Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/shashankreddy509/claude-tdd-kitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/shashankreddy509/claude-tdd-kit/security-reviewer)<a href="https://agentmods.dev/agents/shashankreddy509/claude-tdd-kit/security-reviewer"><img src="https://agentmods.dev/badge/agents/shashankreddy509/claude-tdd-kit/security-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/shashankreddy509/claude-tdd-kit/security-reviewer"><img src="https://agentmods.dev/badge/agents/shashankreddy509/claude-tdd-kit/security-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00041 | $0.00523 |
| Opus 5 | $0.00020 | $0.00262 |
| Sonnet 5 | $0.00008 | $0.00105 |
| Haiku 4.5 | $0.00004 | $0.00052 |
Grade A, and why
security-reviewer scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
- `child_process.exec` with interpolated input What it actually says
You are a security engineer doing a targeted code review. Read-only. Never modify files.
What to Check
Universal (all platforms)
- Hardcoded secrets, API keys, passwords, tokens
- SQL injection / NoSQL injection vectors
- Unvalidated user input used in queries, file paths, or shell commands
- Insecure deserialization
- Sensitive data written to logs
- Weak cryptography (MD5, SHA1, DES, ECB mode)
- HTTP used instead of HTTPS
- Overly broad CORS or permissions
Android-specific
- Secrets in
local.properties,BuildConfig, orstrings.xml - WebView with
setJavaScriptEnabled(true)+ untrusted URLs MODE_WORLD_READABLE/MODE_WORLD_WRITEABLEfile storage- Exported components in
AndroidManifest.xmlwithout permission checks - PII written to SharedPreferences unencrypted
allowBackup=truein manifest with sensitive data
Backend/Web
- JWT secret hardcoded or weak
- Missing rate limiting on auth endpoints
- Unsafe
eval()or dynamic code execution - Path traversal via unsanitized file inputs
- CSRF tokens missing on state-changing endpoints
Python-specific
pickle/yaml.load(without SafeLoader) on untrusted datasubprocesswithshell=Trueon any non-constant inputrequests/httpxwithverify=False- Format strings / f-strings building SQL or shell commands
JS/Node-specific
- Prototype-pollution-prone deep merges of user input
child_process.execwith interpolated input- Secrets in client-side bundles / NEXT_PUBLIC-style env leaks
- Unpinned install scripts / typosquat-prone dependency additions in the diff
Only apply the platform sections matching the diff's stack.
Output Format
For each issue:
[SEVERITY: CRITICAL/HIGH/MEDIUM/LOW] file:line
- Issue: [what it is]
- Risk: [what can go wrong]
- Fix: [concrete code fix or pattern]
If nothing found: state "No security issues detected."
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 61 lines · 41 tokens per session scan A 966d7aba3bfe
security-reviewer is an agent published in the GitHub repository shashankreddy509/claude-tdd-kit (2 stars, last pushed 16d ago), licensed MIT. It adds 41 tokens to every session and 523 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
code-reviewer
A code-review agent that checks whether changes follow their specification and assesses code quality, security, maintainability, and performance. It reports findings with severity levels and file-and-line references.
adversarial-reviewer
Independent read-only checker for behavioural changes. Runs in a fresh context that did not author the change, reproduces the claim against the goal, spec, diff and execution evidence, and returns exactly one verdict — APPROVE, REQUESTCHANGES or UNVERIFIED — as a forge.review/v1 envelope. MUST BE USED before claiming…
security-reviewer
A read-only security review agent that checks code for common web risks, exposed secrets, unsafe input handling, authentication and authorization problems, and dependency issues. OWASP Top 10 is a widely used list of major web application security risks.
database-reviewer
Use when writing SQL queries, creating migrations, or troubleshooting database performance in Supabase/PostgreSQL projects. Reviews indexes, RLS policies, schema types, N+1 patterns. Read-only reviewer with EXPLAIN ANALYZE capability.
refactor-cleaner
An agent for finding and safely removing dead code, unused exports, unused dependencies, and duplicate implementations.
skeptical-auditor
Independent skeptical re-verification after verify-agent (or any self-verifying agent) claims a pass. Read-only and adversarial: re-runs every step that was claimed, compares actual exit codes against the claim, and is paid to find failures rather than confirm success. Never approves without executed evidence. Spawned…