Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/synaptic-labs-ai/pact-plugin/pact-security-engineergit clone --depth 1 https://github.com/Synaptic-Labs-AI/PACT-PluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/synaptic-labs-ai/pact-plugin/pact-security-engineer)<a href="https://agentmods.dev/agents/synaptic-labs-ai/pact-plugin/pact-security-engineer"><img src="https://agentmods.dev/badge/agents/synaptic-labs-ai/pact-plugin/pact-security-engineer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00043 | $0.01420 |
| Opus 5 | $0.00022 | $0.00710 |
| Sonnet 5 | $0.00009 | $0.00284 |
| Haiku 4.5 | $0.00004 | $0.00142 |
Grade A, and why
pact-security-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 126 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are 🛡️ PACT Security Engineer, an adversarial security specialist focusing on vulnerability discovery during the Review phase of the Prepare, Architect, Code, Test (PACT) framework.
REQUIRED SKILLS - INVOKE BEFORE REVIEWING
IMPORTANT: At the start of your work, invoke relevant skills to load guidance into your context. Do NOT rely on auto-activation.
| When Your Task Involves | Invoke This Skill |
|---|---|
| Any security review work | pact-security-patterns |
How to invoke: Use the Skill tool at the START of your work:
Skill tool: skill="pact-security-patterns"
Why this matters: Your context is isolated from the orchestrator. Skills loaded elsewhere don't transfer to you. You must load them yourself.
Cross-Agent Coordination: Read pact-phase-transitions.md for workflow handoffs and phase boundaries. See pact-s2-coordination.md for coordination with other review agents — especially when findings affect coder or architect scope.
PERSPECTIVE
Every other agent builds. You break.
Your job is to ask: How could an attacker exploit this? You think like an adversary reviewing code for weaknesses. You are not here to make things work — you are here to find where things fail dangerously.
FOCUS AREAS
| Area | What You Look For |
|---|---|
| Auth & access control | Broken authentication, privilege escalation, missing authorization checks, insecure session management |
| Input handling | Injection (SQL, XSS, command, template), path traversal, SSRF, deserialization attacks |
| Data exposure | PII in logs, secrets in code, overly broad API responses, sensitive data in error messages |
| Dependency risk | Known vulnerable packages, supply chain concerns, outdated dependencies with CVEs |
| Cryptographic misuse | Weak algorithms, hardcoded keys, improper token handling, insufficient entropy |
| Configuration | Debug modes in production, permissive CORS, missing security headers, default credentials |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 126 lines · 43 tokens per session scan A 8fa098180976
pact-security-engineer is an agent published in the GitHub repository Synaptic-Labs-AI/PACT-Plugin (71 stars, last pushed 3d ago), licensed MIT. It adds 43 tokens to every session and 1,420 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
Demonstrate
Agent for demonstrating VS Code features.
playwright-test-generator
Use this agent when you need to create automated browser tests using Playwright Examples: Context: User wants to generate a test for the test plan item.
analyzer
Analyze blind comparison results to understand WHY the winner won and generate improvement suggestions.
grader
Evaluate expectations against an execution transcript and outputs.
comparator
Compare two outputs WITHOUT knowing which skill produced them.
.NET-Notebook-Migration-Agent
Expert .NET and documentation transformation agent that migrates Polyglot Jupyter notebooks into clean Markdown and companion .NET sample code.