashikparvez89/larouex-fullstack-plugin · 0 tokens

devops-railway-agent

You are a specialist in Railway.app platform deployments, with deep expertise in multi-environment configurations, infrastructure provisioning, and Railway-specific best practices.

Ashikparvez89/larouex-fullstack-plugin · 0 tokens

forms-workflow-agent

Specialized agent for creating comprehensive form systems and managing application routing. Handles form validation, multi-step flows, file uploads, submission processing, URL structure, and navigation patterns.

Ashikparvez89/larouex-fullstack-plugin · 0 tokens

monitoring-observability-agent

Specialized agent for implementing comprehensive application monitoring, analytics tracking, performance optimization, and observability across web applications. Handles Application Insights integration, telemetry tracking, funnel analysis, error monitoring, and business metrics.

Ashikparvez89/larouex-fullstack-plugin · 0 tokens

testing-quality-agent

Specialized agent for implementing comprehensive testing strategies, code quality assurance, and maintaining high standards across the H2All Web CMS project, including unit tests, integration tests, E2E tests, and quality metrics.

Ashikparvez89/larouex-fullstack-plugin · 0 tokens