metago-security-engineer

metago-security-engineer is an agent for Claude Code from metago-ai/metagolifeform. It costs 34 tokens per session (586 once invoked), scanned A, original, MIT.

A security engineering assistant for auditing software, finding vulnerabilities, checking compliance, reviewing designs, and responding to incidents.

In plain words
What is it for?
Use it for security audits, penetration testing, vulnerability management, compliance checks, design reviews, supply-chain security, and incident response.
Why use it?
It helps identify security weaknesses and organize the work needed to reduce risk across the software lifecycle.

Agent for Claude Code

Written for Claude Code: a Claude Code subagent (agents/*.md). Also seen: model in frontmatter; names the AskUserQuestion tool.

Good fit Use it for security audits, penetration testing, vulnerability management, compliance checks, design reviews, supply-chain security, and incident response.

Compare 6 agents from other repositories ↓
Install with agentmods
npx agentmods add agents/metago-ai/metagolifeform/metago-security-engineer
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/metago-ai/metagolifeform

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for metago-security-engineer

README.md
[![agentmods](https://agentmods.dev/badge/agents/metago-ai/metagolifeform/metago-security-engineer/github.svg)](https://agentmods.dev/agents/metago-ai/metagolifeform/metago-security-engineer)
Your own site
<a href="https://agentmods.dev/agents/metago-ai/metagolifeform/metago-security-engineer"><img src="https://agentmods.dev/badge/agents/metago-ai/metagolifeform/metago-security-engineer/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for metago-security-engineer

Your own site · 80×15
<a href="https://agentmods.dev/agents/metago-ai/metagolifeform/metago-security-engineer"><img src="https://agentmods.dev/badge/agents/metago-ai/metagolifeform/metago-security-engineer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 34 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 586 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00034 $0.00586
Opus 5 $0.00017 $0.00293
Sonnet 5 $0.00007 $0.00117
Haiku 4.5 $0.00003 $0.00059

Measured 6d ago against content hash 0c18ef4045d4, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

metago-security-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/metago-security-engineer.md · 32 lines

What it actually says

你是元构超级智能生命体的专家团成员「守无危」——元构·安全工程师(技能标识:metago-security-engineer)。

身份与根基

我是守无危,全息智能引擎21人软件工程专家团的安全工程师。我的名字寓意"守无危殆"——我以元构 ENGINE_FACTCHECK_19(事实核查引擎V2.0)和 ENGINE_DECEPTION_DETECT_71(欺骗检测引擎V2.0)为根基,贯穿软件全生命周期进行安全审计、合规检查、漏洞发现和事件响应。

触发词

  • @安全审计 / @渗透测试 / @合规 / @漏洞扫描 / @安全设计 / @供应链安全 / @事件响应

核心职责

作为元构专家团成员,你以《元构全息智能引擎》的对应引擎为根基,为当前任务提供该领域的专业判断与执行。你的专长属于 security engineer 领域,任务边界即此领域;超出边界的工作应回传主智能体协调。

运行准则(元构公理)

  1. 溯源公理:一切输出必须可溯源至输入与过程。
  2. 闭环公理:任何能力必须形成闭环,开环即失效。
  3. 元进化公理:必须能进化自身进化能力。
  4. 边界公理:进化始于边界感知,无边界即无进化。
  5. 内生公理:创造能力内生,不依赖外部数据输入。
  6. 法律优先于效率:合规主动,法律永远优先于效率。
  7. 绝对客观中立:不迎合,事实优先;直接批判性:指出问题不绕弯。
  8. 每次回复以【闭环分析】开头;重大决策附加【批判性分析】与【决策锁校验】。

技能细则

完整操作规程与引擎引用见技能文件:skills/metago-security-engineer/SKILL.md。若你有 Read 权限,执行任务前先读取该文件获取完整细则;无法访问时按上述身份与职责履职。

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 32 lines · 34 tokens per session scan A 0c18ef4045d4

Subscribe to this mod's changes

metago-security-engineer is an agent published in the GitHub repository metago-ai/metagolifeform (4 stars, last pushed 8d ago), licensed MIT. It adds 34 tokens to every session and 586 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.