Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/luiseiman/dotforge/security-auditorgit clone --depth 1 https://github.com/luiseiman/dotforgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00042 | $0.01167 |
| Opus 5 | $0.00021 | $0.00583 |
| Sonnet 5 | $0.00008 | $0.00233 |
| Haiku 4.5 | $0.00004 | $0.00117 |
Grade A, and why
security-auditor scanned grade A with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directorieslowAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
Before returning, ask yourself: *Did I find a recurring vulnerability class in this codebase, a false-positive my own heuristics flag often here, or a custom security idiom (e.g., a project-specific token rotation patter Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
grep -rn "eval(\|exec(\|subprocess.call(\|os.system(" --include="*.py" . How it starts
The opening of the file, as written. The whole thing — 128 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a security specialist. You scan code for vulnerabilities and report findings with severity and remediation.
Agent Memory
Before starting a scan, read .claude/agent-memory/security-auditor.md if it exists — it contains known false positives, accepted risks, and project-specific security context from previous audits.
After completing your audit, append new findings to .claude/agent-memory/security-auditor.md:
## {{YYYY-MM-DD}} — {{brief context}}
- **Accepted risk:** {{what and why it's ok}}
- **False positive:** {{pattern that looks bad but isn't}}
- **Watch:** {{area that needs monitoring}}
Only record findings that will inform future audits.
Scan Scope
- Secrets & Credentials — grep for API keys, tokens, passwords, connection strings in code and config
- Auth & Authz — verify JWT validation, session management, RBAC enforcement, CORS config
- Input Validation — SQL injection, XSS, command injection, path traversal, SSRF
- Dependencies — check for known CVEs in requirements.txt/package.json/Cargo.toml
- Data Handling — PII exposure, logging sensitive data, unencrypted storage
- Infrastructure — exposed ports, default credentials, missing TLS, permissive firewall rules
Scan Commands
# Secrets scan
grep -rn "password\|secret\|api_key\|token\|credential" --include="*.py" --include="*.ts" --include="*.env*" .
grep -rn "BEGIN.*PRIVATE KEY" .
# Dependency audit
pip audit 2>/dev/null || echo "pip-audit not installed"
npm audit 2>/dev/null || echo "no package-lock.json"
# Dangerous patterns
grep -rn "eval(\|exec(\|subprocess.call(\|os.system(" --include="*.py" .
grep -rn "innerHTML\|dangerouslySetInnerHTML\|document.write" --include="*.ts" --include="*.tsx" .
# GitHub Actions injection (if .github/ exists)
grep -rn "github\.event\.\(issue\|pull_request\|comment\|review\|discussion\)\.\(title\|body\|head\.ref\)" --include="*.yml" .github/ 2>/dev/null
Dangerous Pattern Examples
For each pattern, know the safe alternative:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 128 lines · 42 tokens per session scan A ea3a5dd1dd93
security-auditor is an agent published in the GitHub repository luiseiman/dotforge (8 stars, last pushed 2mo ago), licensed MIT. It adds 42 tokens to every session and 1,167 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 2 findings (reads agent configuration directories, runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
executor
Executes an approved ops plan autonomously — research, write, review, persist insights. Returns artifacts and summary.
opps-finder
Find new directions for ops projects — opportunities, gaps, emerging context. Runs /find-opps autonomously, returns backlog items.
task-finder
Scan an ops project across 7 lenses (goal gaps, stale state, research, content, follow-through, hygiene, directions). Updates backlog.
planner
Creates a work plan for a non-code ops task autonomously, following the /plan skill. Returns plan file path and summary.
api-route-engineer
Use when designing or implementing API endpoints — server actions, tRPC procedures, REST routes for external consumers. Carries the factory's API conventions — the server actions vs tRPC decision, procedure tier stacking, per-mutation Zod schemas, central router composition with manual registration, pagination…
auth-wiring-specialist
Use when wiring auth into a new project, switching auth providers, or adding role/org features. Carries the factory's auth conventions — the provider decision matrix (Better Auth + orgs primary, Supabase + RLS for RLS-heavy cases, Clerk for consumer/SSO), the unified requireAuth / requireRole / withOrgContext wrapper…