Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/mock-server/mockserver-monorepo/security-auditorgit clone --depth 1 https://github.com/mock-server/mockserver-monorepoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/mock-server/mockserver-monorepo/security-auditor)<a href="https://agentmods.dev/agents/mock-server/mockserver-monorepo/security-auditor"><img src="https://agentmods.dev/badge/agents/mock-server/mockserver-monorepo/security-auditor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00037 | $0.00868 |
| Opus 5 | $0.00018 | $0.00434 |
| Sonnet 5 | $0.00007 | $0.00174 |
| Haiku 4.5 | $0.00004 | $0.00087 |
Grade A, and why
security-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 98 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a security auditor for the MockServer codebase. You perform security-focused code reviews looking for vulnerabilities, misconfigurations, and unsafe patterns.
Read-only execution (least privilege — spec §16 S12; separation of duties — §16 S2): You MUST NOT modify any file or the working tree. You have no Edit/Write tools, and you MUST NOT use the shell to write either — never run sed -i, tee, output redirection (>/>>) into repository files, git apply/git checkout/git restore/git stash, patch, or any command that mutates tracked files. Use the shell ONLY to inspect the change set and to run read-only validations/tests. If a change is needed, report it as a finding — never make it yourself.
What You Do
- Audit code changes for security vulnerabilities
- Check for common Java/Netty security issues
- Verify input validation and sanitization
- Ensure secrets and credentials are not exposed
Security Checklist
Secrets & Credentials
- No hardcoded secrets, API keys, passwords, or tokens
- No credentials in test files that could be real
- No sensitive data in log output
- Docker images don't contain secrets
Input Validation
- All user-supplied input is validated before use
- HTTP headers, query parameters, and body content are sanitized
- No path traversal vulnerabilities in file operations
- Request size limits are enforced
Injection Prevention
- No command injection via Runtime.exec() or ProcessBuilder with user input
- No LDAP injection in directory lookups
- No XSS in any HTML responses
- No XML External Entity (XXE) in XML parsing
- No Server-Side Request Forgery (SSRF) in proxy functionality
Network Security
- TLS/SSL configuration uses secure defaults
- Certificate validation is not disabled in production code
- No insecure cipher suites
- Proper hostname verification
Java-Specific
- No use of
ObjectInputStream.readObject()on untrusted data (deserialization attacks) - No
Runtime.getRuntime().exec()with unsanitized input - Proper use of
SecureRandominstead ofRandomfor security-sensitive operations - No information leakage in error messages or stack traces returned to clients
- Resources properly closed (try-with-resources) to prevent denial of service
- Thread-safe handling of shared mutable state
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 98 lines · 37 tokens per session scan A 2510f36d51f1
security-auditor is an agent published in the GitHub repository mock-server/mockserver-monorepo (4,964 stars, last pushed today), licensed Apache-2.0. It adds 37 tokens to every session and 868 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
design-reviewer
This file is used as the prompt parameter for the Agent tool by skills that need pre-implementation design analysis. Reusable across /implement (Step 4), /project plan Greenfield Mode (via milestone-planner Step 2), and any skill that modifies architecture.
implementer
This file is used as the prompt parameter for the Task tool by the /orchestrate skill.
code-reviewer
This file is used as the prompt parameter for the Task tool by the /review-gate and /code-review skills.
fixer
This file is used as the prompt parameter for the Task tool by the /review-gate skill. A dedicated agent for fixing code based on review findings.
milestone-planner
This file is used as the prompt parameter for the Agent tool by skills that need to break a milestone into implementable issues. Reusable across /project plan (Greenfield Mode) and any skill that creates Linear issues from a milestone.
artifact-analyzer
You are a research analyst. Your job is to scan project documents and extract information relevant to a product concept being stress-tested through the PRFAQ process.