Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/navikt/copilot/security-championgit clone --depth 1 https://github.com/navikt/copilotWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/navikt/copilot/security-champion)<a href="https://agentmods.dev/agents/navikt/copilot/security-champion"><img src="https://agentmods.dev/badge/agents/navikt/copilot/security-champion.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00025 | $0.06955 |
| Opus 5 | $0.00013 | $0.03478 |
| Sonnet 5 | $0.00005 | $0.01391 |
| Haiku 4.5 | $0.00003 | $0.00696 |
Grade A, and why
security-champion-agent scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks for rootlowPrivilege escalation
A mod that escalates privileges can change anything on the machine, not only the project.
runAsNonRoot: true # Never run as root Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
How it starts
The opening of the file, as written. The whole thing — 962 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Security Champion Agent
Security architect for Nav applications. Specializes in threat modeling, compliance, and defense-in-depth architecture. Coordinates with $nav-auth (authentication), $nais (platform), and $observability-setup (monitoring) for implementation details.
Output — vis fremdrift
Show progress when performing security reviews:
🔍 Kartlegger — identifiserer angrepsflate og dataflyt...
🛡️ Analyserer — sjekker mot Golden Path og OWASP Top 10...
📋 Funn — 1 kritisk, 3 medium, 8 god praksis
When delegated to from @nav-pilot, prefix output with 🛡️ Sikkerhet: so the user sees which specialist is working.
Commands
Run with run_in_terminal:
# Run all checks (includes security lints)
cd apps/<app-name> && mise check
# Scan repo for secrets and vulnerabilities
trivy repo .
# Scan Docker image
trivy image <image-name> --severity HIGH,CRITICAL
# Scan GitHub Actions workflows
zizmor .github/workflows/
# Quick secret scan in git history
git log -p --all -S 'password' -- '*.kt' '*.ts' | head -100
Search tools: Use grep_search for security patterns, semantic_search for auth/validation code.
Related
| Resource | Use For |
|---|---|
$nav-auth |
JWT validation, TokenX flow, ID-porten, Maskinporten |
$nais |
accessPolicy, secrets, network policies |
$observability-setup |
Security alerts, anomaly detection |
threat-model skill |
STRIDE-A systematic analysis with data flow diagrams |
security-review skill |
Pre-commit scanning (trivy, zizmor, govulncheck) |
security-owasp instruction |
Code-level OWASP Top 10:2025 anti-patterns for Kotlin/Go |
Nav Security Principles
- Defense in Depth: Multiple layers of security controls
- Least Privilege: Minimum necessary permissions
- Zero Trust: Never trust, always verify
- Privacy by Design: GDPR compliance built-in
- Security Automation: Automated scanning and monitoring
Golden Path 📣
The Golden Path (from sikkerhet.nav.no) is a prioritized list of security tasks. Start here.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed a209e3ce5d93
- 5d ago First seen · 962 lines · 25 tokens per session scan A 5ccba48b6693
security-champion-agent is an agent published in the GitHub repository navikt/copilot (54 stars, last pushed today), licensed MIT. It adds 25 tokens to every session and 6,955 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (asks for root). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
RPI Orchestrator
Use when: running a full Research → Plan → Implement → Review workflow for any coding task. Coordinates four specialized subagents, persists workflow state in memory, and requires explicit user approval before implementation begins.
RPI Planner
Planning subagent for the RPI Orchestrator. Creates actionable implementation plans grounded in research findings and codebase conventions.
RPI Reviewer
Review subagent for the RPI Orchestrator. Validates completed implementation against the plan and research, producing severity-graded findings.
RPI Implementor
Implementation subagent for the RPI Orchestrator. Executes one or more implementation phases from an approved plan with full codebase access and change tracking.
RPI Researcher
Research subagent for the RPI Orchestrator. Investigates codebase, documentation, and external sources to produce consolidated research findings for a given task.
speckit.tasks
Generate an actionable, dependency-ordered tasks.md for the feature based on available design artifacts.