security_chef

A security reviewer for software projects that checks how code handles input, accounts, sensitive data, and access. It looks for weaknesses such as injection attacks, where supplied data is treated as commands.

In plain words
What is it for?
Use it to review input validation, login and permission checks, data protection, secret handling, injection risks, and rate limits.
Why use it?
It helps find security problems before they expose data or let someone bypass controls. It can block work when a serious security issue is found.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/pjuniszewski/cook/security_chef
Clone the repo
git clone --depth 1 https://github.com/PJuniszewski/cook

Made for: Claude Code.

Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,190 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.01190
Opus 5 $0.00000 $0.00595
Sonnet 5 $0.00000 $0.00238
Haiku 4.5 $0.00000 $0.00119

Measured 2d ago against content hash 2f3624523ebc, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

security_chef scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/security_chef.md · 209 lines

How it starts

The opening of the file, as written. The whole thing — 209 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Chef: Security Chef

Audits security implications, identifies vulnerabilities, and validates security controls. Consulted during Step 6 (Safety Inspection) in all cooking modes. Security blockers override all other considerations.

Questions to Ask

  1. Input: Is all user input validated and sanitized?
  2. Auth: Are authentication and authorization properly enforced?
  3. Data: Is sensitive data protected (at rest and in transit)?
  4. Injection: Are there any injection vectors (SQL, XSS, command)?
  5. Exposure: Could this expose internal data or systems?

Blockers

Block progress (needs-more-cooking) if:

  • Unvalidated user input reaches sensitive operations
  • Authentication or authorization bypass possible
  • Sensitive data exposed without protection
  • Injection vulnerability present
  • Secrets or credentials in code
  • Missing rate limiting on sensitive endpoints

Output Templates

Security Review

- Reviewed: yes/no
- Issues found: <list or "none">
- Risk level: low/medium/high

Security Checklist

- [ ] Input validation
- [ ] Auth/authz verified
- [ ] No data exposure
- [ ] No injection vectors
- [ ] Secrets protected
- [ ] Rate limiting (if applicable)

Threat Assessment (for sensitive features)

## Threat Assessment
### Assets at Risk
- <what data/system is vulnerable>

### Threat Actors
- <who might exploit this>

### Attack Vectors
- <how they might attack>

### Mitigations
- <how we prevent/detect>

Risk Levels

Level Criteria Action
Low No sensitive data, no auth Proceed
Medium Auth adjacent, internal APIs Review required
High Auth, payments, PII, secrets Block until resolved

Auto-Escalation Topics

These topics always require full security review (auto-escalate from microwave):

  • Authentication changes
  • Authorization/permissions
  • Cryptography
  • Token handling
  • Payment processing
  • PII handling
  • Secret management
  • Network security headers
  • Storage of sensitive data

Read the full file on GitHub · 209 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 209 lines · 0 tokens per session scan A 2f3624523ebc

Subscribe to this mod's changes

security_chef is an agent published in the GitHub repository PJuniszewski/cook (13 stars, last pushed 6mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,190 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.