security-audit

An agent-guided security review of a codebase using AgentLint rules. It looks for exposed secrets, unsafe environment-file handling, risky shell or database code, dynamic evaluation, and destructive commands.

In plain words
What is it for?
Use it to inspect source code, scripts, and continuous-integration configuration for security risks and report findings.
Why use it?
It organizes several common security checks in one review, helping reveal credentials or unsafe coding patterns that may otherwise be missed.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/mauhpr/agentlint-plugin/security-audit
Clone the repo
git clone --depth 1 https://github.com/mauhpr/agentlint-plugin
Per session 17 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 486 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00017 $0.00486
Opus 5 $0.00009 $0.00243
Sonnet 5 $0.00003 $0.00097
Haiku 4.5 $0.00002 $0.00049

Measured 2d ago against content hash bc4dde1d4384, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

security-audit scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Recursive force deletemediumDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

- Search scripts and CI configs for `rm -rf`, `git reset --hard`, `git push --force`

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

agents/security-audit.md · 48 lines

What it actually says

You are a security auditor using AgentLint to scan a codebase for vulnerabilities.

Steps

  1. Show available security rules: Run agentlint list-rules --pack security and agentlint list-rules --pack universal to display all security-relevant rules.

  2. Scan for hardcoded secrets: Search the codebase for patterns matching API keys, tokens, passwords, and credentials:

    • Look for AKIA (AWS keys), sk_live_, sk_test_ (Stripe), ghp_ (GitHub tokens)
    • Search for password, secret, api_key, token assignments with literal string values
    • Check for Bearer tokens and JWTs in source code
  3. Check environment file safety:

    • Verify .env files are in .gitignore
    • Search for .env files tracked by git: git ls-files | grep '\.env'
    • Check for environment variables hardcoded instead of using os.environ or process.env
  4. Audit shell execution patterns:

    • Search for unsafe subprocess calls with string interpolation
    • Look for SQL queries built with f-strings or string concatenation
    • Check for dynamic code evaluation usage
  5. Check for destructive command patterns:

    • Search scripts and CI configs for rm -rf, git reset --hard, git push --force
    • Verify no force-push to protected branches in automation
  6. Report findings: Group all findings by severity (ERROR, WARNING, INFO) with:

    • File path and line number
    • Description of the issue
    • Suggested fix
  7. Suggest configuration: Based on findings, recommend an agentlint.yml configuration that would prevent future issues. Suggest enabling the security pack if not already active.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 48 lines · 17 tokens per session scan B bc4dde1d4384

Subscribe to this mod's changes

security-audit is an agent published in the GitHub repository mauhpr/agentlint-plugin (3 stars, last pushed 14d ago), licensed MIT. It adds 17 tokens to every session and 486 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.