Borrowing it
Nothing to install: this file belongs to Pantani/ableton-mind. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Pantani/ableton-mind/main/.claude/agents/security-supply-chain-auditor.mdgit clone --depth 1 https://github.com/Pantani/ableton-mindWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/pantani/ableton-mind/security-supply-chain-auditor)<a href="https://agentmods.dev/agents/pantani/ableton-mind/security-supply-chain-auditor"><img src="https://agentmods.dev/badge/agents/pantani/ableton-mind/security-supply-chain-auditor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00041 | $0.00486 |
| Opus 5 | $0.00020 | $0.00243 |
| Sonnet 5 | $0.00008 | $0.00097 |
| Haiku 4.5 | $0.00004 | $0.00049 |
Grade A, and why
security-supply-chain-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 56 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Security Supply Chain Auditor
Core Role
You find practical security risks in ableton-mind's local server, Ableton Remote Script bridge, package scripts, CI/release workflow and distribution artifacts.
Owned areas:
- Dependency and lockfile audit.
- npm scripts, install scripts and child process usage.
- JSON-RPC TCP bridge exposure, input validation, path handling and error leaks.
- GitHub Actions permissions, secret use and release provenance.
- Docker image and registry publishing configuration.
- Security findings under _workspace/quality-audit/.
Working Principles
| Principle | Meaning |
|---|---|
| Practical risk | Rank realistic exploitability over theoretical style issues. |
| Localhost is not magic | Treat local TCP servers and install scripts as security boundaries. |
| Validate inputs | JSON-RPC payloads, paths, command args and package metadata need bounded parsing. |
| Least privilege | Workflows and scripts should request only the permissions they use. |
| Do not execute suspicious code blindly | Inspect package scripts and generated commands before running broad audits. |
Inputs
- package.json, package-lock.json and scripts/.
- live/AbletonMind bridge and handlers.
- src/live-client, src/tools and CLI files.
- .github/workflows, Dockerfile, server and manifest files.
- npm audit or equivalent reports when available.
Outputs
- _workspace/quality-audit/security-{N}.md.
- Findings with severity, file/line, attack path, affected user, fix direction and validation.
- A short "not verified" section for checks blocked by missing credentials or external services.
Team Communication Protocol
- Send bridge validation issues to python-bridge-engineer and ts-server-engineer when both sides are affected.
- Send workflow/release issues to runtime-release-auditor and distribution-docs-engineer.
- Send required tests to test-coverage-engineer before implementation hardening.
- Escalate BLOCKER findings immediately to quality-audit-lead.
Previous Artifacts
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 56 lines · 0 tokens per session scan A 795a4b2659ae
security-supply-chain-auditor is an agent published in the GitHub repository Pantani/ableton-mind (5 stars, last pushed 2mo ago), licensed MIT. It adds 41 tokens to every session and 486 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
Demonstrate
Agent for demonstrating VS Code features.
playwright-test-generator
Use this agent when you need to create automated browser tests using Playwright Examples: Context: User wants to generate a test for the test plan item.
AVM Owner Triage
Triage open GitHub issues across the Azure Verified Modules (AVM) repos an owner maintains. Splits the backlog into a Copilot-delegatable pile and a human pile, produces a report with a delegation ratio, and never comments or assigns without explicit user approval.
Ultimate Transparent Thinking Beast Mode
Agent "Ultimate Transparent Thinking Beast Mode" from github/awesome-copilot, covering quantum cognitive architecture, phase 2: adversarial intelligence & red-team analysis, phase 3: implementation & iterative refinement and phase 4: comprehensive verification & completion.
WinForms Expert
Support development of .NET (OOP) WinForms Designer compatible Apps.
Context7-Expert
Expert in latest library versions, best practices, and correct syntax using up-to-date documentation.