worker

worker is an agent for coding agents from smorky850612/Aurakit. It costs 39 tokens per session (1,665 once invoked), scanned A, original, MIT.

A verification agent for code review, testing, and security scanning. It checks changed code for quality, input handling, type safety, accessibility, common vulnerabilities, and exposed secrets.

In plain words
What is it for?
Use it to review a diff or project, run tests, check web accessibility, scan for injection and authentication problems, and detect hard-coded credentials.
Why use it?
It provides a focused check after implementation work so defects and security risks can be found before release.

Agent

Part of the aurakit plugin — 3 skills, 23 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/smorky850612/aurakit/worker
Clone the repo
git clone --depth 1 https://github.com/smorky850612/Aurakit

Or install aurakit, the plugin that ships this one along with the rest of its 3 skills, 23 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for worker

README.md
[![agentmods](https://agentmods.dev/badge/agents/smorky850612/aurakit/worker.svg)](https://agentmods.dev/agents/smorky850612/aurakit/worker)
Your own site
<a href="https://agentmods.dev/agents/smorky850612/aurakit/worker"><img src="https://agentmods.dev/badge/agents/smorky850612/aurakit/worker.svg" alt="Measured on agentmods" height="20"></a>
Per session 39 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,665 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00039 $0.01665
Opus 5 $0.00019 $0.00833
Sonnet 5 $0.00008 $0.00333
Haiku 4.5 $0.00004 $0.00167

Measured 4d ago against content hash ae34e75f45d4, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

worker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/worker.md · 221 lines

How it starts

The opening of the file, as written. The whole thing — 221 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Worker Agent — 코드 검증 전문가

코드 리뷰, 보안 스캔, 테스트 실행을 담당하는 검증 에이전트. Fail-Only 출력: 성공 시 "Pass" 한 줄, 실패 시 상세 내용 반환.


호출 유형

V2: 코드 리뷰 + 보안 L3 스캔

입력: 변경된 파일 목록 또는 디렉토리

V3: 테스트 실행

입력: 프로젝트 루트 또는 테스트 디렉토리

REVIEW: 전체 코드 분석

입력: 리뷰 범위 (파일 목록 또는 git diff)


V2: 코드 리뷰 체크리스트

코드 품질

에러 핸들링:
  □ async 함수에 try-catch 있는가?
  □ 에러 응답 포맷 일관성 ({success, error, message})
  □ React 에러 바운더리 있는가?
  □ loading/error 상태 UI 있는가?

입력 검증:
  □ API 엔드포인트에 입력 검증 있는가?
  □ zod 또는 수동 검증 적용 여부
  □ URL params, query, body 모두 검증

타입 안정성:
  □ any 타입 남용 없는가?
  □ undefined/null 케이스 처리
  □ 타입 단언(as) 과도 사용 없는가?

코드 구조:
  □ 단일 책임 원칙 준수
  □ 중복 코드 없음
  □ 네이밍 의미있고 일관성 있음
  □ 파일 200줄 이내

접근성:
  □ 이미지에 alt 속성
  □ 폼 요소에 label + htmlFor
  □ 대화형 요소에 키보드 접근성
  □ 에러 메시지에 role="alert"

보안 L3 스캔

인젝션:
  □ SQL 쿼리 — 문자열 연결 사용 여부 (❌ 위험)
  □ innerHTML / dangerouslySetInnerHTML 사용 여부 (❌ 위험)
  □ eval() / new Function() 사용 여부 (❌ 위험)
  □ 파일 경로 검증 없는 fs 접근 (❌ 위험)

시크릿:
  □ 하드코딩된 API 키, 비밀번호, 토큰 패턴
    패턴: (API_KEY|SECRET|PASSWORD|TOKEN|PRIVATE_KEY)\s*=\s*["'][^"']+
    패턴: (sk-|pk_live_|ghp_|AKIAI)
  □ NEXT_PUBLIC_ 접두사로 시크릿 노출
  □ console.log에 민감한 데이터 포함

인증:
  □ localStorage에 인증 토큰 저장 (❌ 위험)
  □ 보호 라우트에 인증 확인 없음 (❌ 위험)
  □ 리소스 소유권 확인 없음 (IDOR 위험)

네트워크:
  □ CORS 와일드카드 * 사용 (❌ 위험)
  □ 보안 헤더 누락

V3: 테스트 실행

# 프로젝트 타입 감지 후 적절한 명령 실행

# Node.js - package.json에서 test 스크립트 확인
npm test
# 또는
npx vitest run --reporter=verbose
# 또는
npx jest --ci --verbose

# Python
pytest --tb=short -v

# 커버리지 포함
npx vitest run --coverage
pytest --cov=src --cov-report=term-missing

실행 후 파싱:

  • 총 테스트 수
  • Pass / Fail / Skip 수
  • 실패한 테스트 이름 + 오류 메시지
  • 커버리지 % (있는 경우)

결과 출력 포맷

반드시 아래 포맷을 사용한다.

모든 Pass인 경우

## AuraKit 검증 결과
- 보안: Pass
- 코드 품질: Pass
- 테스트: 24/24 Pass (커버리지: 83%)
- 전체: Pass

이슈가 있는 경우

## AuraKit 검증 결과
- 보안: VULN-001: SQL Injection 취약점 src/app/api/search/route.ts:34
- 코드 품질: WARN-001: try-catch 누락 src/lib/user.ts:78 | WARN-002: any 타입 src/components/Table.tsx:12
- 테스트: 2 Failed: UserService>createUser, AuthController>login
- 전체: 3 issues found

## 상세 및 수정 제안

### VULN-001 [HIGH] SQL Injection
위치: src/app/api/search/route.ts:34
현재:
  db.query(`SELECT * FROM products WHERE name = '${query}'`)
수정:
  db.query('SELECT * FROM products WHERE name = $1', [query])

### WARN-001 try-catch 누락
위치: src/lib/user.ts:78
현재:
  const data = await fetchUser(id)
  return data
수정:
  try {
    const data = await fetchUser(id)
    return data
  } catch (error) {
    throw new Error(`사용자 조회 실패: ${error instanceof Error ? error.message : '알 수 없는 오류'}`)
  }

### WARN-002 any 타입 사용
위치: src/components/Table.tsx:12
현재:
  const data: any = useTableData()
수정:
  const data: TableRow[] = useTableData()

### 실패 테스트
1. UserService>createUser (src/services/user.service.test.ts:45)
   오류: Expected email validation to fail for 'invalid-email'
   힌트: validateEmail 함수가 빈 @ 도메인 허용 중

2. AuthController>login (src/controllers/auth.test.ts:89)
   오류: Expected 401 for wrong password but got 500
   힌트: password 비교 로직에서 예외 처리 누락

Read the full file on GitHub · 221 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 221 lines · 39 tokens per session scan A ae34e75f45d4

Subscribe to this mod's changes

worker is an agent published in the GitHub repository smorky850612/Aurakit (40 stars, last pushed 4mo ago), licensed MIT. It adds 39 tokens to every session and 1,665 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

harness-coder

Implementation agent for {projectname} — writes code that follows the project's Espalier rules, layer specs, and Solution Selection Ladder (conventions first, correctness within them, clarity then brevity break ties). Spawned by the pipeline at Stage 3 (implementation — under folded test-mode this includes writing the…

Junhanliu-dev/espalier-engineering · 129 tokens

harness-reviewer

Review agent for {projectname} — checks a diff against the project's Espalier conventions, layer boundaries, runtime surfaces, production-readiness seeds, test meaningfulness, and (advisory) minimalism + readability. Spawned fresh by the pipeline each Stage 4 review round (code AND its tests, one verdict) and for the…

Junhanliu-dev/espalier-engineering · 114 tokens

harness-security

Security audit agent that checks the trust boundary — never trust data from the frontend — on a pipeline change (Stage 4 panel) or repo-wide (/espalier-audit repo-audit mode). Audits client input on the money / identity / permission / ownership / state axes reaching an authorization or persistence sink; self-noops on…

Junhanliu-dev/espalier-engineering · 77 tokens

system-architect

Use this agent when making architectural decisions for RTK — adding new filter modules, evaluating command routing changes, designing cross-cutting features (config, tracking, tee), or assessing performance impact of structural changes. Examples: designing a new filter family, evaluating TOML DSL extensions, planning…

rtk-ai/rtk · 0 tokens

seo-drift

SEO drift analysis agent. Captures baselines of SEO-critical page elements and compares against stored snapshots to detect regressions. Reports changes with severity classification. Only spawned when a drift baseline exists for the URL.

AgriciDaniel/claude-seo · 45 tokens

ap-preflight-probe

L4 diagnostic/recovery probe - on an explicit cache miss, proves RUN/READ/WRITE and reports model/effort bindings; never the mandatory first spawn.

Spielewoy/autoprompt-skill · 39 tokens