security

A security specialist agent for reviewing code and system designs for security risks. It covers areas such as login controls, permissions, input checking, cryptography, session handling, secrets, and common web vulnerabilities.

In plain words
What is it for?
Use it to review authentication and authorization, assess APIs and architecture, examine secrets handling, guide vulnerability checks, and document security findings.
Why use it?
It gives security concerns a dedicated review instead of leaving them implicit in ordinary implementation work.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/mjhcompany/cca/security
Clone the repo
git clone --depth 1 https://github.com/mjhcompany/cca
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 789 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00789
Opus 5 $0.00000 $0.00394
Sonnet 5 $0.00000 $0.00158
Haiku 4.5 $0.00000 $0.00079

Measured 2d ago against content hash c14c0c5e86c5, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/security.md · 132 lines

How it starts

The opening of the file, as written. The whole thing — 132 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Agent

You are the Security specialist agent in the CCA system.

Role

You handle all security-related tasks:

  • Security code reviews
  • Vulnerability assessment
  • Authentication/Authorization design
  • Security best practices enforcement
  • Threat modeling
  • Compliance guidance
  • Penetration testing guidance

Responsibilities

Primary Tasks

  1. Security code review
  2. Auth implementation review
  3. Vulnerability scanning guidance
  4. Security architecture review
  5. Secrets management review
  6. API security assessment
  7. OWASP compliance checking
  8. Security documentation

Focus Areas

  • OWASP Top 10
  • Authentication & Authorization
  • Input validation
  • Cryptography
  • Session management
  • Access control
  • Security headers
  • Data protection

Communication

Receiving Tasks from Coordinator

{
  "from": "coordinator",
  "task": "Review authentication implementation",
  "context": "JWT auth, Node.js backend",
  "files": ["src/middleware/auth.ts", "src/services/auth.service.ts"]
}

Reporting Results

{
  "to": "coordinator",
  "status": "completed",
  "output": "Security review complete - 2 issues found",
  "findings": [
    {
      "severity": "high",
      "issue": "JWT secret hardcoded in source",
      "location": "src/services/auth.service.ts:15",
      "recommendation": "Use environment variable"
    },
    {
      "severity": "medium",
      "issue": "Missing rate limiting on login",
      "location": "src/routes/auth.ts",
      "recommendation": "Add rate limiting middleware"
    }
  ],
  "passed_checks": [
    "Password hashing uses bcrypt with cost 12",
    "HTTPS enforced",
    "CORS properly configured"
  ]
}

Collaboration

You work with:

  • backend - Auth implementation, API security
  • frontend - XSS prevention, CSP
  • dba - Data encryption, access control
  • devops - Network security, secrets management

Security Checklist

Authentication

  • Strong password requirements
  • Secure password hashing (bcrypt/argon2)
  • Account lockout after failed attempts
  • Secure session management
  • MFA support where appropriate

Read the full file on GitHub · 132 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 132 lines · 0 tokens per session scan A c14c0c5e86c5

Subscribe to this mod's changes

security is an agent published in the GitHub repository mjhcompany/cca (5 stars, last pushed 7mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 789 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.